Governance, Risk & Compliance (GRC) is the business side of security — ensuring security is directed, risk-based and meets legal and regulatory obligations. It builds on Risk Management & Governance.
Compliance Frameworks
The standards and regulations that shape security.
Tap or hover a part to learn more.
ISMS standard.
An international standard for an Information Security Management System (ISMS) — a risk-based, auditable framework organisations get certified against.
Check your understanding
1. What is ISO 27001?
2. Is compliance the same as security?
Keep learning
The three pillars
- Governance — leadership, policy, roles and accountability so security aligns with the business.
- Risk — identify, assess and treat risk consistently (mitigate/transfer/accept/avoid).
The Risk Management Lifecycle
How governance, risk and compliance turns uncertainty into decisions.
Tap or hover a part to learn more.
Find the risks.
Catalogue assets, threats and vulnerabilities. You cannot manage a risk you have not identified — asset inventories and threat modelling feed this step.
Check your understanding
1. Which risk treatment moves the risk to a third party?
2. What do you calculate when assessing a risk?
- Compliance — meeting frameworks and regulations: ISO 27001 (ISMS), NIST CSF, GDPR (data protection), PCI DSS (cards) and SOC 2 (service providers).
GRC translates security into business language, drives audits and certifications, and is a stable, well-paid career path — the domain of the GRC Analyst. Compliance is a baseline, not the finish line: being compliant is not the same as being secure.
