Missiora
Governance, Risk & Compliance (GRC)

Technology Fundamentals

Governance, Risk & Compliance (GRC)

1 min readPublished 22 Jul 2026

Track your progress. Sign in to mark this guide complete and build your Job Readiness Score.

Governance, Risk & Compliance (GRC) is the business side of security — ensuring security is directed, risk-based and meets legal and regulatory obligations. It builds on Risk Management & Governance.

Interactive explainer

Compliance Frameworks

The standards and regulations that shape security.

1ISO 270012NIST CSF3GDPR4PCI DSS & SOC 2

Tap or hover a part to learn more.

ISO 27001

ISMS standard.

An international standard for an Information Security Management System (ISMS) — a risk-based, auditable framework organisations get certified against.

Check your understanding

1. What is ISO 27001?

2. Is compliance the same as security?

Practise this in AI Interview™

The three pillars

  • Governance — leadership, policy, roles and accountability so security aligns with the business.
  • Risk — identify, assess and treat risk consistently (mitigate/transfer/accept/avoid).
Interactive explainer

The Risk Management Lifecycle

How governance, risk and compliance turns uncertainty into decisions.

1Identify2Assess3Treat4Monitor & Review

Tap or hover a part to learn more.

Identify

Find the risks.

Catalogue assets, threats and vulnerabilities. You cannot manage a risk you have not identified — asset inventories and threat modelling feed this step.

Check your understanding

1. Which risk treatment moves the risk to a third party?

2. What do you calculate when assessing a risk?

Practise this in AI Interview™
  • Compliance — meeting frameworks and regulations: ISO 27001 (ISMS), NIST CSF, GDPR (data protection), PCI DSS (cards) and SOC 2 (service providers).

GRC translates security into business language, drives audits and certifications, and is a stable, well-paid career path — the domain of the GRC Analyst. Compliance is a baseline, not the finish line: being compliant is not the same as being secure.

Interview Intelligence

How this topic actually shows up in interviews — and how to demonstrate you understand it.

Why employers ask about this

GRC turns security into business and regulatory outcomes — a stable, in-demand and well-paid path.

Technical questions
What is the difference between compliance and security?+

Compliance meets required controls/regulations; security manages real risk. You can be compliant but not secure.

Behavioural questions
Describe balancing rules/process with practical outcomes.+

Show meeting obligations while keeping controls proportionate and effective.

Real-world scenarios
“The business must achieve ISO 27001 certification.”+

Expected answer: Build an ISMS: governance, risk assessments, controls and evidence — then prepare for audit, ensuring it's genuinely effective, not just paperwork.

Employability Intelligence

Where this knowledge takes you — the jobs, skills and certifications it feeds into.

Relevant roles
GRC AnalystCompliance AnalystSecurity Manager
Skills you're proving
GRCCompliance frameworksRisk management
Recommended certifications
CompTIA Security+ISACA CISM / CRISCISO 27001 Lead Implementer
Career progression

Cyber Fundamentals → GRC Analyst → Security Manager.

What employers expect

That you understand core security principles and can apply them to real risks, controls and incidents.

Frequently asked questions

What does GRC stand for?

Governance, Risk and Compliance — the business and regulatory side of managing security.

Is compliance the same as security?

No — compliance is a baseline of required controls; you can be compliant yet still insecure. Security goes further.

What are common compliance frameworks?

ISO 27001, NIST CSF, GDPR, PCI DSS and SOC 2, among others, depending on industry and data.

Related guides

Practise what you've learned

Turn this guide into real, evidenced progress

Missiora helps you measure, improve and evidence the capabilities employers actually value — start with the tools best suited to this topic.

M
Published by
Missiora

Missiora is an AI Employability Intelligence platform. Our resources are researched and reviewed by the Missiora team to help you measure, improve and prove your career readiness.