Governance, Risk and Compliance (GRC) is the business side of security: making risk-based decisions, following recognised frameworks, and meeting legal obligations. It is where security meets the boardroom — and GRC analyst roles are in strong demand.
The Risk Management Lifecycle
How governance, risk and compliance turns uncertainty into decisions.
Tap or hover a part to learn more.
Find the risks.
Catalogue assets, threats and vulnerabilities. You cannot manage a risk you have not identified — asset inventories and threat modelling feed this step.
Check your understanding
1. Which risk treatment moves the risk to a third party?
2. What do you calculate when assessing a risk?
Beginner: governance vs risk vs compliance
- Governance — who decides, and how (policies, roles, accountability).
- Risk — identifying, assessing and treating what could go wrong.
- Compliance — meeting external rules (laws, standards, contracts).
Intermediate: risk management
Identify assets and threats, assess likelihood × impact, then choose a treatment:
- Mitigate — reduce the risk with controls (e.g. encrypt laptops).
- Transfer — shift it to a third party (e.g. cyber insurance).
- Avoid — stop the risky activity entirely.
- Accept — acknowledge and document a residual risk within appetite.
Both qualitative (high/medium/low) and quantitative methods (SLE, ARO, ALE) appear in Security+.
Advanced: frameworks and regulations
- ISO 27001 — an Information Security Management System (ISMS) standard.
- NIST CSF / 800-53 — widely used control frameworks.
- CIS Controls — prioritised, practical safeguards.
- PCI DSS — protects payment card data.
- UK GDPR / Data Protection Act 2018 — personal data protection.
Policies (acceptable use, data classification, incident response) turn frameworks into day-to-day behaviour. Third-party/supplier risk is increasingly examined too.
Practical example
A company runs a risk assessment, finds unencrypted laptops as a high risk, and mitigates it by enabling full-disk encryption. The small residual risk is documented and formally accepted by management — a defensible, evidence-based decision rather than a guess.
Common mistakes
- Treating compliance as security (ticking boxes without reducing risk).
- No data classification, so controls are applied blindly.
- Policies that exist on paper but are never followed or enforced.
- Ignoring third-party and supply-chain risk.
Best practices
Run regular risk assessments, adopt a recognised framework, classify data, keep policies practical and enforced, and manage third-party risk. This connects to Secure Architecture & Cloud (control design) and Incident Response (breach obligations).
What employers expect
You can explain the four risk-treatment options, name common frameworks and their purpose, and articulate why compliance and security are related but not identical.
Technical interview questions
- What are the four ways to treat a risk?
- What is the difference between compliance and security?
- Name a security framework and explain what it is for.
- What is the purpose of a data classification policy?
- How would you assess and manage third-party risk?
Behavioural interview questions
- Tell me about a time you had to follow a policy you disagreed with.
- Describe how you would explain a risk decision to senior management.
Practice questions
- Buying cyber insurance is which risk treatment? (Transfer)
- Which standard defines an ISMS? (ISO 27001)
- Likelihood × impact estimates the level of? (Risk)
- Which regulation governs UK personal data? (UK GDPR / DPA 2018)
Where this fits in your Security+ pathway
This domain is one part of the CompTIA Security+ study hub. When you're confident here, review Incident Response & Forensics and move on to Threats, Attacks & Vulnerabilities to keep building toward the full exam.
Practise with Missiora
- AI Interview™ — rehearse Security+ style questions on this topic and get scored feedback.
- Career Coach™ — turn this knowledge into a study-to-job plan.
- Job Intelligence™ — see which of these skills real security adverts demand.
