Security+ Domain: Governance, Risk & Compliance

IT & Cyber Certifications

Security+ Domain: Governance, Risk & Compliance

3 min readPublished 22 Jul 2026

Track your progress. Sign in to mark this guide complete and build your Job Readiness Score.

Governance, Risk and Compliance (GRC) is the business side of security: making risk-based decisions, following recognised frameworks, and meeting legal obligations. It is where security meets the boardroom — and GRC analyst roles are in strong demand.

Interactive explainer

The Risk Management Lifecycle

How governance, risk and compliance turns uncertainty into decisions.

1Identify2Assess3Treat4Monitor & Review

Tap or hover a part to learn more.

Identify

Find the risks.

Catalogue assets, threats and vulnerabilities. You cannot manage a risk you have not identified — asset inventories and threat modelling feed this step.

Check your understanding

1. Which risk treatment moves the risk to a third party?

2. What do you calculate when assessing a risk?

Practise this in AI Interview™

Beginner: governance vs risk vs compliance

  • Governance — who decides, and how (policies, roles, accountability).
  • Risk — identifying, assessing and treating what could go wrong.
  • Compliance — meeting external rules (laws, standards, contracts).

Intermediate: risk management

Identify assets and threats, assess likelihood × impact, then choose a treatment:

  • Mitigate — reduce the risk with controls (e.g. encrypt laptops).
  • Transfer — shift it to a third party (e.g. cyber insurance).
  • Avoid — stop the risky activity entirely.
  • Accept — acknowledge and document a residual risk within appetite.

Both qualitative (high/medium/low) and quantitative methods (SLE, ARO, ALE) appear in Security+.

Advanced: frameworks and regulations

  • ISO 27001 — an Information Security Management System (ISMS) standard.
  • NIST CSF / 800-53 — widely used control frameworks.
  • CIS Controls — prioritised, practical safeguards.
  • PCI DSS — protects payment card data.
  • UK GDPR / Data Protection Act 2018 — personal data protection.

Policies (acceptable use, data classification, incident response) turn frameworks into day-to-day behaviour. Third-party/supplier risk is increasingly examined too.

Practical example

A company runs a risk assessment, finds unencrypted laptops as a high risk, and mitigates it by enabling full-disk encryption. The small residual risk is documented and formally accepted by management — a defensible, evidence-based decision rather than a guess.

Common mistakes

  • Treating compliance as security (ticking boxes without reducing risk).
  • No data classification, so controls are applied blindly.
  • Policies that exist on paper but are never followed or enforced.
  • Ignoring third-party and supply-chain risk.

Best practices

Run regular risk assessments, adopt a recognised framework, classify data, keep policies practical and enforced, and manage third-party risk. This connects to Secure Architecture & Cloud (control design) and Incident Response (breach obligations).

What employers expect

You can explain the four risk-treatment options, name common frameworks and their purpose, and articulate why compliance and security are related but not identical.

Technical interview questions

  1. What are the four ways to treat a risk?
  2. What is the difference between compliance and security?
  3. Name a security framework and explain what it is for.
  4. What is the purpose of a data classification policy?
  5. How would you assess and manage third-party risk?

Behavioural interview questions

  1. Tell me about a time you had to follow a policy you disagreed with.
  2. Describe how you would explain a risk decision to senior management.

Practice questions

  1. Buying cyber insurance is which risk treatment? (Transfer)
  2. Which standard defines an ISMS? (ISO 27001)
  3. Likelihood × impact estimates the level of? (Risk)
  4. Which regulation governs UK personal data? (UK GDPR / DPA 2018)

Where this fits in your Security+ pathway

This domain is one part of the CompTIA Security+ study hub. When you're confident here, review Incident Response & Forensics and move on to Threats, Attacks & Vulnerabilities to keep building toward the full exam.

Practise with Missiora

Interview Intelligence

How this topic actually shows up in interviews — and how to demonstrate you understand it.

Why employers ask about this

GRC connects security to the business and the law; interviewers value candidates who can speak risk and compliance, not just tech.

Technical questions
What is the difference between a policy, a standard and a procedure?+

A policy states intent, a standard sets mandatory requirements, and a procedure gives step-by-step instructions.

What does GDPR require of organisations?+

To protect personal data, process it lawfully, minimise what they collect and report breaches within set timeframes.

Behavioural questions
Describe getting people to follow a security policy they resisted.+

Explain how you communicated the 'why', made compliance easy, and gained buy-in rather than just mandating it.

Real-world scenarios
“A team stores customer data in an unapproved app.”+

Expected answer: Explain the compliance/risk exposure, work with them on an approved alternative, and document the remediation.

Common candidate mistakes
  • Treating compliance as a tick-box exercise rather than risk management.
  • Confusing policies with procedures.

Employability Intelligence

Where this knowledge takes you — the jobs, skills and certifications it feeds into.

Relevant roles
GRC AnalystCompliance AnalystRisk Analyst
Skills you're proving
Risk managementPolicy & governanceCompliance frameworksData protection
Recommended certifications
Career progression

Security Analyst → GRC Analyst → Risk/Compliance Manager.

What employers expect

That you connect security to business risk, regulation and clear policy.

Frequently asked questions

Is GRC boring compared to the technical domains?

It is less hands-on but hugely employable — GRC analyst roles are in demand, and understanding risk makes you a better technical practitioner too.

Do I need to memorise every framework?

Know the purpose of the major ones (ISO 27001, NIST, CIS, PCI DSS, UK GDPR) and the difference between a framework, a standard and a regulation.

What is the difference between a policy, a standard and a procedure?

A policy states intent (what and why), a standard sets mandatory requirements (the specific rules), and a procedure gives step-by-step instructions (how). Together they turn governance into repeatable, auditable practice.

Related guides

Practise what you've learned

Turn this guide into real, evidenced progress

Missiora helps you measure, improve and evidence the capabilities employers actually value — start with the tools best suited to this topic.

M
Published by
Missiora

Missiora is an AI Employability Intelligence platform. Our resources are researched and reviewed by the Missiora team to help you measure, improve and prove your career readiness.