Governance, risk and compliance (GRC)
Also known as: GRC
The joined-up work of steering security from the top, deciding which dangers to handle, and proving that rules are met.
Draft - this entry has not been reviewed yet.
Formal
A way of organising security work in which governance sets direction and ownership, risk management decides where to spend effort, and compliance checks the result against laws, standards and the organisation's own policy - run as one connected process.
In plain English
Like a school - the head sets the goals, the teachers spot which pupils are falling behind, and the outside examiner checks the results against the rules.
In practice
At a Danish water utility, the newly hired security officer keeps one shared list where every risk has an owner, a planned control and a note of which NIS2 or ISO 27001 requirement it answers.
Why it matters
When the three parts are done by separate teams, the same work is done twice and gaps fall between them; joining them gives leaders one clear picture.
Technical deep dive
The term GRC was popularised in the early 2000s by OCEG (founded in 2002), whose GRC Capability Model, known as the Red Book, defines GRC as the integrated collection of capabilities that enable an organisation to reliably achieve objectives, address uncertainty and act with integrity, summarised as "principled performance". The rise of the concept followed the Sarbanes-Oxley Act of 2002, which forced listed companies to evidence internal controls over financial reporting and exposed how much duplicated control testing existed between finance, IT, legal and risk functions. In information security, GRC denotes the non-technical control plane around security operations.
Each component has its own reference standards. Governance of IT and security draws on ISO/IEC 38500 and ISO/IEC 27014 (governance of information security) and, since NIST CSF 2.0 was published in February 2024, on the new Govern function, which covers organisational context, risk-management strategy, roles, policy, oversight and cybersecurity supply-chain risk management. Risk management uses ISO 31000:2018 as the generic framework and ISO/IEC 27005:2022 for information security risk, or COSO ERM (2017) at enterprise level. Compliance management is described in ISO 37301:2021, which is certifiable. ISO/IEC 27001 combines all three in one management system: leadership and policy (clause 5), risk assessment and treatment (6.1), and performance evaluation and audit (9).
The integration idea is operationalised through a common control framework: a single set of internal controls, each mapped to the requirements it satisfies across frameworks (for example NIS2 Art. 21, ISO 27001 Annex A, GDPR Art. 32, DORA and customer contracts), tested once and reported many times. Each risk in the risk register links to controls, owners and key risk indicators; each control links to evidence and test results; each requirement links to controls. GRC platforms implement this as a relational data model with workflows for policy attestation, risk assessment, control testing, issue management and vendor assessment, but the model can equally be kept in spreadsheets in a small organisation.
Organisationally GRC is often framed through the IIA Three Lines Model (2020): management owns and manages risk (first line), specialist risk and compliance functions provide expertise, monitoring and challenge (second line), and internal audit gives independent assurance (third line). Common failure modes are tool-first implementations that digitise poor processes, compliance-driven programmes where controls exist on paper but do not reduce risk, and risk registers disconnected from decisions. NIS2 Art. 20, which requires management bodies to approve cybersecurity risk-management measures, oversee their implementation and undergo training, has pushed governance back to the board rather than leaving GRC as a back-office function.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Compliance
- →Governance
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Risk management
- →Governance, risk and compliance (GRC)
Relationships
- Unlocks
- Grey roles
Sources & further reading
Course material
- Cyber Security Fast Track - Kursuskompendium, Formål med kurset
Reference works
- OCEG GRC Capability Model (Red Book)
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…