GRC 101 - Governance, Risk, and Compliance
“Security without structure is just chaos with good intentions.”GRC stands for Governance, Risk, and Compliance, and if you’ve never heard of it, that’s not surprising. It doesn’t have the same flashy reputation as red teaming or incident response, but it’s arguably one of the most important functions in any mature security program. In simple terms: Governance is about who makes decisions and how. Risk is about what could go wrong and how bad it would be. Compliance is about making sure you’re meeting the rules you’ve agreed or are required to follow. Together, they form the structural backbone of an organization’s security posture. Think of it this way - the red team finds the holes, the blue team defends, and GRC makes sure there’s an actual strategy, accountability, and set of standards tying everything together.
What GRC Professionals Actually Do
GRC is a broad discipline and the day-to-day work varies a lot depending on the organization and role. But here’s what the work generally looks like:- Policy Development - Writing and maintaining security policies, standards, and procedures (acceptable use, data classification, access control, etc.)
- Risk Assessments - Identifying threats and vulnerabilities, estimating the likelihood and impact of risks, and helping the business decide how to handle them (accept, mitigate, transfer, or avoid)
- Compliance Management - Tracking requirements from frameworks and regulations (ISO 27001, SOC 2, PCI-DSS, GDPR, etc.) and making sure the organization is actually meeting them
- Vendor/Third-Party Risk Management - Assessing the security posture of suppliers, cloud providers, and partners who have access to your data or systems
- Internal Audits - Reviewing controls and processes to validate they’re working as intended
- Security Awareness Training - Building and delivering training programs so employees understand their responsibilities
- Incident Escalation & Documentation - Making sure security incidents are properly documented, escalated, and lessons are captured
- Regulatory Liaison - Communicating with regulators, external auditors, and certification bodies
Scope - What GRC Covers
GRC cuts across the entire organization, not just the IT or security team. It involves conversations with legal, HR, finance, operations, and executive leadership.GRC in Different Industries
The specific regulations you deal with depend heavily on the industry:- Finance / Banking - DORA, CBEST, OJK POJK 11, PCI-DSS, Basel III/IV risk requirements
- Healthcare - HIPAA, HITECH, clinical data privacy obligations
- E-commerce / Fintech - PCI-DSS (card data), data privacy laws, anti-fraud regulations
- Government - NIST SP 800-53, FedRAMP, local national cybersecurity regulations
- Global companies - GDPR (EU), PDPA (Thailand/Singapore), UU PDP (Indonesia), and others depending on geography
Key Frameworks to Know
This is the part where GRC gets dense fast, there are a lot of frameworks out there. Here are the most commonly referenced ones:Security Frameworks
Compliance & Regulatory Frameworks
Risk Management Standards
Core Concepts to Understand
The Risk Management Lifecycle
Risk management isn’t a one-time exercise. It’s a continuous process:- Identify - What assets do we have? What threats exist? What vulnerabilities could be exploited?
- Analyze - How likely is each risk? How bad would it be? Qualitative (High/Medium/Low) or quantitative (in dollars)?
- Evaluate - Which risks exceed our tolerance? Which ones can we live with?
- Treat - For each risk, decide: mitigate, accept, transfer (insurance), or avoid
- Monitor - Track risks over time. The landscape changes, so your risk register should too.
Control Types
When you’re assessing whether an organization is protected, it helps to think in terms of control types:- Preventive - Stops something bad from happening (firewalls, access controls, encryption)
- Detective - Identifies when something bad has happened (logs, IDS, alerts)
- Corrective - Fixes something after it’s gone wrong (incident response, backups, patching)
- Deterrent - Discourages bad behavior (security awareness training, legal notices)
- Compensating - An alternative control that satisfies a requirement when the primary one isn’t feasible
What a Risk Register Looks Like
A risk register is basically a living document tracking identified risks. For each risk, you typically capture:- Risk description
- Risk owner (who’s accountable)
- Likelihood rating
- Impact rating
- Inherent risk score
- Existing controls
- Residual risk score (after controls)
- Treatment plan and timeline
Essential Tools to Know
GRC work is less tool-heavy than red or blue teaming, but there’s still a toolset to be aware of:GRC Platforms (Enterprise)
For Smaller Teams / Getting Started
Certifications Worth Looking At
- CISA (Certified Information Systems Auditor) - ISACA cert, widely respected. Audit-focused.
- CRISC (Certified in Risk and Information Systems Control) - ISACA again. More risk-management focused.
- CISM (Certified Information Security Manager) - Management-level security cert from ISACA
- CISSP - Broad security cert with a GRC-relevant domain. Highly recognized globally.
- ISO 27001 Lead Implementer / Lead Auditor - Hands-on cert for building and auditing ISMSs
- CompTIA Security+ - Good starting point before specializing in GRC
- CDPSE (Certified Data Privacy Solutions Engineer) - For those leaning into the privacy side of GRC
Where to Practice & Learn
GRC is harder to “lab” in the traditional sense compared to red/blue team - there’s no virtual machine you can spin up to practice risk assessment. But there are still good ways to build real knowledge:- NIST resources - All publicly available and free: csrc.nist.gov. Read the CSF, read SP 800-53.
- ISO 27001 Annex A - Understand what the controls are and why they exist.
- ISACA - Study materials and communities at isaca.org
- IAPP (International Association of Privacy Professionals) - Best resource for privacy-focused GRC
- LinkedIn Learning / Coursera - Surprisingly solid intro GRC and compliance courses
- Practice writing policies - Draft an actual Acceptable Use Policy or Data Classification Policy for a fictional org. It’s harder than it looks.
- Read real compliance reports - Public SOC 2 Type II reports, GDPR DPA decisions, and regulatory enforcement actions teach you what regulators actually care about.
A Few Things People Get Wrong About GRC
GRC is not just checkbox compliance. The worst version of GRC is “we filled out the questionnaire and got the certification.” The best version is a program where risk decisions are genuinely informed, controls are actually tested, and the organization understands its real security posture. GRC people need to understand the technical side. You don’t need to be a developer or a pentester, but you need to understand what SQL injection is, what a misconfigured S3 bucket means, and why logging matters. Otherwise, you can’t have credible conversations with the people doing the actual technical work. Risk appetite is a business decision, not a security decision. Security teams can advise, but the business decides how much risk is acceptable. Part of the GRC role is making sure that decision is informed - not made by default.Good Starting Points
- NIST Cybersecurity Framework - Free, well-structured, widely used
- ISO 27001 Overview - Understand the structure before going deep
- ISACA GRC Community - Community and resources from the CISA/CRISC body
- IAPP Resources - Privacy-focused GRC, lots of free material
- The GRC Analyst Forum - Practitioner community for GRC professionals
- Vanta Blog - Practical, startup-friendly GRC content
GRC is often where the most impactful security work quietly happens. It’s the difference between a team that reacts to incidents and an organization that’s actually built to reduce the likelihood of them happening in the first place.
