Governance, Risk, and Compliance (GRC)

Securing the business, not just the computers.

GRC ensures that IT activities align with business goals (Governance), risks are identified and managed (Risk), and legal/regulatory requirements are met (Compliance).

The Triad

  1. Governance: The strategy. "What are we doing and why?"
  2. Risk: The uncertainty. "What could go wrong?"
  3. Compliance: The rules. "What must we do?"

Section Contents