COMPLIANCE

GRC

Governance, Risk, and Compliance. The coordinated practice of setting policy, managing risk, and proving adherence to regulations, often supported by a dedicated platform.

IN PRACTICE

A GRC platform maps each security control to the frameworks it satisfies, so one piece of evidence can answer SOC 2, HIPAA, and ISO 27001 auditors at once.

← Back to glossary