Cybersecurity definition
What is GRC?
GRC stands for Governance, Risk, and Compliance.
By Cyber Tool Stack Editorial TeamUpdated
Definition
The combined discipline of setting policy (governance), identifying and managing what could go wrong (risk), and proving adherence to laws and standards (compliance) — usually the umbrella term for the programs and tools that manage all three together.
Where GRC fits in the security landscape
These beginner lessons use this term while explaining the surrounding security control.
Related cybersecurity terms
Risk RegisterA tracked, living list of an organization's identified risks, each with an owner, likelihood and impact rating, and a treatment plan — the central artifact most GRC programs and audits are built around.SOC 2An audit report, defined by the AICPA (the American Institute of CPAs) — SOC stands for System and Organization Controls — that evaluates a service organization's controls around security, availability, and related trust criteria. SOC 2 is the specific report enterprise SaaS customers most often require, as distinct from SOC 1's focus on financial reporting controls.