// THREAT DETECTION AND DATA PRIVACY TERM

Governance Risk Compliance

Governance, Risk, and Compliance (GRC) is a strategic approach that helps organizations manage their overall governance, effectively identify and mitigate risks, and ensure adherence to relevant laws, regulations, and internal policies.

Governance Risk Compliance — illustration from Wikipedia
Image via Wikipedia

TECHNICAL DEFINITION

Governance, Risk, and Compliance (GRC) is an integrated framework enabling organizations to consistently achieve objectives, address uncertainty and risk management, and act with integrity by adhering to regulatory compliance obligations, internal policies, and ethical standards across all operational domains, crucial for maintaining security posture and regulatory standing in cybersecurity and defense.

BACKGROUND

Computer security is a subdiscipline within the field of information security. It focuses on protecting computer software, systems, and networks from threats that can lead to unauthorized information disclosure, theft, or damage to hardware, software, or data, as well as to the disruption or misdirection of the services they provide.

READ MORE ON WIKIPEDIA

SYNONYMS & ALIASES

  • Integrated GRC
  • Enterprise GRC
  • Risk Compliance Management
  • Regulatory Compliance
  • Information Security GRC

USAGE NOTE

GRC is commonly implemented through specialized software platforms to streamline processes, automate control monitoring, and provide real-time visibility into an organization's compliance and risk landscape.

DEVELOPERS

Organizations developing technology related to Governance Risk Compliance.

  • MetricStream

    A global leader in Governance, Risk, and Compliance (GRC) solutions, offering a comprehensive platform for enterprise GRC, IT GRC, and cyber GRC to help organizations manage risk and regulatory compliance.

  • Archer (an RSA business)

    Provides an integrated risk management (IRM) platform that helps organizations manage enterprise-wide GRC programs, including IT & security risk management, regulatory compliance, and third-party risk.

  • ServiceNow

    Offers IT GRC solutions as part of its Now Platform, enabling organizations to automate and manage risk, compliance, and audit processes, and gain visibility into their security and operational risks.

  • IBM Security

    Provides a wide range of cybersecurity solutions and services, including GRC consulting, security intelligence platforms, and identity and access management tools that support robust governance and risk management frameworks.

  • SAP

    Offers a comprehensive Governance, Risk, and Compliance (GRC) suite that helps organizations automate and manage key GRC processes, including access control, process control, risk management, and international trade.

  • OneTrust

    A leading platform for trust intelligence, offering solutions for privacy, security, data governance, GRC, and ESG, helping organizations comply with global regulations and build trusted relationships.

  • LogicManager

    Provides an integrated risk management (IRM) software platform that helps organizations centralize and connect risk, compliance, IT GRC, and incident reporting to make better business decisions.

  • AuditBoard

    Offers a cloud-based platform for audit, risk, and compliance management, helping organizations streamline SOX compliance, internal audits, IT risk, and third-party risk management processes.

RELATED TERMS IN COMPLIANCE & PRIVACY