GRC Udemy Flashcards
Set of policies, rules, or practices that a company uses to achieve its business goals
Governance
Potential for loss or harm to the IT infrastructure
Risk
Adherence of organizations to laws regulations, standards, policies and guidelines
Compliance
Structured way to align IT with business goals while managing risks and meeting all industry regulations
GRC
GRC Disciplines. Name 3
-governance and oversight
-strategy and performance
-risk management
-compliance and ethics
-information security
-audit and assurance
3 lines defense model
- Business,
- security and
- internal audit
Governing body
Management
Internal audit
Meet stakeholders needs by providing value.
Achieved through policy rules and practices
Governance
Soc
Compliance framework
Service organizations control
NIST Framework
5 cores
Identify
Protect
Detect
Respond
Recover
Determines what exists, dangers involved and connect to company goal is what most core function?
Ex. Asset and risk management, governance
Identify
Safeguarding assets and data. Access control and data encryption. Nist
Protect
Safeguarding asset and data. Incident detection monitoring
Detect
Mitigating impact of risk. Notify stakeholders and keep operations up
Respond
Repair and restore, effective response
Recover
Requirement for ISMS. 93 controls.
ISO 27001