Skip to content
Clear Infosec

Governance & Compliance

What is Governance, Risk, and Compliance?

Also known as: GRC

Governance, risk, and compliance is an integrated approach that aligns security strategy and controls with business objectives, manages risk, and ensures adherence to laws, regulations, and standards. It matters because it turns scattered security and compliance efforts into a coordinated, accountable program.

Example

A GRC program maps controls to a framework so that a single control set satisfies multiple regulatory requirements at once.

Reference: NIST ↗

Related Clear Infosec services

Related terms

Have a question about governance, risk, and compliance in your environment? Talk to our team.