1/20
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced |
---|
No study sessions yet.
GRC in Cybersecurity
An integrated framework for aligning IT with business objectives, managing risks, and ensuring adherence to laws and regulations in cybersecurity. It also aims to make cybersecurity accessible to non-technical professionals.
Cybersecurity
The protection of systems, networks, and data from digital threats.
Governance
In GRC, it establishes policies, roles, and accountability for protecting digital resources, aligning with company goals, risk tolerance, and regulatory mandates.
Risk Management
In GRC, it identifies, assesses, and mitigates threats to confidentiality, integrity, and availability of data, as well as managing and monitoring cyber risks.
Compliance
In GRC, it ensures adherence to laws, regulations, and standards (e.g., GDPR, HIPAA, PCI DSS, SOX, NIST CSF, ISO 27001).
CIA Triad
Core concepts of cybersecurity: Confidentiality, Integrity, and Availability.
Risk Calculation
Risk = Likelihood \times Impact
Common Cybersecurity Risks
Malware (viruses, ransomware), phishing variants, and password attacks.
Quantitative Risk Math
Risk = Likelihood \times Impact
GRC Tools
Specialized software (e.g., RSA Archer, Hyperproof) for optimizing governance, risk, and compliance workflows and supporting automation.
Core GRC Skills for Non-Tech Professionals
Communication, Analytical/Problem-Solving, Continuous Learning, Regulatory Knowledge, Project Management, Collaboration, Attention to Detail, Decision-Making, Resilience, and Adaptability.
Useful GRC Certifications
CISA, CISM, CRISC, CIPP, CRCM.