GRC
GRC is governance, Risk, and Compliance, an integrated approach to managing organizational governance, risk identification and treatment, and regulatory compliance.
Why it matters
GRC programs produce the policies and controls that security answers are drawn from and define how vendor risk is governed.
Where it appears in the workflow
Provides the policy and control framework underlying questionnaire answers and TPRM assessments.
Common mistakes
- Treating grc as a universal term with no workflow context.