Knowledge Graph

Concept Maps

Explore how terms connect across your learning. Click any concept to see its full relationship map.

1801terms
0links
1809topics
Reset

grc

80

72-Hour Notification

A 72-hour notification is a regulatory deadline that requires an organization to report certain security or privacy incidents within 72 hours of becoming aware of them.

Architecture Finding Communication

Conveying the results of a security architecture review so stakeholders understand each design weakness, why it matters, and what to change, adjusting depth and framing for technical teams versus leadership.

Architecture Findings

The weaknesses identified during a security architecture review, such as missing trust boundaries, weak authentication between components, or single points of failure, that stem from how a system is designed rather than from a single bug.

Architecture Review Methodology

The defined process for reviewing a system's security architecture from start to finish: setting scope, gathering design information, applying threat modeling, identifying findings, and communicating recommendations.

Architecture Review Scope

The boundaries of a security architecture review: which systems, components, data flows, and concerns are in or out, set at the start so the review stays focused and its findings are meaningful.

Asset-Based Identification

A risk identification approach that starts from the organization's important assets, such as systems, data, and services, and asks what threatens each one. It anchors risk discovery in what actually matters to protect.

Audit Categories

The major kinds of audit, such as financial, operational, compliance, and IT or cybersecurity audits, each with a different objective and scope. Knowing the category sets expectations for what an audit will and will not cover.

Audit Discipline

The body of professional rigor that defines good auditing: systematic methodology, evidence-based conclusions, objectivity, and adherence to standards. It is what makes audit results credible and repeatable.

Audit Engagement Management

Running an external audit engagement well from the company's side: selecting the firm, scoping the work, coordinating evidence and timelines, and managing distribution of the resulting report, so the audit is efficient and the outcome is usable.

Audit Ethics

The ethical obligations that govern auditors, including objectivity, integrity, confidentiality, and avoiding conflicts of interest. Because others rely on audit conclusions, ethical lapses undermine the entire value of the work.

Audit Firm Selection

Audit firm selection is the process of choosing an independent assessment partner based on scope, expertise, independence, and the compliance framework being assessed.

Audit Independence

The auditor's freedom from influence or conflicts that could bias their conclusions, in both fact and appearance. Without independence, an audit's assurance is worthless because its objectivity cannot be trusted.

Audit Profession

The field of auditing as a recognized professional discipline, with its own standards, ethics, certifications, and career structure. Membership implies adhering to shared expectations of competence and integrity.

Audit Quality

How well an audit achieves its purpose: conclusions that are accurate, well-evidenced, and relevant, reached through sound methodology and objectivity. Poor quality erodes the trust that makes audit useful.

Audit Report Distribution

Controlling who receives an audit report and how, since reports often contain sensitive findings and may be shared with customers, regulators, or partners under specific conditions. Distribution must balance transparency with confidentiality.

Audit Standards

The formal frameworks that define how audits must be conducted, such as the IIA Standards for internal audit or ISACA's standards for IT audit. They set expectations for independence, evidence, documentation, and reporting.

Audit Universe

The complete set of areas, processes, and systems that could potentially be audited in an organization. It is the master list from which a risk-based audit plan selects what to audit and when.

Auditor Skills

The competencies an effective auditor needs, combining technical knowledge and methodology with communication, skepticism, and judgment. They determine how reliably an auditor can find and explain real issues.

Authentication Architecture Review

Assessing how a system proves who users are, examining the design of login flows, multi-factor authentication, session handling, token issuance, and federation, to find design weaknesses before they are exploited.

Authorization Architecture Review

Assessing how a system decides what an authenticated user is allowed to do, examining the design of its access model (such as RBAC or ABAC), enforcement points, and default-deny posture, to find gaps that allow excess access.

Awareness Program Applied

An applied awareness program turns security guidance into practical habits through role-aware training, reminders, reporting paths, and reinforcement.

BC/DR Applied

Putting business continuity and disaster recovery into practice within a real security program: producing the plans, recovery objectives, and tested procedures rather than treating BC/DR as a theoretical document.

Building Framework Mapping

When building a compliance program, mapping the organization's controls to one or more frameworks (like SOC 2, ISO 27001, or NIST) so a single control can satisfy multiple requirements and gaps become visible.

Business Impact Analysis

A structured process that identifies an organization's critical processes, what they depend on, and the consequences of disruption over time, producing the recovery priorities and objectives that drive continuity planning.

Calibrated Estimation

A skill for making numerical risk estimates whose stated confidence matches reality, so that when an estimator says they are 90% confident, they are right about 90% of the time. It produces honest, useful ranges instead of false precision or vague guesses.

Certifiable vs Reference

A distinction between security frameworks you can be formally certified against (like ISO 27001) and reference frameworks meant as guidance you adopt and adapt (like the NIST Cybersecurity Framework). The type changes how you use the framework.

Cloud Architecture Security Review

A security architecture review focused on a cloud environment, examining how accounts, identity, networking, data protection, and services are designed to find systemic weaknesses such as over-broad access, flat networks, or unprotected data.

Cloud Reference Architectures

Vetted, reusable blueprints for securely designing common cloud scenarios, such as a secure landing zone, a three-tier app, or a data platform, that an architecture reviewer compares a real design against to spot gaps.

Comprehensive Identification

A thorough approach to finding risks that combines multiple techniques, asset-based, scenario-based, threat-based, and external sources, so the organization surfaces a complete picture of its risks rather than missing whole categories.

Continuous Risk Management

Treating risk management as an ongoing, living process rather than a periodic exercise, continuously identifying, assessing, treating, and monitoring risks as the environment and threats change, so the risk picture stays current.

Day-to-Day GRC Work

The recurring practical tasks of a governance, risk, and compliance analyst, maintaining controls and evidence, running risk assessments, mapping and testing controls, tracking findings, and communicating status, that keep a GRC program operating.

Evidence Practices

The end-to-end practices for handling compliance evidence in a security program, how it is collected, organized, validated, and presented, applied as part of building and running a coherent program in the capstone context.

Evidence Repository

A central, organized store where compliance evidence is kept, control proof, logs, policies, and records, so it is preserved, version-tracked, and easy to retrieve for audits and ongoing compliance.

External Risk Sources

Risks that originate outside the organization, such as threat-actor activity, regulatory change, supply-chain and vendor risk, economic shifts, and geopolitical events, that risk identification must look beyond internal assets to capture.

First Line and Second Line

Two of the 'three lines' model: the first line owns and operates risks and controls (the business and operations), while the second line (risk and compliance functions) sets policy and oversees, advises, and challenges the first line.

GDPR Compliance Posture

An organization's overall state of GDPR readiness within a security program, how well its policies, controls, data handling, and evidence actually satisfy GDPR, assessed and improved as part of building the program.

GDPR Data Mapping

Building the inventory of personal data flows required for GDPR, what personal data the organization holds, where it comes from, how it is used, and where it goes, as a foundation for the program's GDPR compliance.

GRC Analyst

A practitioner who carries out governance, risk, and compliance work, running risk assessments, mapping and testing controls, maintaining evidence, supporting audits, and tracking findings, to keep an organization's GRC program functioning.

GRC Deliverables

The concrete outputs a GRC analyst produces, risk assessments and registers, control matrices, compliance reports, evidence packages, policies, and findings reports, that make the program's work visible and actionable to stakeholders.

GRC Maturity

How developed and effective an organization's governance, risk, and compliance program is, from ad-hoc and reactive to integrated, proactive, and continuously improving, used to assess where a program stands and what to improve next.

GRC Program

The organized set of governance, risk, and compliance activities, policies, risk management, controls, compliance, audit support, and reporting, run as a coherent program with ownership, processes, and tooling rather than scattered tasks.

GRC Stakeholders

The people and groups a GRC program serves and works with, executives and the board, business and operations teams, auditors, regulators, IT and security, whose differing needs the GRC analyst must understand and balance.

GRC vs Operations

The distinction between GRC's oversight-and-assurance role and the operational teams that actually run controls, GRC sets policy, assesses risk, and verifies, while operations owns and performs the day-to-day security work.

IA Independence

The principle that an internal audit function must be organizationally independent and objective, reporting in a way that keeps it free from management influence, so its assessments of controls and risk are credible and unbiased.

IA Maturity

How developed an internal audit function is, from a basic, compliance-focused activity to a strategic, risk-based, value-adding function, used to assess where internal audit stands and how to advance its capability.

IA Methodology

The structured approach an internal audit function follows to plan and perform audits, risk-based planning, fieldwork and testing, evidence gathering, and reporting, so audits are consistent, rigorous, and aligned to risk.

IA Reporting

How an internal audit function communicates results, audit reports with findings, risk ratings, and recommendations to management, and summary reporting to the board or audit committee, so assurance leads to action and oversight.

Internal Audit Charter

The formal document that establishes an internal audit function's purpose, authority, scope, and independence, approved by the board or audit committee, giving the function its mandate to operate and access what it needs.

Internal Audit Function

The organizational unit that performs internal audit, its people, structure, mandate, and processes, providing independent assurance over controls, risk, and governance to management and the board.

ISO 31000 Process

The risk-management process defined by ISO 31000, establishing context, then identifying, analyzing, evaluating, and treating risk, with ongoing communication and monitoring, providing a generic, principles-based framework for managing any risk.

Multi-Framework Control Mapping

Mapping the organization's controls to several frameworks at once so each control's evidence can be claimed against every framework it satisfies, the practical core of running multi-framework compliance.

Multi-Framework Efficiency

The gains in cost, effort, and consistency that come from running multiple frameworks as a coherent program with shared controls and evidence, rather than handling each separately, the payoff of a mature multi-framework approach.

NIST RMF

The NIST Risk Management Framework: a structured process (categorize, select, implement, assess, authorize, monitor) for managing security and privacy risk for systems, widely used in US federal government and influential more broadly.

Phishing Simulation

Sending controlled, fake phishing emails to staff to measure susceptibility and reinforce training, a security-awareness tool used carefully to build resilience without blaming or demoralizing employees.

Policy Communication

Making policies known and understood across the organization, through accessible language, awareness campaigns, training, and easy-to-find publication, so people can actually follow what policies require.

Policy Library Structure

How an organization organizes its set of policies, by topic, hierarchy, ownership, and version, so the library is navigable, complete, and maintainable, an essential GRC and capstone-level deliverable.

Policy Lifecycle

The full cycle policies move through, drafting, approval, communication, operation, review, revision, and eventual retirement, ensuring policies are managed deliberately over time rather than written and forgotten.

Qualitative Risk

Risk analysis expressed in non-numeric, descriptive terms such as high/medium/low or red/amber/green, common in GRC for its accessibility, often paired with structured criteria for consistency.

Quantitative Risk

Risk analysis expressed in numbers, frequencies, probability distributions, and dollar amounts, that enables comparison, aggregation, and clear financial reasoning. FAIR is the leading quantitative approach in cybersecurity.

Risk Assessment Scope

Defining what an assessment covers, which systems, processes, threats, and time horizon, so its findings are bounded, comparable, and meaningful rather than vague.

Risk Communication Throughout

Communicating risk continuously across the risk lifecycle, not only at assessment, so stakeholders stay aligned on status, decisions, and changes rather than learning about risk only at headline moments.

Risk Context

Establishing the context in which risk is assessed, the organization's objectives, environment, stakeholders, and constraints, so risk analysis is grounded in what actually matters to the organization.

Risk Definition

The shared meaning of 'risk' an organization adopts (often impact times likelihood, or chance of consequence), grounding the GRC program in a consistent concept so people are talking about the same thing.

Risk Lifecycle

The full sequence each risk moves through, identification, analysis, evaluation, treatment, monitoring, communication, that frames risk management as a continuing process rather than a one-time activity.

Risk Maturity Models

Models that describe maturity levels of a risk-management capability, from ad hoc to optimized, used to assess where an organization stands and plan investment to grow the function over time.

Risk Program Structure

How the risk-management function is organized, ownership, roles, committees, reporting lines, frameworks, that determines whether risk management operates as a coherent program or a collection of activities.

Risk Workshops

Facilitated sessions with stakeholders to identify, analyze, or rate risks together, useful for gathering diverse perspectives and producing shared understanding alongside structured outputs.

Risk-Based Audit Planning

Planning audits to focus on the highest-risk areas first, rather than auditing everything equally, so limited audit capacity goes where it most affects outcomes.

Scenario-Based Identification

An approach to risk identification that imagines specific 'what-if' scenarios, an attacker doing X, a system failing in Y way, to surface risks that abstract analysis might miss.

Security Program Charter

A foundational document establishing a security program's authority, scope, mission, and structure, signed by executive leadership, that authorizes the program and anchors its governance.

Security Program Presentation

Communicating the security program's status, priorities, and asks to executive and board audiences clearly, persuasively, and concisely, a capstone skill that determines whether the program gets support.

Security Program Scope

What the security program covers, business units, systems, geographies, controls, that defines the program's responsibilities and boundaries so they are clear rather than assumed.

Security Training Program

A managed program that designs, delivers, and measures the security training employees receive, across the awareness and GRC capstone perspectives, so training is intentional rather than ad hoc.

SOC 2 Gap Assessment

An internal assessment that compares current controls against SOC 2 Trust Services Criteria to find gaps before an external audit, so they can be remediated in time.

SOC 2 Policy Coverage

Ensuring an organization's policy set covers all areas SOC 2 expects, access control, change management, vendor risk, incident response, so audit evidence about policies is complete.

SOC 2 Policy Requirements

The specific policies SOC 2 expects to see, with content, ownership, and approvals appropriate to the Trust Services Criteria, that organizations meet to satisfy the policy side of SOC 2.

SOC 2 Program Design

The capstone exercise of designing a complete SOC 2 program, scope, controls, policies, evidence, audit plan, that demonstrates a working approach to satisfying SOC 2 end to end.

Threat-Based Identification

Identifying risks by walking specific threats and asking what they could do, surfacing concrete risks tied to plausible adversary behavior rather than starting from generic categories.

TPRM Applied

Applying third-party risk management in practice end to end, vendor inventory, tiering, due diligence, contracts, monitoring, that builds a working TPRM function rather than a paper one.

Vulnerability-Based Identification

Identifying risks by starting from known vulnerabilities and weaknesses in the environment, then tracing what they could allow, a concrete risk-identification approach.