Terminology Index
Glossary
1801 terms
Showing 705-736 of 1801 terms
GRC vs Operations
The distinction between GRC's oversight-and-assurance role and the operational teams that actually run controls, GRC sets policy, assesses risk, and verifies, while operations owns and performs the day-to-day security work.
A common confusion is what GRC does versus what operations does. GRC (a second-line function) defines policy, assesses risk, maps and tests controls, and provides assurance, but it does not run the firewalls, patch the servers, or respond to incidents; first-line operational teams do that. Clarifying GRC vs operations prevents GRC from being mistaken for hands-on security work and frames it correctly as governance, oversight, and advisory.
Introduced in: GRC Analyst Fundamentals
Examples
- GRC testing whether a control works, while operations runs it.
- Operations patching servers, while GRC verifies patching compliance.
- GRC setting policy, with operational teams implementing it.
No related terms linked yet.
