GRC STEPS Governance Risk Compliance Policies Controls Frameworks Auditing & Evidence Reporting Who makes decisions and sets rules? What can go wrong, and how serious is it? What laws, regulations, and standards must be followed? What rules does the organization create? What safeguards are put in place? NIST, ISO 27001, CIS, COBIT, etc. How do you prove controls actually work? How do you communicate risks, gaps, and compliance to management? Governance Policies, roles, accountability and security oversight to support business objectives. Risk Management Identify, assess, treat and monitor risks that could impact the organisation. Compliance Meet regulatory, legal and contractual requirements with proper evidence. Cybersecurity Implement controls and processes to protect systems, data and business operations.