| GRC area | Frameworks you should know particularly well |
|---|---|
| Risk management | NIST CSF, NIST 800-53, ISO 27001, DORA, NIS2 |
| Access control / IAM | NIST 800-53, ISO 27002, PCI DSS, SOC 2 |
| Security policies | ISO 27001/27002, NIST, SOC 2 |
| Incident management | NIST, ISO 27002, PCI DSS, NIS2, DORA |
| Business continuity / DR | ISO 27002, NIST 800-53, DORA, NIS2 |
| Vulnerability management | NIST 800-53, ISO 27002, PCI DSS, NIS2 |
| Logging / monitoring | NIST 800-53, ISO 27002, SOC 2, PCI DSS |
| Data protection / privacy | GDPR, UK GDPR, ISO 27002, NIST 800-53 |
| Third-party risk | ISO 27002, NIST 800-53, SOC 2, DORA, NIS2 |
| Security awareness | NIST 800-53, ISO 27002, PCI DSS, NIS2 |
| Cryptography | ISO 27002, NIST 800-53, PCI DSS, GDPR, NIS2 |
| Secure development | NIST 800-53, ISO 27002, PCI DSS, NIS2, EU AI Act |
| Audit/evidence/testing | ISO 27001, SOC 2, PCI DSS, NIST 800-53 |
| AI governance | EU AI Act |
| Financial operational resilience | DORA |
The key GRC skill you are building
You should eventually be able to take something like:
GDPR Article 32 → Security requirement → ISO 27001/27002 control → NIST control → Evidence → Test → Gap → Remediation
or:
DORA Article 6 → ICT risk requirement → ISO 27001 control → NIST control → Evidence → Testing → Gap → Remediation
That mapping/crosswalk ability is much more valuable to you than simply memorizing framework names.