GRC

Abbreviation · Security & Infosec

Definitions

  1. Short for governance, risk, and compliance, the organizational framework used to manage policies, control requirements, audits, and risk decisions in a consistent way. GRC programs help tie technical security work to business ownership and regulatory obligations.

    In plain English: A shorthand for the work of managing security policies, risks, and compliance.

    Example: "The GRC team tracked evidence collection while engineering implemented the missing controls."

Related Terms