GRC

Governance, risk & compliance

The policies, audits, and regulations that prove security is actually managed.

22 terms

The regulations, standards, and internal processes that turn "we take security seriously" into something an auditor, insurer, or client can actually verify.

Showing 22 of 22
Cyber insurance Insurance covering breach response, legal fees, and lost income from an incident. Detect The CSF function for spotting attacks and compromises as they happen. NIST CSF 2.0 · Detect Due care vs. due diligence Research before acting, versus ongoing effort to maintain protection after. General Data Protection Regulation (GDPR) The EU's data protection law, giving individuals rights over their personal data. Govern The CSF 2.0 function for setting strategy, roles, and executive oversight. NIST CSF 2.0 · Govern Governance, risk & compliance (GRC) Setting direction, managing uncertainty, and meeting obligations, together. HIPAA Security Rule Sets specific safeguard requirements for protecting electronic health data. Identify The CSF function for cataloguing assets, data, and risk before protecting them. NIST CSF 2.0 · Identify Information security management system (ISMS) An ongoing program for managing information security, built on ISO/IEC 27001. ISO/IEC 27001 The international standard for building and certifying an ISMS. NIST Cybersecurity Framework 2.0 (NIST CSF 2.0) A framework built around six functions for structuring a cybersecurity program. NJ data breach notification New Jersey's rule requiring state police notice before customer notice. Payment Card Industry Data Security Standard (PCI DSS) Security requirements for any organization handling payment card data. Policy, standard & procedure A policy sets the rule, a standard sets the requirement, a procedure the steps. Protect The CSF function for putting safeguards in place to manage known risk. NIST CSF 2.0 · Protect Recover The CSF function for restoring normal operations after an incident. NIST CSF 2.0 · Recover Respond The CSF function for acting on an incident while it's actively happening. NIST CSF 2.0 · Respond Risk register A living list of identified risks, their impact, and who owns each one. Security awareness training Ongoing education that teaches staff to recognize phishing and handle data. SOC 2 An auditor's report on how well a service provider's security controls hold up. Third-party risk management (TPRM) Assessing the security risk vendors and contractors introduce to you. Vendor security questionnaire Standard questions used to assess a vendor's security before signing.