Governance Risk Compliance
控制框架
A structured set of governance, risk, and compliance (GRC) policies, processes, and controls aligned to industry standards for managing and mitigating organizational risks.
Quick answer: A structured set of governance, risk, and compliance (GRC) policies, processes, and controls aligned to industry standards for managing and mitigating organizational risks.
This term page is part of the Protermify Cybersecurity glossary and is published as static HTML for fast indexing and clear language coverage.
Definition
A structured set of governance, risk, and compliance (GRC) policies, processes, and controls aligned to industry standards for managing and mitigating organizational risks.
Operational example
Our organization implemented a NIST-based control framework to meet compliance requirements and manage cyber risk holistically.
Localized example
我们组织实施了基于NIST的控制框架,以满足合规要求并整体管理网络风险。
Definition language
English reference definition
Source
ISO 27001, NIST Cybersecurity Framework, MITRE ATT&CK
Exam relevance
- CISSP
- CompTIA Security+
- CEH
Target audience
- SOC Analysts
- Security Engineers
- Incident Responders