惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 叶小钗
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
酷 壳 – CoolShell
酷 壳 – CoolShell
月光博客
月光博客
人人都是产品经理
人人都是产品经理
宝玉的分享
宝玉的分享
博客园 - 司徒正美
WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
罗磊的独立博客
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss
T
Tailwind CSS Blog
A
About on SuperTechFans
Apple Machine Learning Research
Apple Machine Learning Research
L
LangChain Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
V
Visual Studio Blog
S
SegmentFault 最新的问题
Google DeepMind News
Google DeepMind News
博客园 - 聂微东

Black Hills Information Security, Inc.

Bad Habits: An ANTISOC Operation Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other How to Identify and Exploit New Vulnerabilities Swapper – A Pure Regex Match/Replace Burp Extension A Practical Guide to BloodHound Data Collection Network Engineering Basics Signed, Trusted, and Abused: Proxy Execution via WebView2 Getting Started In Pentesting – Advice From The BHIS Pentest Lead Cloud Security: Tips and Resources for Securing the Cloud Lessons From A Chatbot Incident How to Lead Effective Tabletops The “P” in PAM is for Persistence: Linux Persistence Technique Malware Analysis: How to Analyze and Understand Malware OSINT: How to Find, Use, and Control Open-Source Intelligence What to Do with Your First Home Lab When the SOC Goes to Deadwood: A Night to Remember Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions Common Cyber Threats Finding the Right Penetration Testing Company Deceptive-Auditing: An Active Directory Honeypots Tool The Curious Case of the Comburglar How to Set Smart Goals (That Actually Work For You) Inside the BHIS SOC: A Conversation with Hayden Covington Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation Why You Got Hacked – 2025 Super Edition Abusing Delegation with Impacket (Part 2): Constrained Delegation Abusing Delegation with Impacket (Part 1): Unconstrained Delegation GoSpoof – Turning Attacks into Intel Model Context Protocol (MCP) Bypassing WAFs Using Oversized Requests
Understanding GRC: How to Navigate Risks and Compliance S...
BHIS · 2026-03-11 · via Black Hills Information Security, Inc.

, , , , ,

written by Sean Reilly || Guest Author

This article was originally published in the InfoSec Survival Guide: Green Book. Find it free online HERE or order your $1 physical copy on the Spearphish General Store.

“GRC” isn’t all witchcraft and administrative nonsense — it’s the core that drives security initiatives, connects security spend to business outcomes, and powers a well-functioning security team.

GRC in a Nutshell

  • Stands for Governance, Risk Management, and Compliance.
  • Translates business risk appetite into a target risk profile, creates policies and mandates controls to achieve that risk, measures compliance, and gets business agreement on residual risk.
  • Helps businesses understand security’s activities, justifies spend, and enables riskinformed decisions.
  • The goal is to manage risk, not eliminate it completely.

Measuring Risk – Numbers or Opinions?

There are 2 core approaches to assessing risk:

  • Quantitative Assessment: Measuring risk in actual $$ values or similar quantifiable measures. Challenging, requiring a mature business and security program.
  • Qualitative Assessment: Rating risk on a scale (e.g., 1-5) through expert opinions and measurable tests. Easier — therefore, more common.

Most frameworks consider impact and likelihood, often including assets (determining impact), vulnerabilities (determining likelihood), and threats. GRC considers a broad range of risks, including tech flaws, insider threats, natural disasters, and external market conditions.

Managing Risk

Risk management is what GRC is all about. GRC defines policies and controls based on business risk tolerance, assesses implementation, and identifies residual risk.

When risk is outside tolerance, we typically either:

  • Remediate the source of the risk – Address the cause or vulnerability, often with temporary risk acceptance during the fix.
  • Accept the risk as an exception – Document and accept isolated exposures.
  • Adjust the target risk profile – Reevaluate and adjust overall tolerance.

Decisions are based on both impact and current or potential mitigations. Risks over agreed thresholds will be directly communicated to or signed off by business stakeholders.

Interested in Getting Into GRC?

Become the driving force behind security and a key interface between business and security leaders.

Educational Background

A bachelor’s degree is generally required. Focus on analytical, technical, or risk-oriented fields like engineering, computer science, or business administration. Combine business acumen with technical skills.

Early Career & Company Selection

Good initial roles include:

  • Junior Auditor / Analyst
  • IT Helpdesk or Systems Support: Though not “GRC,” these roles build analytical thinking and communication abilities while sharpening tech skills.

Look for employers in regulated industries like finance and healthcare, who need regular compliance assessments. Also, consider consulting firms (e.g., the “Big 4” – Deloitte, KPMG, PwC, and EY), who employ small armies of auditors and have career tracks from junior analyst to team lead.

Certifications

Certifications can help, but experience trumps all. Here are some helpful ones that won’t break the bank:

  • CompTIA Security+
  • ISACA CISA

As you gain experience, consider:

  • ISACA CRISC
  • ISC2’s CISSP or ISACA’s CISM – both are management focused
  • Pursue other niche certs only if you want to focus in a specific area

Helpful GRC Resources

NIST

ISO27001

PCI-DSS

HIPAA

ITIL & COBIT



Explore the Infosec Survival Guide and more… for FREE!

Get instant access to all issues of the Infosec Survival Guide, as well as content like our self-published infosec zine, PROMPT#, and exclusive Darknet Diaries comics—all available at no cost.

You can check out all current and upcoming issues here: https://www.blackhillsinfosec.com/prompt-zine/