QuestionQ6

Managing the Data Protection Environment

Which processes support the planning and implementation of security controls while ensuring adherence to internal and external policies?

Explanation

Governance, Risk, and Compliance (GRC) coordinates governance, risk management, and compliance activities so that security controls can be planned, implemented, assessed, and tracked against organizational policies and external requirements. NIST identifies GRC as governance, risk, and compliance, and its Risk Management Framework includes security-control selection, implementation, assessment, authorization, and monitoring.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!