Skip to main content

A Guide to Internal Governance, Risk, and Compliance

By Sagar Shah
1 minute
Last Updated February 25, 2021

Governance, risk, and compliance (GRC) programs

Developing or maintaining your organization’s governance, risk and compliance (GRC) program can seem like a daunting task, but fortunately there are many free or low cost solutions to help your organization get, well, organized! GRC is a strategy for managing your organization’s overall governance, enterprise risk management and compliance with regulations. GRC is how your organization aligns IT with business objectives, while managing risk and meeting compliance requirements.

Recognized cybersecurity frameworks

Not even sure where to start? Take the free version of RealCISO, which is a self-assessment tool closely aligned with NIST Cybersecurity Framework (CSF).

Data privacy frameworks and resources

  • NIST Privacy Framework
  • International Association of Privacy Professionals (IAPP)
    • IAPP is the largest and most comprehensive global information privacy community and resource. The IAPP website provides solid free content and more robust content for members

Risk management frameworks

Recent articles

Navigating Business Continuity and Disaster Recovery

The actions you take in the first 48 hours of a business disruption set the stage for recovery. Our guide to BCDR can help get you started.

Recent articles

Best Practices for Managing Cyber Risks in Open-Source Software

Discover key strategies to mitigate cybersecurity risks in open-source software such as vetting standards, compliance, and the role of cyber insurance.

Recent articles

A Guide to Mitigating Infostealer Malware

Threat actors are increasingly using infostealer malware to infiltrate and exploit digital systems. Here's what you need to know.