Cybersecurity
Governance, risk and compliance
Governance is where security stops being a technical opinion and becomes an organisational decision with a name against it. Risk assessment ranks what could go wrong, policy states what the organisation will do about it, and compliance and audit prove that it did. People from IT often dismiss all this as paperwork, then discover that this is where the money for their own projects gets allocated.
Why this topic exists: Policies, risk assessment, frameworks (NIST CSF, ISO 27001) and audit are the management half of the field: CISSP domain 1 (16 %), CISM, CISA, Security+ Program Management (20 %).
Governance, risk and compliance forms the management half of security. Its practitioners seldom configure systems; they decide what the organisation is trying to protect, how much risk it will carry, which rules bind it, and how it will demonstrate that it has done what it claims. Job titles vary (risk analyst, information security officer, compliance manager, IT auditor), but the work comes down to turning technical uncertainty into decisions someone senior signs, and then checking those decisions were carried out.
Frameworks give the conversation a shape
Most GRC work is organised around a framework, because a framework lets a board, an auditor and an engineer point at the same page. The NIST Cybersecurity Framework is the most widely used free one. Its 2.0 revision added Govern as a sixth function beside Identify, Protect, Detect, Respond and Recover, which made strategy, roles and supplier oversight part of security itself rather than a preamble. ISO/IEC 27001 is the certifiable alternative: an organisation builds a management system to its requirements and an accredited auditor confirms it, which is why the standard turns up in so many supplier contracts. Regulations such as the GDPR sit on top of either and add duties that are not optional.
Underneath all of them lies risk assessment: naming the assets, the threats to them and the likely harm, then deciding for each risk whether to reduce, transfer, avoid or accept it. Controls are chosen to fit that decision, never the other way round.
Three senior credentials, three different chairs
- CISSP spans all eight of its domains at the depth a manager needs, and weights security and risk management most heavily. It suits the person who designs a security programme and must defend it technically.
- CISM is aimed at whoever answers for running that programme day to day, and it examines governance and incident handling from the manager's desk rather than the engineer's.
- CISA certifies the auditor, who asks whether controls exist, operate and can be evidenced. It is the credential for people who check other people's security.
- Security+ ends with a domain on programme management and oversight, a lighter first taste for anyone not yet eligible for the three above, all of which require years of experience.
The beginner's error runs in two directions. Technical people treat GRC as box-ticking and are surprised when a well-argued risk register moves more budget than any demonstration. People who enter GRC without technical grounding write policies nobody can implement and run audits that check documents instead of systems. The strongest practitioners have spent time on the other side: an auditor who has run a server knows which evidence is real and which was produced for the visit. Security awareness is the neighbouring topic, because training staff is a governance obligation, and incident response shows what a governed reaction to a real event looks like.
Next to this topic
- Security fundamentalsEvery blueprint opens here: the CIA triad, control types and the threat, vulnerability and risk vocabulary (SY0-701 General Security Concepts, 12 %; CISSP domain 1).
- Network securityFirewalls, segmentation, IDS/IPS, VPNs and zero trust are where most defensive work starts (CISSP Communication and Network Security, 13 %; Network+ and CCNA security domains).
- Identity and access managementWho may do what is its own discipline with its own exam (SC-300) and a full CISSP domain (13 %): authentication, MFA, SSO, directories and least privilege.
- CryptographyEncryption, hashing, keys and PKI underlie every other topic; the exams test them as applied choices, not maths (CISSP Security Architecture and Engineering; SY0-701 domain 1).
- Threats and attacksThe second-largest Security+ domain (Threats, Vulnerabilities and Mitigations, 22 %; only Security Operations weighs more): malware, phishing, social engineering, ransomware and the attack techniques defenders must recognise.
- Security operationsMonitoring, detection and the SOC are the largest Security+ domain (28 %) and the whole of SC-200 and CySA+: SIEM, logging, alert triage, threat hunting.
- Penetration testing and ethical hackingAuthorised attack as a profession: scoping, reconnaissance, exploitation, reporting (PTES; PenTest+ and CEH). Also the most-searched security topic on the course side.
- Application securityA large share of breaches begins in software: secure design, secure build, security testing and the OWASP Top 10 (OWASP SAMM; CISSP Software Development Security, 10 %).
- Cloud securityShared responsibility, cloud identity and posture management are tested in every cloud exam (SAA-C03 Design Secure Architectures, 30 %) and in SC-900; the cloud silo owns the platforms, this topic owns the defence.
- Security awareness for everyoneMost incidents start with a person, not a port: what every employee and freelancer must know about phishing, passwords, MFA, backups and updates (NICE Oversight and Governance; the management side of every blueprint).
Concepts to know
Glossary entries with the reason each one matters here.
- Security Risk Assessment
The method governance runs on.
- Least Privilege
The policy most audits check first.
- Incident Response
Regulators ask for the plan before the incident.
Certifications that test it
Vendor exams and free certificates; facts, cost and the preparation path are on each page, and the certifications hub has them all.
- ISC2 · CISSPCertified Information Systems Security Professional (CISSP)Security and risk management is its first domain.
- ISACA · CISMCertified Information Security Manager (CISM)The management-side certification.
- ISACA · CISACertified Information Systems Auditor (CISA)The audit-side certification.
- CompTIA · SY0-701CompTIA Security+Programme management and oversight domain.
Frequently asked
- Is GRC a technical career?
- Partly. Daily work is more writing, interviewing and deciding than configuring, but the best practitioners understand the systems they assess. Someone who can read a firewall rule set or a cloud access policy will produce findings that engineers respect and act on.
- CISM or CISSP?
- CISM if your path is managing a security programme and you want the credential built for that chair. CISSP if you want wider recognition and a broader technical span, for example as an architect or a security lead who still reviews designs. Both require years of experience, so the choice usually follows the job you already hold.
- What is the difference between NIST CSF and ISO 27001?
- The NIST framework is a free, flexible structure for describing and improving a security programme, with no certificate at the end. ISO/IEC 27001 specifies a management system that an accredited body can certify, which is why customers and contracts ask for it. Many organisations use the NIST functions to plan the work and ISO certification to prove it.
Courses in the directory
117 courses are filed here; the top 6 by our ranking, details and the provider link on each course page.
Last reviewed 26 September 2026 · Getting Digital
