GRC Engineering Club · Atlanta chapter
GRC Terms Explorer Explore the terms behind policies, controls, audits, privacy, and AI governance. The Atlanta chapter of the GRC Engineering Club connects each concept to a practical example, related terms, and further reading.
A few good places to start 6 terms shown · 48 in the collection
Reset Browse all 48↓
TERM GRC
Policy An organization’s high-level direction or expectation for how people and systems should operate.
Explore Policy ↓ Why it matters It gives teams a shared requirement to turn into practical work.
In the wild An access policy says that privileged access must use MFA.
Source & framework context Organizational policy in the Building Blocks lesson; usage differs by source.
Related terms Keep learning with the Atlanta chapter TERM GRC · Security · SOC 2
Control A safeguard or activity used to address risk and support an objective or requirement.
Explore Control ↓ Why it matters A written intention needs an operating practice behind it.
In the wild An identity system blocks privileged sign-in unless MFA succeeds.
Source & framework context Building Blocks uses “control” for a safeguard that operates. Frameworks may also use the word for a stated control objective or requirement.
Related terms Keep learning with the Atlanta chapter TERM GRC · SOC 2
Evidence Information used to support a conclusion about what happened or how something works.
Explore Evidence ↓ Why it matters Reviewers need relevant, reliable information for the question and period they are checking.
In the wild A dated access-review record shows who reviewed accounts and what they removed.
Source & framework context Practitioner explanation connected to Building Blocks and the Field Guide; sufficiency depends on the evaluation.
Related terms Keep learning with the Atlanta chapter TERM GRC · Security
Risk Uncertainty that could affect an objective, such as the possibility and consequences of unauthorized access.
Explore Risk ↓ Why it matters It helps teams decide which problems deserve attention and resources.
In the wild A team considers how stolen administrator credentials could interrupt its service.
Source & framework context Security-focused illustration; risk definitions and rating methods depend on the source and organizational context.
Related terms Keep learning with the Atlanta chapter TERM ISO 27001 · Security
Information security management system The organized way an organization manages information-security risk and improves its practices.
Explore Information security management system ↓ Why it matters It connects security work to leadership, objectives, and recurring review.
In the wild An owner coordinates risk work, control checks, leadership decisions, and improvement actions.
Source & framework context ISO/IEC 27001:2022 describes requirements for an information security management system.
Related terms Keep learning with the Atlanta chapter TERM GRC · Security · Privacy
Secure Controls Framework A catalog that connects cybersecurity and privacy controls with many sources of requirements.
Explore Secure Controls Framework ↓ Why it matters It helps practitioners organize overlapping expectations around common controls.
In the wild A team follows one access control’s mappings to investigate several customer requirements.
Source & framework context SCF common-controls approach; mappings do not establish compliance by themselves.
Related terms Keep learning with the Atlanta chapter Search and filters need JavaScript. Start with the cards above or continue in the Field Guide .