GRC Engineering Club · Atlanta chapter

GRC Terms Explorer

Explore the terms behind policies, controls, audits, privacy, and AI governance. The Atlanta chapter of the GRC Engineering Club connects each concept to a practical example, related terms, and further reading.

A few good places to start

6 terms shown · 48 in the collection

TERMGRC

Policy

An organization’s high-level direction or expectation for how people and systems should operate.

Explore Policy

Why it matters

It gives teams a shared requirement to turn into practical work.

In the wild

An access policy says that privileged access must use MFA.

Source & framework context

Organizational policy in the Building Blocks lesson; usage differs by source.

Related terms

Keep learning with the Atlanta chapter

TERMGRC · Security · SOC 2

Control

A safeguard or activity used to address risk and support an objective or requirement.

Explore Control

Why it matters

A written intention needs an operating practice behind it.

In the wild

An identity system blocks privileged sign-in unless MFA succeeds.

Source & framework context

Building Blocks uses “control” for a safeguard that operates. Frameworks may also use the word for a stated control objective or requirement.

Related terms

Keep learning with the Atlanta chapter

TERMGRC · SOC 2

Evidence

Information used to support a conclusion about what happened or how something works.

Explore Evidence

Why it matters

Reviewers need relevant, reliable information for the question and period they are checking.

In the wild

A dated access-review record shows who reviewed accounts and what they removed.

Source & framework context

Practitioner explanation connected to Building Blocks and the Field Guide; sufficiency depends on the evaluation.

Related terms

Keep learning with the Atlanta chapter

TERMGRC · Security

Risk

Uncertainty that could affect an objective, such as the possibility and consequences of unauthorized access.

Explore Risk

Why it matters

It helps teams decide which problems deserve attention and resources.

In the wild

A team considers how stolen administrator credentials could interrupt its service.

Source & framework context

Security-focused illustration; risk definitions and rating methods depend on the source and organizational context.

Related terms

Keep learning with the Atlanta chapter

TERMISO 27001 · Security

Information security management system

The organized way an organization manages information-security risk and improves its practices.

Explore Information security management system

Why it matters

It connects security work to leadership, objectives, and recurring review.

In the wild

An owner coordinates risk work, control checks, leadership decisions, and improvement actions.

Source & framework context

ISO/IEC 27001:2022 describes requirements for an information security management system.

Related terms

Keep learning with the Atlanta chapter

TERMGRC · Security · Privacy

Secure Controls Framework

A catalog that connects cybersecurity and privacy controls with many sources of requirements.

Explore Secure Controls Framework

Why it matters

It helps practitioners organize overlapping expectations around common controls.

In the wild

A team follows one access control’s mappings to investigate several customer requirements.

Source & framework context

SCF common-controls approach; mappings do not establish compliance by themselves.

Related terms

Keep learning with the Atlanta chapter