2.1.5. Governance, Risk, and Compliance (GRC)
💡 First Principle: GRC names three activities that must work together for an organization's compliance posture to mean anything — governance sets the policies and who's accountable for them, risk management identifies and prioritizes what could go wrong, and compliance verifies that reality actually matches the policy — and removing any one of the three breaks the whole cycle.
Without governance, there's no agreed-upon policy to measure against. Without risk management, effort gets spent evenly across all controls instead of prioritized toward the highest-impact gaps. Without compliance verification, an organization has policies and priorities but no evidence they're actually being followed. Microsoft Purview's Compliance Manager (Phase 5) is essentially a GRC tool: it holds assessments (governance), highlights gaps by impact (risk), and tracks completed improvement actions with a score (compliance verification) — all three activities in one workflow.
⚠️ Exam Trap: GRC is not one activity with three names — it's three distinct, interdependent activities. A scenario testing "which GRC component is missing" expects you to identify specifically whether it's a policy gap, a prioritization gap, or a verification gap.
Reflection Question: An organization has clear security policies and a documented risk register, but has never audited whether employees actually follow the policies. Which GRC component are they missing?