{"id":1129,"date":"2026-09-10T06:59:55","date_gmt":"2026-09-10T06:59:55","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1129"},"modified":"2026-09-10T06:59:55","modified_gmt":"2026-09-10T06:59:55","slug":"grc","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/grc\/","title":{"rendered":"GRC"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: GRC (GOVERNANCE, RISK AND COMPLIANCE)\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">GRC is the operating layer that decides who owns security risk, how that risk is measured, and how you prove to an outsider that both things actually happen.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Compliance<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>GRC stands for governance, risk and compliance. Governance sets who decides and who answers for it. Risk identifies what could go wrong and what you are doing about each item. Compliance demonstrates the arrangement to auditors and regulators. It is a management discipline rather than a product category, which is why buying a tool rarely fixes an audit finding on its own.<\/p>\n<\/div>\n\n<p>The three parts fail together. A risk register nobody owns is a spreadsheet. Controls with no risk behind them are guesswork. Evidence with no governance above it proves activity, not accountability.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#three\">The three parts of GRC<\/a><\/li>\n    <li><a href=\"#produces\">What a GRC programme produces<\/a><\/li>\n    <li><a href=\"#versus\">What GRC is not<\/a><\/li>\n    <li><a href=\"#india\">GRC under Indian regulation<\/a><\/li>\n    <li><a href=\"#osto\">How Osto handles GRC<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"three\">The three parts of GRC<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 204\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"The three parts of GRC: governance, risk and compliance, and how they feed each other.\">\n  <defs><marker id=\"grcA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"14\" y=\"28\" width=\"230\" height=\"82\" rx=\"14\" fill=\"#e9ecfa\"\/>\n  <text x=\"129\" y=\"55\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#4a52a8\">Governance<\/text>\n  <text x=\"129\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Who decides, who is accountable,<\/text>\n  <text x=\"129\" y=\"91\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">which policies apply<\/text>\n  <line x1=\"248\" y1=\"69\" x2=\"266\" y2=\"69\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#grcA)\"\/>\n\n  <rect x=\"272\" y=\"28\" width=\"216\" height=\"82\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"380\" y=\"55\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#ffffff\">Risk<\/text>\n  <text x=\"380\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">What could go wrong, how<\/text>\n  <text x=\"380\" y=\"91\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">likely, and what you chose to do<\/text>\n  <line x1=\"492\" y1=\"69\" x2=\"510\" y2=\"69\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#grcA)\"\/>\n\n  <rect x=\"516\" y=\"28\" width=\"230\" height=\"82\" rx=\"14\" fill=\"#e3f0e9\"\/>\n  <text x=\"631\" y=\"55\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#3a6f5d\">Compliance<\/text>\n  <text x=\"631\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Proof the controls exist and<\/text>\n  <text x=\"631\" y=\"91\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">operated, sampled by an auditor<\/text>\n\n  <line x1=\"631\" y1=\"116\" x2=\"631\" y2=\"132\" stroke=\"#4a52a8\" stroke-width=\"2\"\/>\n  <line x1=\"129\" y1=\"132\" x2=\"631\" y2=\"132\" stroke=\"#4a52a8\" stroke-width=\"2\"\/>\n  <line x1=\"129\" y1=\"132\" x2=\"129\" y2=\"146\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#grcA)\"\/>\n\n  <rect x=\"14\" y=\"154\" width=\"732\" height=\"42\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"180\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Audit findings feed back into governance. A programme with no return loop drifts within one cycle.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Part<\/th><th>Core question<\/th><th>Typical artefact<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Governance<\/strong><\/td><td>Who is accountable, and under what policy?<\/td><td>Approved policy set, defined roles, a security committee with minutes<\/td><\/tr>\n    <tr><td><strong>Risk<\/strong><\/td><td>What could go wrong, and what did we decide?<\/td><td>A <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">risk assessment<\/a> and a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-treatment-plan\/\">risk treatment plan<\/a> with named owners<\/td><\/tr>\n    <tr><td><strong>Compliance<\/strong><\/td><td>Can we prove it to somebody external?<\/td><td>Control mapping, evidence records, audit reports<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"produces\" class=\"c-sage\">What a GRC programme produces<\/h2>\n\n<p>Auditors do not assess intent. They sample artefacts. These are the ones that get pulled in almost every engagement.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Artefact<\/th><th>What it has to show<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Risk register<\/td><td>Each risk with an owner, a likelihood and impact rating, a decision, and a review date that has actually passed<\/td><\/tr>\n    <tr><td>Policy set<\/td><td>Approved, versioned, dated, and acknowledged by staff with a record of who read what<\/td><\/tr>\n    <tr><td>Control mapping<\/td><td>Every control tied to the framework clause it satisfies, so one control can answer several frameworks<\/td><\/tr>\n    <tr><td>Evidence records<\/td><td>Dated artefacts showing a control ran, not a screenshot taken the week of the audit<\/td><\/tr>\n    <tr><td>Access reviews<\/td><td>Recertification records from the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">IAM<\/a> cycle, with removals traceable to tickets<\/td><\/tr>\n    <tr><td>Vendor register<\/td><td>Third parties, what data each touches, and the assurance held on each one<\/td><\/tr>\n    <tr><td>Exception log<\/td><td>Accepted risks, who approved each, and when the acceptance expires<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The review date is what gets checked<\/p>\n  <p>A risk register with fifty entries and no review dates fails faster than one with twelve entries reviewed quarterly. Auditors look for evidence of a cycle, not volume. The same applies to policies: an approved policy nobody has revisited in three years is a finding, even when its contents are fine.<\/p>\n<\/div>\n\n<h2 id=\"versus\" class=\"c-plum\">What GRC is not<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Term<\/th><th>How it differs<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Compliance automation<\/td><td>Tooling that collects evidence and monitors controls. It serves the compliance third of GRC and does not set governance or make risk decisions<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">ISMS<\/a><\/td><td>The specific management system ISO 27001 certifies. An ISMS is one formalised expression of GRC, scoped to information security<\/td><\/tr>\n    <tr><td>Enterprise risk management<\/td><td>Risk across the whole business, including financial, legal and operational. Security risk is one input into it<\/td><\/tr>\n    <tr><td>Internal audit<\/td><td>An independent check on whether the programme works. It assesses the arrangement rather than running it<\/td><\/tr>\n    <tr><td>Security controls<\/td><td>The technical measures themselves. GRC decides which ones matter and proves they operated<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"india\" class=\"c-sky\">GRC under Indian regulation<\/h2>\n\n<p>Indian regulators have moved GRC from good practice to a named obligation, usually with a board-level reporting line attached.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Regime<\/th><th>What it expects<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>RBI IT Governance Directions<\/td><td>Board-approved IT and information security policy, a defined risk management framework, and a designated accountable officer for entities in the relevant NBFC layers<\/td><\/tr>\n    <tr><td>SEBI CSCRF<\/td><td>Governance structure, periodic risk assessment and compliance reporting scaled to the entity&#8217;s category<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a><\/td><td>Accountability for personal data, reasonable security safeguards, and breach intimation obligations<\/td><\/tr>\n    <tr><td>CERT-In Directions<\/td><td>Designated point of contact, log retention in Indian jurisdiction, and incident reporting within the stated window<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The common thread is proof of ownership. Every one of these asks a named person to answer for the programme, which is a governance requirement rather than a technical one.<\/p>\n\n<h2 id=\"osto\">How Osto handles GRC<\/h2>\n\n<p>The compliance third of GRC is where most of the manual effort goes, and it is the part Osto removes. Controls run inside the platform rather than across a dozen vendors, so evidence comes from the same system that enforces the control. That covers access and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">identity<\/a>, endpoint, cloud posture, web and API protection, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">logging<\/a>, mapped once and reused across 200 or more frameworks including <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>, HIPAA and the DPDP Act.<\/p>\n\n<p>Policies are generated in context rather than lifted from a template pack, and security awareness training runs in the platform with completion records attached. Governance and risk decisions stay with your team, as they have to. What changes is that the evidence backing those decisions assembles itself instead of being reconstructed the month before an audit.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Evidence that assembles itself<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto runs the controls and produces the records from one stack, mapped across 200 or more frameworks. Your team keeps the decisions. The paperwork stops being a project.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">200+ frameworks mapped &middot; Evidence from your own stack &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is GRC?<\/summary>\n  <p>Governance, risk and compliance: the discipline of setting who is accountable for security, deciding what to do about identified risks, and proving both to auditors and regulators. It is a management practice supported by tooling, not a product you install.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between GRC and compliance?<\/summary>\n  <p>Compliance is one third of GRC. It answers whether you can demonstrate controls to an outside party. Governance decides who owns the programme and under what policy, and risk decides which controls are worth having in the first place.<\/p>\n<\/details>\n\n<details>\n  <summary>Is an ISMS the same as GRC?<\/summary>\n  <p>Not quite. An information security management system is a formalised, certifiable expression of GRC scoped to information security, which is what ISO 27001 assesses. GRC is the broader practice and does not require certification to exist.<\/p>\n<\/details>\n\n<details>\n  <summary>Do small companies need a GRC programme?<\/summary>\n  <p>They need the substance rather than the apparatus. A named owner, a maintained risk register, an approved policy set and evidence that controls ran will satisfy an auditor at a twelve person company. A dedicated platform and a committee structure become worthwhile later.<\/p>\n<\/details>\n\n<details>\n  <summary>Who should own GRC in a startup?<\/summary>\n  <p>A named individual with the authority to accept risk, usually a founder, CTO or head of operations. Indian regulators including the RBI expect a designated officer for entities in scope. What matters to an auditor is that accountability sits with a person, not a team.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">ISMS<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">Risk Assessment<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-treatment-plan\/\">Risk Treatment Plan<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">IAM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>GRC is the operating layer that decides who owns security risk, how that risk is measured, and how you prove\u2026<\/p>\n","protected":false},"author":8,"featured_media":1130,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[534,533],"class_list":["post-1129","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-governance-risk-and-compliance","tag-grc"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1129","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1129"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1129\/revisions"}],"predecessor-version":[{"id":1131,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1129\/revisions\/1131"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1130"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1129"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1129"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1129"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}