Frameworks
Cybersecurity and GRC (Governance Risk and Compliance) often crosses paths, Cyber Security and GRC rely on several industry frameworks that can either be ahdered too and audited against or used as guidance and building blocks.
If you’re in a regulated industry its likely you will NEED to have one of these.
SOC2
Based on Trust Service Criteria
- Security
- Availability
- Processing Integrity
- Confidentiality
- Privacy
“Service providers cannot conduct self-audits, nor can their clients. To ensure impartiality, any organization handling customer data in the cloud has the option to pursue an independent SOC audit. This audit involves comprehensive evaluations of essential departments and processes that handle sensitive data.”