GRC is a great on ramp into cybersecurity, often overlooked, and confusing as to what it actually is.
Join Gerald Auger of Simply Cyber for coffee and a unbridled discussion around GRC. Gerry will share his thoughts an then take as much Q&A as you can handle.
Simply Cyber's mission is to help purpose driven professionals make and and take a cybersecurity career further, faster.
π± Social Media
LinkedIn: LinkedIn: geraldauger
Twitter: Twitter: Gerald_Auger
YouTube: geraldauger
Discord: Discord: discord
Twitch: Twitch: gerald_auger_simplycyber
π₯ My Curated Website of Free Cyber Resources
https://SimplyCyber.io
GRC is a great on ramp into cybersecurity, often overlooked, and confusing as to what it actually is.
Join Gerald Auger of Simply Cyber for coffee and a unbridled discussion around GRC. Gerry will share his thoughts an then take as much Q&A as you can handle.
Simply Cyber's mission is to help purpose driven professionals make and and take a cybersecurity career further, faster.
π± Social Media
LinkedIn: LinkedIn: geraldauger
Twitter: Twitter: Gerald_Auger
YouTube: geraldauger
Discord: Discord: discord
Twitch: Twitch: gerald_auger_simplycyber
π₯ My Curated Website of Free Cyber Resources
https://SimplyCyber.io
00:00 π― Gerald Auger introduces the topic of GRC (Governance, Risk, and Compliance) in cybersecurity and aims to answer questions about it in the video.
01:11 π’ GRC (Governance, Risk, and Compliance) is a crucial aspect of cybersecurity and offers a great career path, allowing professionals to engage with the business side of an organization.
05:48 π Compliance Analysts focus on checking whether specific controls are in place, while Risk Analysts assess the likelihood and impact of potential risks, enabling a smooth career progression in the GRC field.
08:42 π§© GRC fits into an organization under the CISO, handling governance, policy, procedures, and audit aspects, while Security Operations (SecOps) handles incident response and blue team functions.
10:47 π Entry-level GRC roles, like Compliance Analyst positions, are a great on-ramp into cybersecurity, especially for individuals without an IT background. Federal IT contractors often offer entry-level GRC positions and are open to training candidates.
19:41 πΌ CMMC (Cybersecurity Maturity Model Certification) is becoming crucial for organizations working with the government, and being certified or familiar with it can be a valuable skill for cybersecurity professionals.
21:05 π Recommended certifications for GRC Analysts include CISA (Certified Information Systems Auditor) and HIPAA-related certifications.
22:01 π‘οΈ GRC roles require some basic technical knowledge, such as understanding networking and operating systems, to ensure effective audits and assessments.
23:24 π NIST (National Institute of Standards and Technology) Cybersecurity Framework is a great starting point for learning GRC standards and best practices.
24:22 πΌ Practical Enterprise Risk Assessment course by the speaker is a resource for learning compliance auditing and risk assessment in GRC.
25:51 π Excellent written and verbal communication skills are essential for GRC Analysts to effectively communicate with the organization and information security teams.
29:51 π‘ NIST CSF (Cybersecurity Framework) and ISO 27001 are recommended standards for GRC, with CSF having more community collaboration and industry practice behind it.
30:06 π CMMC (Cybersecurity Maturity Model Certification) is a subset of controls within NIST CSF, and compliance with CSF would cover the requirements of CMMC.
34:10 π NIST Special Publications 800 series provides comprehensive documentation on various cybersecurity topics, including risk assessments and supply chain risk management.
39:03 π£ Effective communication skills are critical for GRC Analysts to bridge the gap between information security and the organization's business needs.
41:48 βοΈ Cloud security and identity and access management are in-demand areas within cybersecurity, making certifications in these fields valuable for GRC-focused roles.
42:31 π GRC (Governance, Risk, and Compliance) is a great entry point into cybersecurity and offers an easier on-ramp.
43:12 π Recommended certifications for GRC include CMMC certified practitioner, ISACA CISA, and industry-specific compliance certifications.
43:41 π GRC roles do not require a minimum certification, making it a flexible and forgiving career path.
45:34 π‘ Transitioning from a network security role to GRC can involve integrating GRC-type activities into your current role to showcase expertise and interest.
46:59 π Before conducting any assessment, create an audit plan, identify key stakeholders, and schedule focused interviews to gather necessary information.
51:14 π Familiarize yourself with risk management frameworks like MITRE ATT&CK and NIST 800-171 to enhance your understanding of GRC processes.
52:10 π Don't be overly attached to risk assessments, as some organizations may not prioritize cybersecurity until they face a significant incident.
57:35 π
Made with HARPA AI