From the course: Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Cert Prep by Microsoft Press

Unlock this course with a free trial

Join today to access over 24,000 courses taught by industry experts.

Describe governance, risk, and compliance (GRC) concepts

Describe governance, risk, and compliance (GRC) concepts

- Understanding security and compliance concepts, let's describe compliance concepts. Compliance refers to the process of adhering to a set of rules or regulations set by a governing body or industry. These rules and regulations are put in place to ensure that the organizations are operating in a manner that is safe, secure, and ethical. Compliance helps organizations to avoid legal and financial penalties, and to maintain the trust of their customers and stakeholders. In the context of information technology compliance refers to the process of ensuring that an organization's IT systems and processes meet the requirements set by various regulatory bodies. Some common examples of IT compliance regulations include FedRAMP, ISO 27001, and the NIST SP 800 series. Each of these regulations has its own set of requirements and controls that organizations must implement in order to be considered compliant. Some common…

Contents