GRC · Cheatsheet

GRC Cheatsheet

A short reminder sheet that pairs with the full playbook. Use it in a meeting when you need the next move, not a long read. Tap “What this means” on any card if a heading is unclear.

Civil Service specific Universal any sector Both
MAP-01

Control maps

Both

Govern: Orange Book · Three Lines · GovS

ISMS / cyber: ISO 27001 · NIST CSF · NCSC CAF

Data: UK GDPR · DPIA

Pick the lightest map that answers today's decision.

RL-01

The role

Both

You own the control story. Delivery operates. Audit opines.

Run daily:

  • Which risk reduced?
  • Who operates tomorrow?
  • Would evidence survive audit?
RK-01

Risk craft

Universal
  • Future event + cause + impact
  • Treatment with owner and date
  • Accepted risks expire or renew
  • Issues are not risks
CT-01

Proportionate controls

Universal

Map control to risk, operator, evidence, test

Prefer pipeline and identity automation

Detective controls need playbooks

Consolidate duplicates

AS-01

Three lines

Both

1st: own and operate

2nd: challenge and thematic assure

3rd: independent opinion

Do not let second line operate what it assures

DP-01

UK GDPR

Civil Service
  • Lawful basis and purpose before build hardens
  • DPIA actions into backlog
  • Minimisation and retention challenged
  • Know the breach clock
EV-01

Audit readiness

Both

Evidence in the flow of work

Control note: risk, operator, location, last tested

SoA maps to real controls

Findings need cause + verify

EX-01

Exceptions

Universal

Timebox + compensating control + approver

Material exceptions visible to SRO

Track exception age as a metric

IN-01

Tone & ask

Universal

Team: concrete control path

SRO: residual risk + options + recommendation

Drop "security says no". Name the risk and the call.

PT-01

Digital partnership

Both
  • Join discovery and architecture early
  • Publish a fast-path review SLA
  • One shared material-risk list with DM/PM
  • Keep assessment evidence warm
GV-03

Troubleshooting: symptom to first move

Universal
!Checkbox compliance: trace top five risks to operated controls or mark gaps
!Control theatre: move one control into the pipeline or live ceremony
!Audit scramble: name continuous evidence locations; kill screenshot week
!Forever exceptions: timebox all; escalate aged to appetite owner
!DPIA theatre: convert open risks into backlog items with owners
!Watermelon RAG: thank the next early red; fix the incentive
REF-01

Field reference

Both

One-minute checklist when the control story is on fire:

  • Name the biggest residual risk, one sentence
  • Ownership, design, evidence, appetite or data?
  • Decision that unlocks most reduction, who owns it
  • Brief SRO / appetite owner before distorted versions
  • Protect delivery from noise while you sort it

Maps: Orange Book, ISO 27001, CAF, Three Lines

Data: UK GDPR, DPIA, DPA 2018

Craft: residual risk, SoA, compensating control

Govern: RAID, RAG, SRO, exception age