GRC ยท Frameworks

Frameworks & use cases for GRC

A framework is just a named way of working. Pick the lightest one that answers the question you have today. Each card below says what it is, when to use it, how a GRC practitioner might apply it, what goes wrong, and where to read more.

Cards start folded. Expand one at a time. The open card fills the width and the rest move below.

UK government risk

Orange Book

HM Treasury guidance on the principles of risk management in government, covering culture, appetite, governance and assurance.

ISMS

ISO/IEC 27001

International standard for establishing, implementing, maintaining and continually improving an information security management system, with Annex A control reference.

Cyber outcomes

NIST Cybersecurity Framework

Outcomes-based framework organised around Identify, Protect, Detect, Respond and Recover functions for cyber risk conversations.

Civil Service / UK cyber

NCSC Cyber Assessment Framework

NCSC outcomes-based framework used widely in UK government and critical sectors to assess cyber resilience.

Data protection

UK GDPR / DPA 2018

UK data protection law setting principles, lawful bases, individual rights and accountability duties for personal data processing.

Assurance

Three Lines Model

IIA model clarifying first-line ownership, second-line oversight and third-line independent assurance.

Control catalogue

CIS Critical Security Controls

Prioritised set of defensive controls commonly used as a practical starting catalogue for cyber hygiene.

IT governance

COBIT

ISACA framework for governing and managing enterprise information and technology, linking objectives to processes and practices.

Quantitative risk

FAIR

Factor Analysis of Information Risk: a model for analysing frequency and magnitude of loss to support more quantitative cyber risk decisions.

Service management

ITIL change enablement

ITIL practices for enabling changes with appropriate risk assessment, authorisation and review without freezing flow.

Civil Service standard

GDS Service Standard

Fourteen points on meeting user needs, providing a good service, and using the right technology, including privacy, security and openness expectations.

Civil Service standard

GovS functional standards

Mandated government functional standards suite (including project delivery and related functions) using shall/should language for governance expectations.

Sector control standard

PCI DSS

Payment Card Industry Data Security Standard for environments that store, process or transmit cardholder data.

Change

ADKAR

Individual change journey: Awareness, Desire, Knowledge, Ability, Reinforcement. Useful when control adoption depends on staff behaviour.