GRC · Playbook

GRC Playbook

A practical guide to proportionate control, not performative control. Standards describe what good looks like. Frameworks describe how you organise risk, controls and evidence. Keep those ideas separate so you do not bury a team in logos, or leave a regulated service with no defensible story.

MAP-01 Control maps

MAP-01

Control & risk maps

Know which framework answers which question before you mandate it.

Every framework below answers a different question. Mandates and standards set floors. Management systems organise how you run security and risk. Control catalogues give you building blocks. Mixing them up is the fastest way to invent parallel paperwork that delivery cannot operate.

Maps you will actually use

MapAnswersShape
Orange BookHow should risk be governed in UK government?Principles, appetite, culture, assurance
ISO 27001How do we run an information security management system?ISMS requirements · Annex A controls
NIST CSF / NCSC CAFHow do we talk cyber outcomes with boards and engineers?Identify to Recover · outcomes-based CAF
UK GDPR / DPA 2018What must we do with personal data?Principles, lawful basis, rights, DPIA
Three Lines ModelWho owns, who oversees, who assures independently?1st · 2nd · 3rd line accountability
GovS / functional standardsWhat is mandated for government delivery and security?Shall / should clauses across functions

Choose in practice

  • Board risk conversation: Orange Book principles and a written appetite statement first.
  • Certifiable ISMS or supplier assurance: ISO 27001 as the management system spine.
  • Engineering cyber outcomes: NCSC CAF or NIST CSF language, mapped to controls you already run.
  • Personal data in a digital service: UK GDPR principles and DPIA before build hardens.
  • Confused ownership of control failures: redraw Three Lines before adding another policy PDF.
If a framework never changes a control decision or an appetite call, stop collecting it as a logo.