Most people picture cybersecurity as somebody at a keyboard watching alerts or breaking into a box. Somebody else decides what all of that work has to prove. That’s governance, risk and compliance, or GRC.
This post covers what the job is, the vocabulary it runs on, and the part that matters most: how one control goes from a line in a standard to evidence an assessor will accept.
What a GRC analyst actually does
A GRC analyst turns requirements into practice and then proves it. The requirement might come from a regulation, a contract, a framework the company chose, or its own leadership. The work is the same: figure out what’s being asked, check whether the organization actually does it, collect the proof, and track what’s missing until it’s fixed.
The titles vary. GRC analyst, compliance analyst, IT auditor, and in government and defense work, ISSO, or Information System Security Officer. An ISSO owns the security of a specific system: its documentation, its controls, and its authorization to operate.
It’s a real way into cyber for people who don’t want to live on the command line. It still rewards technical people, because the best GRC analysts can tell when a control only exists on paper.
Six terms every GRC analyst uses
- Control: a specific safeguard a framework requires. “Use multifactor authentication for network access” is a control.
- Evidence: proof the control is in place and working. A policy says you do it. Evidence shows that you do.
- SSP (System Security Plan): the document that describes a system, its boundary, and how each required control is implemented.
- POA&M (Plan of Action and Milestones): the list of controls that aren’t fully met yet, with an owner, a fix and a due date for each.
- Risk register: the running list of what could go wrong, how likely and how bad it would be, and what the organization decided to do about it.
- CUI (Controlled Unclassified Information): sensitive government information that isn’t classified but still has to be protected. It’s the reason defense contractors deal with CMMC.
The standard: NIST SP 800-171 and CMMC
NIST SP 800-171 sets the security requirements for protecting CUI in non-federal systems, which in practice means contractors and suppliers. The Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) is how the DoD verifies that its contractors actually meet them. CMMC Level 2 is built on the 110 requirements in NIST SP 800-171 Revision 2.
You don’t need to memorize 110 requirements. You need to understand the pattern, because every one of them follows it.
One control, start to finish
Here’s the full trace for the multifactor authentication requirement (3.5.3 in Revision 2):
- The requirement. Use multifactor authentication for local and network access to privileged accounts, and for network access to non-privileged accounts.
- The implementation. Which systems are in scope, which identity provider enforces MFA, and which accounts are exceptions and why.
- The documentation. How the SSP describes the implementation, in plain language an assessor can check.
- The evidence. The configuration showing MFA is enforced, the report showing who’s enrolled, and the sign-in logs showing it’s actually used.
- The gap. What happens when a service account can’t do MFA, and how it lands on the POA&M instead of being quietly ignored.
Try this: think about one account you use every day at work or school. How would you prove, to a stranger, that it requires a second factor? That’s the job.
Questions worth thinking through
- What’s the difference between a control that’s implemented and one that’s effective?
- Who decides which risks a company accepts, and where does that decision get written down?
- How do GRC analysts work with the SOC and the engineers without becoming the department of no?
Where this path leads
GRC & Compliance is one of the six career paths on Chrysalus. The roles are GRC analyst and ISSO, and the credentials on this path are ISACA’s CRISC and ISC2’s CGRC.
- Not sure GRC is your lane? Take the free career path assessment.
- Prep for the certs: CRISC Practice Exam and CGRC Practice Exam.
- Browse every Cover6 course.
See it live with Cover6 Community
We cover this live in the Cover6 Community session GRC Analyst Fundamentals: Controls to Evidence on Wednesday, October 14 at 6:00 PM ET, streaming to the DMV, Atlanta and South Florida chapters at once. Planning to attend? Use this post as your read-ahead. RSVP on Meetup or watch on YouTube. The replay gets added here afterward.