Expert Advice Community

Guest

IT-GRC and ISO 27001

  Quote
Guest
Guest user Created:   Jan 13, 2016 Last commented:   Jan 13, 2016

IT-GRC and ISO 27001

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
AntonioS Jan 13, 2016

I need your little help, can you just tell me the relationship or difference between IT-GRC and ISO 27001 ?
IT-GRC is all about an integrated approach towards Governance, Risk management and Compliance, where ISO 27001 talks about all the aspects like top management and Risk management etc. So my doubt is why organizations are getting attracted towards the IT-GRC approch ? What is the main difference between them.?
 

Answer:

From my point of view, the main difference is that IT-GRC is related to the governance of IT, however it is not established in ISO 27001 (there are another standard for the IT governance: ISO 38500). On the other hand, the common point between both is that they are related with the risk management and the compliance of policies, procedures, laws and regulations.
Finally, IT-GRC approach can be interesting for companies that want a framework related to the governance of IT, and ISO 27001 is for companies that want to implement and certify an Information Security Management System (you cannot certify IT-GRC).
By th e way, do you know what are the 6 basic steps in the ISO 27001 risk assessment & treatment? Here you can see an interesting article “ISO 27001 risk assessment & treatment – 6 basic steps” : https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics