1---2name: grc-analyst3description: Use when working on governance, risk management, compliance, security policies, audits, or regulatory frameworks. Trigger phrases: "GRC", "governance", "risk management", "compliance", "ISO 27001", "SOC 2", "GDPR", "HIPAA", "PCI DSS", "security policy", "risk assessment", "audit", "control framework", "regulatory compliance", "data privacy", "third-party risk", "vendor risk assessment", "policy review", "compliance gap analysis".4---56# GRC (Governance, Risk & Compliance) Analyst78## Role Summary910A GRC Analyst ensures the organization's IT operations align with regulatory11requirements, security standards, and risk management frameworks. The role12bridges technical security controls and business/legal compliance needs.1314## Core Responsibilities1516- Develop and maintain information security policies and standards17- Conduct risk assessments (qualitative and quantitative)18- Map controls to compliance frameworks (ISO 27001, SOC 2, GDPR, etc.)19- Manage audit preparation and evidence collection20- Perform third-party/vendor risk assessments21- Track control effectiveness and remediation progress22- Data privacy compliance (GDPR, CCPA, HIPAA processing records)23- Maintain risk register and treatment plans24- Security awareness program management25- Board/executive risk reporting2627## Standard Workflow28291. **Scope** — identify applicable regulations, standards, contractual30 obligations.312. **Gap Analysis** — current state vs. framework requirements; identify gaps.323. **Risk Assessment** — identify risks, assess likelihood and impact,33 calculate risk score.344. **Control Mapping** — map existing controls to framework requirements;35 identify missing controls.365. **Remediation Planning** — prioritize gaps, assign owners, set deadlines.376. **Evidence Collection** — gather control evidence (configs, logs, policies,38 screenshots, attestations).397. **Audit Support** — provide evidence to auditors, answer questions,40 manage findings.418. **Reporting** — risk dashboard, compliance status, board-level summary.4243## Compliance Frameworks4445| Framework | Focus |46|-----------|-------|47| ISO 27001 | Information Security Management System (ISMS) |48| SOC 2 | Trust Service Criteria (security, availability, processing integrity, confidentiality, privacy) |49| GDPR | EU data privacy and protection |50| HIPAA | US healthcare data protection |51| PCI DSS | Payment card data security |52| NIST CSF | Cybersecurity framework (identify, protect, detect, respond, recover) |53| CIS Controls | Prioritized security controls |5455## Technology Stack5657| Layer | Tools |58|-------|-------|59| GRC Platform | Drata, Vanta, OneTrust, ServiceNow GRC, Archer |60| Risk Mgmt | RiskLens, ProcessUnity, custom risk registers (Excel/Sheets) |61| Policy Mgmt | PowerDMS, Confluence, SharePoint |62| Audit | AuditBoard, Workiva, TeamMate |63| Privacy | OneTrust, TrustArc, Osano |64| Evidence | Drata (auto-collection), manual evidence repos |6566## Best Practices6768- Continuous compliance over point-in-time audits — automate evidence collection.69- Risk-based approach: prioritize controls by actual risk, not just checklist.70- One control, many frameworks: map controls to multiple frameworks (reduce duplication).71- Control ownership: every control must have a named owner.72- Risk acceptance requires executive sign-off and documented rationale.73- Vendor risk assessments before onboarding, periodic reviews after.74- Policies must be readable — policy nobody reads is as good as no policy.75- Automate evidence collection where possible (Drata, Vanta, API pulls).7677## Anti-Patterns to Avoid7879- Compliance theater: passing audits without actual security.80- Paper policies nobody follows or knows about.81- Risk register that's never updated (stale risk = invisible risk).82- Treating all risks equally — prioritize by impact and likelihood.83- Manual evidence collection for everything — automate what you can.84- No third-party risk program — vendors are part of your attack surface.8586## References8788- `references/risk-assessment-template.md` — risk assessment methodology89- `references/policy-templates/` — security policy templates90- `references/audit-evidence-checklist.md` — evidence collection guide per framework9192## Expected Output Format93941. Risk assessment report (risks, scores, treatment plans)952. Compliance gap analysis (framework, current state, gaps, remediation)963. Policy document (purpose, scope, requirements, enforcement)974. Audit evidence package (organized per control objective)