Home > CIO Definitions - GRC (governance, risk management and compliance) software
SearchCIO.com Definitions (Powered by WhatIs.com)
EMAIL THIS
LOOK UP TECH TERMS Powered by: WhatIs.com
Search listings for thousands of IT terms:
Browse tech terms alphabetically:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #

GRC (governance, risk management and compliance) software


Show me everything on Compliance strategies and best practices


Word of the Day


DEFINITION - GRC (governance, risk management and compliance) software allows publicly-held companies to integrate and manage IT operations that are subject to regulation. Such software typically combines applications that manage the core functions of GRC into a single integrated package.

GRC software enables an organization to pursue a systematic, organized approach to managing GRC-related strategy and implementation. Instead of keeping data in separate "silos," administrators can use a single framework to monitor and enforce rules and procedures. Successful installations enable organizations to manage risk, reduce costs incurred by multiple installations and minimize complexity for managers.

GRC software implementation typically involves complex installations that include coordination of data between multiple departments, including business, IT, security, compliance, and auditing. Once in place, however, dashboard s and data analytics tools allow administrators to identify an organization's risk exposure , measure progress towards quarterly goals or quickly pull together an information audit . Good governance, defined as effective, ethical management of a company at the executive level, is treated as an objectively measurable commodity. Data retention and risk management are converted to similarly measurable metrics.

GRC software can satisfy the needs of multiple stakeholders, including:

  • business executives that need to identify and manage risk.
  • finance managers assigned to meet regulatory compliance requirements.
  • legal counsels grappling with discovery and records retention.
  • IT directors managing software installations related to GRC projects across an organization.
Data retention and risk management procedures mandated by the Sarbanes-Oxley Act ( SOX ), HIPAA , Basel II and regional regulations have all placed unprecedented pressure on IT administrators to coordinate enterprise-wide tracking and organization of compliance measures. As a result, the GRC software category has rapidly become a hotly contested space between industry giants like SAP, Oracle, IBM, CA and a host of smaller startups. Given the complex regulatory burden imposed upon both executives and IT administrators, the tools provided by GRC software will become increasingly important to meeting the new standards.

Learn more about Compliance strategies and best practices
Email archiving solutions and strategies for enterprise CIOs: Effective email archiving solutions and strategies are an important part of a CIO's job, as e-discovery, litigation and compliance regulations require detailed email policies.
Enterprise risk management solutions for CIOs: Enterprise risk management programs buffer organizations from risky business practices. In this guide, learn how to employ enterprise risk management solutions in an organization.
Information security and IT governance guides for CIOs: Keeping your IT organization safe and secure is one battle. Doing it while staying in compliance with all applicable laws and regulations is another.
E-discovery and litigation guide for CIOs: Electronic discovery and litigation concerns are serious responsibilities for IT staffs. Learn how to tackle them with this CIO Briefing.
Regulatory compliance for the enterprise: The regulatory compliance for the enterprise All-in-One-Guide offer resources from various TechTarget sites for all levels of IT employees and from multiple angles.

LAST UPDATED: 06 Mar 2009

Do you have something to add to this definition? Let us know.
Send your comments to techterms@whatis.com

More resources from around the web:
- OCEG is a nonprofit that provides advice to organizations implementing GRC practices, including guidelines, standards and evaluation criteria for software.
- GRC Journal publishes case studies and research designed to help executives understand current GRC market trends.
- Linda Musthaler and Brian Musthaler wrote about "Governance, risk management and compliance and what it means to you" at NetworkWorld.com.
- Data management expert Michael Rasmussen compares GRC technology with spreadsheets.





FILE EXTENSION AND FILE FORMAT LIST
File Extension and File Format List:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #


RELATED CONTENT
Email archiving solutions and strategies for enterprise CIOs
Effective email archiving solutions and strategies are an important part of a CIO's job, as e-discovery, litigation and compliance regulations require...
Miscues abounded in Boston email retention policy, practices
Boston CIO Bill Oates talks about measures taken to tune an email retention policy after disconnects between user practice and system capability set...
Health care security, HIPAA compliance on deck for CIOs in Obama era
HIPAA enforcement has long been lax, but that's changing with stiffer HIPAA security and privacy rules and incentives to move to electronic health...

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
sustainability risk management (SRM)  (SearchCIO.com)
Sustainability risk management (SRM) is a business strategy that aligns profit goals with internal green computing policies. (Continued...)




Discover CIO solutions for IT Management, Outsourcing, Governance and GRC (governance, risk management and compliance) software Solutions
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts