What Is GRC in Cyber Security? Governance, Risk and Compliance Explained
GRC in cyber security stands for Governance, Risk, and Compliance, the combined discipline of setting security policy, managing risk, and proving you meet regulatory requirements. Most businesses hit this question when a client, insurer, or regulator asks for proof, and ISO 27001 is usually the framework that proof points back to.
What is GRC in cyber security, and where does ISO 27001 fit in?
GRC covers three connected functions: governance sets policy and accountability, risk management identifies and treats threats to your information, and compliance proves you’re meeting external requirements. ISO 27001 is the international standard businesses use to structure and certify all three at once.
Think of GRC as the umbrella and ISO 27001 as the most common certifiable structure underneath it. A business can have governance and risk processes without ever pursuing certification, but ISO 27001 gives those processes an auditable, internationally recognized shape that clients and regulators trust. That’s why the two terms show up together so often in cyber security compliance conversations.
What is ISO 27001?
ISO 27001 is the international standard for building an Information Security Management System, or ISMS, the set of policies, processes, and controls an organization uses to manage information security risk. Certification proves to customers, partners, and regulators that your security practices meet a recognized, independently audited standard.
Getting certified means an accredited body reviews your ISMS through a Stage 1 documentation review and a Stage 2 operational audit, checking that the controls you say you have actually work in practice. It’s not a one-time test. Certified organizations undergo surveillance audits, typically annually, to keep the certificate active.
The 93 controls, four themes: what changed in 2022
ISO 27001:2022 restructured Annex A from 114 controls across 14 domains down to 93 controls organized under four themes: Organizational, People, Physical, and Technological. The consolidation merged overlapping controls rather than removing protection, while adding 11 entirely new ones to address modern risks.
Here’s how the current structure breaks down:
| Theme | Number of Controls | Covers |
| Organizational | 37 | Governance, policies, third-party management, access control |
| People | 8 | HR security, training, awareness |
| Physical | 14 | Facility protection, equipment security |
| Technological | 34 | Encryption, monitoring, logging, malware defense |
If your business is scoping an ISMS for the first time, this four-theme structure is genuinely easier to assign ownership against than the old 14-domain layout, since most people can quickly tell whether a control belongs to the organization, its people, its buildings, or its systems.
Is the old 2013 version still valid? A clear, current answer
No, ISO 27001:2013 is no longer valid. Certified organizations had 36 months from the 2022 revision’s publication to transition, with a hard deadline of October 31, 2025. Certificates still showing the 2013 version after that date are not recognized by accreditation bodies.
This matters more than most guides admit. If your business is holding a 2013 certificate right now, it’s expired, not just outdated, and clients or auditors checking your certification status will flag it immediately. If you missed the transition window entirely, you don’t get the lighter transition audit that used to exist, you now need a full Stage 1 and Stage 2 audit against the 2022 version, effectively starting over. Anyone currently claiming ISO 27001:2013 compliance in a bid document, insurance renewal, or client contract needs to correct that immediately, since it’s now a factually inaccurate claim rather than a slightly old one. Check your certificate date before your next client renewal or tender submission, not after.
Annex A is a menu, not a checklist, and here’s why that matters
Annex A is a reference set of controls, not a mandatory checklist, meaning you don’t implement all 93. You select the ones relevant to your risk assessment and document every inclusion and exclusion in your Statement of Applicability, with a justification tracing back to actual identified risk.
This distinction causes more failed audits than almost anything else in the certification process. Auditors don’t expect every one of the 93 controls implemented. What they expect is a Statement of Applicability that clearly justifies every exclusion and shows the controls you did select are operating effectively, not just documented on paper. Selecting controls simply because they’re listed in the annex, without tying each one to a genuine risk your organization faces, is the most common implementation error security teams make during their first certification attempt. A retail business with no cloud infrastructure, for example, can reasonably exclude cloud-specific controls in its SoA, provided the risk assessment supports that exclusion clearly. Treating Annex A as a box-ticking exercise instead of a risk-driven selection process is exactly the pattern that turns a Stage 2 audit into a failed one, since auditors are trained specifically to probe weak justifications in the SoA before checking anything else.
What’s genuinely new: threat intelligence, cloud security, and data leakage controls
The 2022 revision added 11 controls that didn’t exist before, addressing gaps the 2013 version left implicit. These cover threat intelligence, cloud service security, business continuity readiness, physical security monitoring, configuration management, data handling, and secure coding practices.
The full list of new additions includes threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. Most transition work for existing certificate holders landed on these 11, since they name practices many organizations were already doing informally but had never formally documented or audited. If your business uses cloud services or handles customer data at any real scale, expect auditors to focus specifically here.
ISO 27001 vs ISO 27002: a distinction worth getting right
ISO 27001 is the certifiable standard containing the requirements your ISMS must meet, including Annex A’s control list. ISO 27002 is the companion guidance document explaining how to actually implement each of those controls in practice. You get certified against 27001. You implement using 27002.
| Standard | Purpose | Can You Get Certified Against It? |
| ISO 27001 | States requirements and lists controls | Yes |
| ISO 27002 | Explains how to implement each control | No |
Confusing the two causes real friction during procurement, when a client asks whether you’re “ISO 27002 certified” and the honest answer is that certification only applies to 27001. Keep the distinction simple: 27001 is the exam, 27002 is the study guide.
What’s changed even more recently, in 2026?
ISO/IEC 27000:2026, the sixth edition, was published this year, replacing the 2018 version and changing how the whole family’s terminology works. It’s no longer the primary glossary for the ISMS family, shrinking its defined terms significantly and pointing users to ISO’s online browsing platform for everything else.
This update matters for anyone building an ISMS right now, because most existing guidance online still describes the older 2018 structure. The 2026 edition reorganizes the family by function rather than by document type, and explicitly restates that Annex A controls are a reference set, not a mandatory list, reinforcing the exact point covered above. Separately, ISO published a climate action amendment to 27001:2022 in February 2024, directing organizations to consider whether environmental changes are relevant to their ISMS context, a requirement that’s easy to miss if your compliance documentation hasn’t been reviewed since initial certification. If you certified before 2024, check whether your ISMS scope statement addresses this amendment specifically, since some certification bodies are now checking for it during surveillance audits.
How does this connect to Cyber Essentials and your UK compliance stack?
Cyber Essentials and ISO 27001 aren’t competing options, they solve different assurance problems. Cyber Essentials is a UK government-backed baseline covering five technical controls, while ISO 27001 is a full management system covering governance, risk, and a much broader control set, including everything Cyber Essentials touches.
For UK SMBs, the practical sequence usually makes sense in that order. Cyber Essentials is faster and cheaper to achieve, often required for UK government contracts, and gives you a technical baseline. ISO 27001 builds a full management system on top of that baseline and carries more weight internationally, particularly with clients outside the UK who may not recognize Cyber Essentials at all. Many businesses hold both, using Cyber Essentials for domestic government tender requirements and ISO 27001 for broader client assurance.
A realistic path if this is your very first certification
Start with a gap analysis against the current 93 controls before writing any policy documents, since building documentation before understanding your actual gaps wastes the most time in a first certification attempt. Most first-time certifications take 6 to 12 months from gap analysis to Stage 2 audit.
Build your risk assessment and Statement of Applicability together, not sequentially, since each control decision in the SoA should trace directly back to a specific risk you identified. Budget for an internal audit before your Stage 2 external audit, catching documentation gaps while they’re still cheap to fix. Cyber Security Solutions Ltd works with first-time certification clients through exactly this sequence, and the businesses that skip the gap analysis and jump straight to writing policies almost always redo significant work later, once the risk assessment reveals gaps the policies never addressed.
Conclusion
GRC in cyber security comes down to one connected system: governance sets the rules, risk assessment decides what actually matters, and ISO 27001 gives that system a certifiable shape clients and regulators trust. Check your certificate date, treat Annex A as a risk-driven selection rather than a checklist, and budget time for a proper gap analysis before your first audit.
FAQs
GRC stands for Governance, Risk, and Compliance. It’s the combined discipline of setting security policy, managing risk to information assets, and proving you meet regulatory or contractual requirements. ISO 27001 is the most widely adopted framework businesses use to structure and certify all three functions together.
ISO 27001 is the international standard for building an Information Security Management System, or ISMS. It’s a structured set of policies, processes, and controls that manage information security risk, and certification proves to clients and regulators that an independent auditor has verified your practices meet the standard.
GRC stands for Governance, Risk, and Compliance. Governance covers policy and accountability structures, risk management identifies and treats threats to information, and compliance proves an organization meets external regulatory or contractual requirements, often through a certifiable framework like ISO 27001.
Annex A lists 93 reference controls organized into four themes: Organizational, People, Physical, and Technological. Organizations select which controls apply based on their own risk assessment, documenting inclusions and exclusions in a Statement of Applicability rather than implementing all 93 by default.
A Statement of Applicability, or SoA, is a document listing every Annex A control and stating whether it applies to your organization, with justification tied to your risk assessment. Auditors use it to verify that control selections are risk-driven rather than arbitrary during certification.
No. The transition deadline was October 31, 2025. Certificates issued against the 2013 version are no longer recognized after that date. Organizations that missed the transition window now need a full Stage 1 and Stage 2 audit against ISO 27001:2022, not the lighter transition process that previously existed.
ISO 27001 is the certifiable standard containing requirements and the Annex A control list. ISO 27002 is the companion guidance document explaining how to implement each control. Organizations get certified against 27001; they use 27002 as an implementation reference, since 27002 itself isn’t certifiable.
