Governance, Risk and Compliance

Edition: 1

Copyright: 2026

Pages: 520

Choose Your Format

Ebook

$76.00 USD

ISBN 9798319727497

Details Electronic Delivery EBOOK 180 days

In an era of relentless regulatory pressure, evolving cyber threats, and increasing organizational complexity, the organizations that endure are not simply the most technically advanced; they are the most governed, the most prepared, and the most resilient.

Governance, Risk, and Compliance are no longer back-office functions buried in policy documents and audit checklists. They are the strategic pillars upon which secure, trustworthy, and sustainable organizations are built. Governance, Risk, and Compliance is the essential guide for information security professionals, risk managers, and organizational leaders who must transform GRC from a compliance obligation into a powerful competitive advantage. 

This comprehensive, practitioner-focused resource bridges the gap between theory and execution, equipping you with the frameworks, methodologies, and strategic insight needed to build GRC programs that don't just satisfy auditors, but genuinely protect and strengthen your organization from the inside out.

About the Authors 
Video Library
Introduction 

Chapter 1: The Strategic Imperative of GRC in Information Security 
Chapter 2: Establishing Robust IT Governance Frameworks 
                   The Implementation Journey: A Real-World Example 
Chapter 3: Navigating the Complexities of Regulatory Compliance 
Chapter 4: Foundations of Information Security Risk Management 
Chapter 5: Conducting Comprehensive Risk Assessments 
Chapter 6: Developing Effective Risk Treatment Strategies 
Chapter 7: Building Enterprise-Wide Risk Management Strategies 
Chapter 8: Developing and Implementing Security Policies 
Chapter 9: The Intricacies of Information Security Audits 
Chapter 10: Integrating GRC With Incident Response and Management 
Chapter 11: Implementing Business Continuity and Disaster Recovery 
Chapter 12: Establishing Effective Information Security Governance Structures 
Chapter 13: Metrics, Monitoring, and Continuous Improvement 
Chapter 14: Building a Culture of Security and Compliance 
Chapter 15: The Future of GRC and Organizational Resilience 

Further Readings 
Index

Rebecca M Basta

Rebecca M. Basta is a distinguished bioinformatics and cybersecurity education specialist with deep expertise at the critical intersection of health care technology, data science, and cybersecurity. Holding a Master of Science in Bioinformatics and a Bachelor of Science in Biochemistry with a Minor in Biotechnology, Basta combines advanced academic credentials with hands-on laboratory and educational expertise.
With an impressive portfolio of 30+ professional certifications spanning health care data analytics, AI governance, cybersecurity, risk management, and emerging security technologies, Basta demonstrates exceptional breadth across intersecting disciplines. Her credentials include Certified Health Data Analyst (CHDA), Certified Information Privacy Professional/United States (CIPP/US), Artificial Intelligence Governance Professional (AIGP), ISO 27001 and ISO 42001 Certified Lead Auditor, Certified Analytics Professional Expert (CAP), Certified Lean Six Sigma Master Black Belt, Certified Red Team Operations Management (CRTOM), and Certified Artificial Intelligence Security & Risk (CAISR). This diverse certification landscape reflects her commitment to understanding security from multiple angles: defensive, offensive, and governance perspectives. Basta’s research and publication record is exceptionally prolific, focusing on the convergence of health care security and advanced data analytics.

Stavros E Basta

Stavros E. Basta is an accomplished cybersecurity professional and published researcher 
specializing in industrial control systems (ICS) security and critical infrastructure protection. Holding a Master of Science in Cybersecurity and a Bachelor of Science in Cybersecurity, Basta brings advanced academic credentials alongside extensive industry experience.
With an impressive portfolio of 25+ professional certifications spanning security leadership, penetration testing, risk management, and cloud security, including GIAC Global Industrial Cyber Security Professional (GICSP), Certified Information Security Manager (CISM), Licensed Penetration Testing Master (LPTM), GIAC Security Leadership (GSLC), and Certified Penetration Testing Professional (CPENT), Basta demonstrates deep expertise across the cybersecurity landscape. Basta’s research investigates the critical gap between traditional cybersecurity frameworks and the unique vulnerabilities of industrial control systems and critical infrastructure. 

In an era of relentless regulatory pressure, evolving cyber threats, and increasing organizational complexity, the organizations that endure are not simply the most technically advanced; they are the most governed, the most prepared, and the most resilient.

Governance, Risk, and Compliance are no longer back-office functions buried in policy documents and audit checklists. They are the strategic pillars upon which secure, trustworthy, and sustainable organizations are built. Governance, Risk, and Compliance is the essential guide for information security professionals, risk managers, and organizational leaders who must transform GRC from a compliance obligation into a powerful competitive advantage. 

This comprehensive, practitioner-focused resource bridges the gap between theory and execution, equipping you with the frameworks, methodologies, and strategic insight needed to build GRC programs that don't just satisfy auditors, but genuinely protect and strengthen your organization from the inside out.

About the Authors 
Video Library
Introduction 

Chapter 1: The Strategic Imperative of GRC in Information Security 
Chapter 2: Establishing Robust IT Governance Frameworks 
                   The Implementation Journey: A Real-World Example 
Chapter 3: Navigating the Complexities of Regulatory Compliance 
Chapter 4: Foundations of Information Security Risk Management 
Chapter 5: Conducting Comprehensive Risk Assessments 
Chapter 6: Developing Effective Risk Treatment Strategies 
Chapter 7: Building Enterprise-Wide Risk Management Strategies 
Chapter 8: Developing and Implementing Security Policies 
Chapter 9: The Intricacies of Information Security Audits 
Chapter 10: Integrating GRC With Incident Response and Management 
Chapter 11: Implementing Business Continuity and Disaster Recovery 
Chapter 12: Establishing Effective Information Security Governance Structures 
Chapter 13: Metrics, Monitoring, and Continuous Improvement 
Chapter 14: Building a Culture of Security and Compliance 
Chapter 15: The Future of GRC and Organizational Resilience 

Further Readings 
Index

Rebecca M Basta

Rebecca M. Basta is a distinguished bioinformatics and cybersecurity education specialist with deep expertise at the critical intersection of health care technology, data science, and cybersecurity. Holding a Master of Science in Bioinformatics and a Bachelor of Science in Biochemistry with a Minor in Biotechnology, Basta combines advanced academic credentials with hands-on laboratory and educational expertise.
With an impressive portfolio of 30+ professional certifications spanning health care data analytics, AI governance, cybersecurity, risk management, and emerging security technologies, Basta demonstrates exceptional breadth across intersecting disciplines. Her credentials include Certified Health Data Analyst (CHDA), Certified Information Privacy Professional/United States (CIPP/US), Artificial Intelligence Governance Professional (AIGP), ISO 27001 and ISO 42001 Certified Lead Auditor, Certified Analytics Professional Expert (CAP), Certified Lean Six Sigma Master Black Belt, Certified Red Team Operations Management (CRTOM), and Certified Artificial Intelligence Security & Risk (CAISR). This diverse certification landscape reflects her commitment to understanding security from multiple angles: defensive, offensive, and governance perspectives. Basta’s research and publication record is exceptionally prolific, focusing on the convergence of health care security and advanced data analytics.

Stavros E Basta

Stavros E. Basta is an accomplished cybersecurity professional and published researcher 
specializing in industrial control systems (ICS) security and critical infrastructure protection. Holding a Master of Science in Cybersecurity and a Bachelor of Science in Cybersecurity, Basta brings advanced academic credentials alongside extensive industry experience.
With an impressive portfolio of 25+ professional certifications spanning security leadership, penetration testing, risk management, and cloud security, including GIAC Global Industrial Cyber Security Professional (GICSP), Certified Information Security Manager (CISM), Licensed Penetration Testing Master (LPTM), GIAC Security Leadership (GSLC), and Certified Penetration Testing Professional (CPENT), Basta demonstrates deep expertise across the cybersecurity landscape. Basta’s research investigates the critical gap between traditional cybersecurity frameworks and the unique vulnerabilities of industrial control systems and critical infrastructure.