In an era of relentless regulatory pressure, evolving cyber threats, and increasing organizational complexity, the organizations that endure are not simply the most technically advanced; they are the most governed, the most prepared, and the most resilient.
Governance, Risk, and Compliance are no longer back-office functions buried in policy documents and audit checklists. They are the strategic pillars upon which secure, trustworthy, and sustainable organizations are built. Governance, Risk, and Compliance is the essential guide for information security professionals, risk managers, and organizational leaders who must transform GRC from a compliance obligation into a powerful competitive advantage.
This comprehensive, practitioner-focused resource bridges the gap between theory and execution, equipping you with the frameworks, methodologies, and strategic insight needed to build GRC programs that don't just satisfy auditors, but genuinely protect and strengthen your organization from the inside out.
About the Authors
Video Library
Introduction
Chapter 1: The Strategic Imperative of GRC in Information Security
Chapter 2: Establishing Robust IT Governance Frameworks
The Implementation Journey: A Real-World Example
Chapter 3: Navigating the Complexities of Regulatory Compliance
Chapter 4: Foundations of Information Security Risk Management
Chapter 5: Conducting Comprehensive Risk Assessments
Chapter 6: Developing Effective Risk Treatment Strategies
Chapter 7: Building Enterprise-Wide Risk Management Strategies
Chapter 8: Developing and Implementing Security Policies
Chapter 9: The Intricacies of Information Security Audits
Chapter 10: Integrating GRC With Incident Response and Management
Chapter 11: Implementing Business Continuity and Disaster Recovery
Chapter 12: Establishing Effective Information Security Governance Structures
Chapter 13: Metrics, Monitoring, and Continuous Improvement
Chapter 14: Building a Culture of Security and Compliance
Chapter 15: The Future of GRC and Organizational Resilience
Further Readings
Index
Rebecca M Basta
Rebecca M. Basta is a distinguished bioinformatics and cybersecurity education specialist with deep expertise at the critical intersection of health care technology, data science, and cybersecurity. Holding a Master of Science in Bioinformatics and a Bachelor of Science in Biochemistry with a Minor in Biotechnology, Basta combines advanced academic credentials with hands-on laboratory and educational expertise.
With an impressive portfolio of 30+ professional certifications spanning health care data analytics, AI governance, cybersecurity, risk management, and emerging security technologies, Basta demonstrates exceptional breadth across intersecting disciplines. Her credentials include Certified Health Data Analyst (CHDA), Certified Information Privacy Professional/United States (CIPP/US), Artificial Intelligence Governance Professional (AIGP), ISO 27001 and ISO 42001 Certified Lead Auditor, Certified Analytics Professional Expert (CAP), Certified Lean Six Sigma Master Black Belt, Certified Red Team Operations Management (CRTOM), and Certified Artificial Intelligence Security & Risk (CAISR). This diverse certification landscape reflects her commitment to understanding security from multiple angles: defensive, offensive, and governance perspectives. Basta’s research and publication record is exceptionally prolific, focusing on the convergence of health care security and advanced data analytics.
Stavros E Basta
Stavros E. Basta is an accomplished cybersecurity professional and published researcher
specializing in industrial control systems (ICS) security and critical infrastructure protection. Holding a Master of Science in Cybersecurity and a Bachelor of Science in Cybersecurity, Basta brings advanced academic credentials alongside extensive industry experience.
With an impressive portfolio of 25+ professional certifications spanning security leadership, penetration testing, risk management, and cloud security, including GIAC Global Industrial Cyber Security Professional (GICSP), Certified Information Security Manager (CISM), Licensed Penetration Testing Master (LPTM), GIAC Security Leadership (GSLC), and Certified Penetration Testing Professional (CPENT), Basta demonstrates deep expertise across the cybersecurity landscape. Basta’s research investigates the critical gap between traditional cybersecurity frameworks and the unique vulnerabilities of industrial control systems and critical infrastructure.