What is GRC?
As explained by the Managing Partner, founder, and CEO Robin Basham, GRC “is the enterprise program and supporting platforms that collectively enforce governance, risk management and compliance with legal, operational, financial, and information requirements, as determined necessary by the entity's industry, board, consumer and investor communities."
EnterpriseGRC Solutions® Professional's real-world experience, thought leadership, methods, and tools add to your absolute solution for a mature and ongoing program of GRC. EnterpriseGRC Solutions® practice is involved with SIM®, ISACA®, ITSMF®, and various organizations focused on audit automation. One way that EnterpriseGRC Solutions® differentiates our market services in controls assessment, is by delivering free tools for IT Regulatory (SOX) reporting that allow reduced dependency on external consulting, retains proprietary knowledge, and lower volume and time on testing.

Facilitated Compliance Management™ provides a Common Methodology in Delivering a Successful GRC.
A clear win for any IT Service organization can be found in providing Unified and Integrated control framework mapping to comply once and meet with many similarly purposed regulations. Aligning service delivery to regulatory-driven compliance models enables sustained client value. The simplest possible view of controls mapping might include:
- Business Process - Service
- Business Control Requirement - Regulation
- Control Process – Control Framework Identifier
- System Enablers – Technology policy
- People Enablers – Business Policy
- Standard and Frequency of Measure – Compliance Metrics
- Compliance Reporting – Representation of Compliance
Facilitated Compliance Management™
Every client has unique goals and capabilities. Typical engagements include Policy Baseline, Configuration Management, Control Assessment, Enterprise Risk Management
- Policy Mapping is the Foundation of Actionable, Auditable Control
- RunBooks Identify Expected and KEY Services and Systems, resulting in Establishing a Technology Baseline Supporting Critical Automated Business Controls
- RiskWatch iterates the gap between Policy, Standards and Business Realities
- Assessment Reviews, CMDB – Configuration Management Alignment to Security Policy and Service Standards (such as the selected control frameworks)

Organizations face challenges that drive the need for IT governance:
- Keeping IT running
- Delivering value to customers
- Managing IT costs
- Master complexity
- Align IT with business
- Ensure regulatory compliance
- Manage security
EnterpriseGRC Solutions® has custom tools that facilitate mapping client documentation and artifacts to their industry-specific array of requirements. Recent projects have involved creating a single risk framework with client policies mapped and risk ranked against collections of the following cybersecurity and cloud frameworks.
- Cloud Controls Matrixv4 as CCM WG leader for the mapping to NIST SP 800-53 and new ISO/IEC FDIS 27002
- 21 CFR Part 11
- 21 CFR Part 820
- HIPAA-HITECH CFR 45
- Eudralex V4 Annex 11
- GAMP® 5*
- HITRUST 9.3* (if associated to valid client license with HITRUST)
- ISO 13485:2016
- ISO/IEC 30111:2019
- ISO/IEC 27001:2013 €
- ISO/IEC 27017:2015 € 27002 for cloud services
- ISO/IEC 27799:2016 €
- ISO/IEC 27002:2013 € New ISO/IEC FDIS 27002 and mapping to CCM V4 and NIST 171 Assessment
- ISO/IEC 27018:2019 €
- ISO/IEC 27701:2019 €
- NIST SP 800-171r2, NIST SP 800-171A, NIST SP 800-172, NIST.HB.162
- NIST SP 800-53 r5
- FedRamp SP 800-53B now NIST SP 800-53C
- GDPR
- CCPA 1798
- AICPA SOC 2 2017
- NIST Cybersecurity Framework, CSF
- CIS Benchmarks - OSCAL & SCAP integration, mapping to custom cybersecurity products
- CIS CSC v7.1-> 8.1 - the top 18
- PCI DSS V3.2.1
- COSO 2013 as mapped to IT and Cybersecurity standards and ISMS
- FFIEC
- NCSC NATIONAL CYBERSECURITY STRATEGY 2016-2021
- UK Cyber Essentials
- Criminal Justice Information Services (CJIS) Security Policy
- Compliance Controls Catalogue (C5)
- More upon request.
Note that as of October 17th, 2011, products created by Phoenix Business and Systems Process, Inc., to include Facilitated Compliance Management TM, are now owned and distributed exclusively through EnterpriseGRC Solutions Inc ®

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics