GRC Academy

The Compliance Playbook to Cybersecurity


Listen Later

"Compliance is the security referee - frameworks are the playbooks."

In this episode, I’m joined by Tim Golden, Founder of Compliance Scorecard, to unpack the misunderstood, and mission-critical world of cyber GRC.

Tim shares what he’s learned from decades of hands-on work - from implementing NIST frameworks before “GRC” was even a term, to helping teams understand why writing policies is just as important as patching vulnerabilities.

Here are some highlights from the episode:

  • What GRC actually means - and why governance is the most misunderstood part
  • Why people who say "compliance isn't security" are missing the point
  • How explaining the "why" of cybersecurity controls aids in acceptance
  • Why data retention policies can protect you from major legal headaches
  • And yes… a story about how Tim accidentally ransomwared himself 🙃

This is a must-listen for anyone navigating compliance, cybersecurity, or just trying to understand how it all fits together!

I really enjoyed this conversation! What were your biggest takeaways? Let me know in the comments.

Follow Tim on LinkedIn: https://www.linkedin.com/in/timothygolden/

Compliance Scorecard Website: https://compliancescorecard.com/

-----------

Thanks to our sponsor Vanta!

Get back time to focus on strengthening security and scaling your business.

Discover the new way to GRC here: https://vanta.com/grcacademy

-----------

Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!

Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-e9&utm_campaign=courses

#cybersecurity

...more
View all episodesView all episodes
Download on the App Store

GRC AcademyBy Jacob Hill

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like GRC Academy

View all
Security Now (Audio) by TWiT

Security Now (Audio)

2,003 Listeners

Intelligent Machines (Audio) by TWiT

Intelligent Machines (Audio)

777 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

638 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,002 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

175 Listeners

Hacking Humans by N2K Networks

Hacking Humans

313 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

188 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

73 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

134 Listeners

Cyberspin by Redspin

Cyberspin

2 Listeners

Sum IT Up: CMMC News Roundup by Summit 7

Sum IT Up: CMMC News Roundup

14 Listeners

GRC & Cyber Security Podcast by SureCloud

GRC & Cyber Security Podcast

3 Listeners

Climbing Mount CMMC by Bobby Guerra

Climbing Mount CMMC

2 Listeners

CMMC Compliance Guide by CMMC Compliance Guide

CMMC Compliance Guide

0 Listeners

CUI Hotline: Live CMMC Q&A by Summit 7

CUI Hotline: Live CMMC Q&A

0 Listeners