From some comments Dwayne made on yesterday’s post.
IT- GRC is just threat / vulnerability pairing when you consider external regulatory compliance pressures as the Threat Community. If you think of it this way, you might be able to understand why I’m not keen on the value of GRC many current solutions. As Shrdlu (or was it rybolov?) once said - GRC is (usually*) just a report. Turns out, it’s just a threat/vulnerability pairing report.
* “usually” is my addition.





