{"id":1432,"date":"2021-08-12T20:56:00","date_gmt":"2021-08-12T20:56:00","guid":{"rendered":"https:\/\/www.pax8.com\/future-blog\/governance-risk-compliance\/"},"modified":"2023-05-17T02:04:50","modified_gmt":"2023-05-17T02:04:50","slug":"governance-risk-compliance","status":"publish","type":"post","link":"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/","title":{"rendered":"How to tackle governance, risk, and compliance"},"content":{"rendered":"<p>We break down these concepts and discuss where to start.<\/p>\n<p>The words &#8220;governance, risk, and compliance&#8221; (GRC) usually come packaged together and likely conjure up images of insurance agents and auditors. You might also think that these concepts only matter to large organizations and enterprises. But in fact, they\u2019re crucial components to maintaining secure operations for businesses of every size \u2013 especially in today\u2019s digital business world filled with cyber threats such as ransomware.<\/p>\n<p>These three concepts are intrinsically connected and flow from each other. At their most simplified, you can think of them this way:<\/p>\n<p><strong>Governance: <\/strong>What your company does<\/p>\n<p><strong>Risk: <\/strong>The inherent risks based on what your company does<\/p>\n<p><strong>Compliance: <\/strong>The policies and controls your company should follow to mitigate those risks<\/p>\n<p>Below, we\u2019ll dive deeper into each of these concepts to discuss why they matter to your business and ways you can start to build them into your IT operations to improve security.<\/p>\n<h3>Governance<\/h3>\n<p>Proper governance ensures that day-to-day operations align with overarching business goals. This is achieved through policies and processes that coordinate and drive performance \u2014ensuring that resources are functioning how they\u2019re meant to function and are achieving what they\u2019re meant to achieve.<\/p>\n<p>In IT, governance is usually discussed in relation to technology resource management and data protection. This of course depends on what\u2019s relevant to your specific organization. For example, as a cloud-only company, Pax8 doesn\u2019t transfer hardware \u2014 so we don\u2019t have any risks related to hardware transfers and don\u2019t need to build policies for them.<\/p>\n<h3>Risk<\/h3>\n<p>Risk comes in many forms across a business and are often interconnected and highly dependent on circumstances such as your industry, geographical location, and supply chain. A simple example would be if your business is located in California, you are at a heightened earthquake risk with a potential for severe damage. Therefore, steps need to be taken to mitigate that risk; in this case, most likely through an insurance policy.<\/p>\n<p>Risk mitigation often involves procedures such as a risk assessment, business impact analysis, and business continuity\/disaster recovery (BC\/DR) plan. When identifying and assessing risks, you need to consider:<\/p>\n<p><strong>&#8211; What is the risk?<\/strong><\/p>\n<p><strong>&#8211; What is the likelihood of dealing with that risk? <\/strong>The potential damage of a risk might be high, but if the chance of it happening is extremely low, then it\u2019s not a high priority for risk planning. For example, if your business is located in a year-round warm climate, you likely have less need to plan for the possible disruption of a snowstorm. However, in today\u2019s cybersecurity landscape, nearly every business is at high risk for a ransomware attack and must plan accordingly to <a href=\"https:\/\/www.pax8.com\/blog\/prevent-ransomware\/\" target=\"_blank\" rel=\"noopener\">prevent and mitigate that threat<\/a>.<\/p>\n<p><strong>&#8211; What is the potential impact or disruption that risk can cause?<\/strong> This can be financial, such as lost productivity, sales and revenue, or regulatory fines and penalties. It can also be intrinsic damage such as loss of brand reputation, customer trust, employee morale, or legal consequences.<\/p>\n<p>Once you have defined a risk, you then need to look at it from several perspectives to ask yourself:<\/p>\n<p><strong>&#8211; Is that a risk that we can minimize or mitigate with planning? <\/strong>Some risks can be almost entirely prevented through proper solutions or planning, while others can at least be reduced to some extent.<\/p>\n<p><strong>&#8211; Can we transfer the risk?<\/strong> For example, by taking out an insurance policy or through partnership with another company?<\/p>\n<p><strong>&#8211; Can we accept that risk?<\/strong> This comes down to weighing the potential damage against your investment \u2014 for example, you wouldn\u2019t bother to insure a $200 office chair (yes, even if it has adjustable lumbar support)! However, your business data is extremely valuable and, if stolen or held hostage, has the potential to cause severe disruption, so it\u2019s worth investing upfront to properly protect your data with a <a href=\"https:\/\/www.pax8.com\/blog\/the-msps-guide-to-a-building-a-security-stack\/\" target=\"_blank\" rel=\"noopener\">comprehensive security and continuity stack<\/a>.<\/p>\n<p>The National Institute of Standards and Technology (NIST) has a <a href=\"https:\/\/csrc.nist.gov\/Projects\/risk-management\" target=\"_blank\" rel=\"noopener\">Risk Management Framework (RMF)<\/a> that provides a repeatable, measurable 7-step process you can use to manage your information security and privacy risk.<\/p>\n<h3>Compliance<\/h3>\n<p>Compliance entails developing and putting into practice guidelines, policies, and procedures to mitigate risk and meet legal and regulatory requirements. This is basically all about proving that you &#8220;walk the walk&#8221; and adhere to the processes you say that you will follow.<\/p>\n<p>Measuring compliance often requires some form of external validation, usually in the form of audits and certifications. Achieving a third-party certification can boost client\/prospect confidence in your brand. They often entail an external auditing organization assessing your vulnerabilities and verifying your policies and procedures related to critical activities, technologies, and interdependencies.<\/p>\n<p>Different certifications are more relevant to specific industries, but some examples include:<\/p>\n<p><strong>&#8211; <\/strong><a href=\"https:\/\/www.iso.org\/isoiec-27001-information-security.html\" target=\"_blank\" rel=\"noopener\"><strong>ISO\/IEC 27001<\/strong><\/a> \u2013 Standard published by the International Organization for Standardization for managing information security<\/p>\n<p><strong>&#8211; <\/strong><a href=\"https:\/\/www.iso.org\/iso-9001-quality-management.html\" target=\"_blank\" rel=\"noopener\"><strong>ISO 9001<\/strong><\/a> \u2013 Standard published by the International Organization for Standardization for quality management<\/p>\n<p><strong>&#8211; <\/strong><a href=\"https:\/\/www.acq.osd.mil\/cmmc\/faq.html\" target=\"_blank\" rel=\"noopener\"><strong>CMMC Levels 1 to 5<\/strong><\/a> \u2013 Cybersecurity Maturity Model Certification standards for the defense industry<\/p>\n<p><strong>&#8211; <\/strong><a href=\"https:\/\/www.fedramp.gov\/\" target=\"_blank\" rel=\"noopener\"><strong>FedRAMP<\/strong><\/a> \u2013 Federal Risk and Authorization Management Program that provides a government-approved cybersecurity risk management for cloud products and services<\/p>\n<p>Compliance has also become increasingly important when it comes to regulations. More and more companies of all sizes are now subject to data privacy and protection regulations \u2014 such as the Health Insurance Portability and Accountability Act (HIPAA), the California Consumer Privacy Act (CCPA), and the General Data Protection Regulation (GDPR) of the European Union.<\/p>\n<p>Failing to meet relevant regulations can lead to serious fines and penalties. To help manage compliance for themselves and clients, MSPs can take advantage of cloud solutions such as <a href=\"https:\/\/www.pax8.com\/en-us\/vendors\/compliancy-group\/\" target=\"_blank\" rel=\"noopener\">HIPAA compliance software.<\/a><\/p>\n<h3>Understanding the big picture<\/h3>\n<p>Applying a GRC framework allows you to gain a holistic view of your operational landscape to better understand the interdependencies and cascading effects of different risks, policies, and processes throughout the organization. This helps you avoid communication siloes, overcomplicated mitigation strategies, and competing or conflicting processes. It also helps you establish a standardized organizational vocabulary.<\/p>\n<p>For smaller businesses trying to understand the bigger picture, a gap analysis can be a great launching off point. A gap analysis compares existing operations and performance with your ideal state to identify areas for improvement. You can use a gap analysis to examine any area of the business \u2014 in IT, it\u2019s commonly used to assess security posture.<\/p>\n<p>A SWOT analysis is one well-known gap analysis tool that helps you identify the strengths, weaknesses, opportunities, and threats to your organization. For MSPs, the <a href=\"https:\/\/cybertechaccord.org\/improving-security-posture-through-the-4-step-gap-analysis-process\/\" target=\"_blank\" rel=\"noopener\">Cybersecurity Tech Accord has a 4-step gap analysis process<\/a> that is an excellent template to help you and your clients develop a security roadmap to address security gaps everywhere, from endpoint and email security to password management and end user training.<\/p>\n<h2>Start somewhere (and we can help)<\/h2>\n<p>With so many frameworks, certifications, plans, and analysis templates out there related to GRC planning, it can be especially hard for smaller businesses to know where to start.<\/p>\n<p>At Pax8, we recommend just starting <em>somewhere<\/em>. Find the lowest-hanging fruit of security gaps and identify ways to address them quickly, such as deploying multifactor authentication or an anti-phishing solution. You can continue to build on your security roadmap to layer in solutions, policies, and controls as you mature.<\/p>\n<p>You\u2019re not alone! Pax8 can talk you through guiding security principles and offer resources, such as security controls documentation and policy templates. Our <a href=\"https:\/\/www.pax8.com\/en-us\/professional-services\/\" target=\"_blank\" rel=\"noopener\">Professional Services team<\/a> offers security advisory sessions to provide advice on your security roadmap, budget, compliance and regulatory requirements, and more.<\/p>\n<p>We also offer an 8-week instructor-led <a href=\"https:\/\/www.pax8.com\/en-us\/securityfoundations\/\" target=\"_blank\" rel=\"noopener\">Security Foundations course<\/a> in <a href=\"https:\/\/www.pax8.com\/en-us\/academy\/\">Pax8 Academy<\/a> designed specifically to help MSPs assess their security posture, identify gaps, and develop an action plan. Remember \u2014 just start somewhere!<\/p>\n<p><a class=\"btn-primary\" href=\"https:\/\/www.pax8.com\/academy\">Explore Pax8 Academy<\/a><br \/>\n<a href=\"\/blog\/contact-pax8\">Schedule a call<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We break down these concepts and discuss where to start. The words &#8220;governance, risk, and compliance&#8221; (GRC) usually come packaged together and likely conjure up images of insurance agents and auditors. You might also think that these concepts only matter to large organizations and enterprises. But in fact, they\u2019re crucial components to maintaining secure operations [&hellip;]<\/p>\n","protected":false},"author":141,"featured_media":268,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"","_relevanssi_noindex_reason":"","site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-1432","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How to tackle governance, risk, and compliance - Pax8 Blog<\/title>\n<meta name=\"description\" content=\"\u201cGovernance, risk, and compliance\u201d can sound intimidating, but we\u2019re here to break down these concepts and show you where to start.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to tackle governance, risk, and compliance - Pax8 Blog\" \/>\n<meta property=\"og:description\" content=\"\u201cGovernance, risk, and compliance\u201d can sound intimidating, but we\u2019re here to break down these concepts and show you where to start.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/\" \/>\n<meta property=\"og:site_name\" content=\"Pax8 Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-08-12T20:56:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-05-17T02:04:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.pax8.com\/blog\/wp-content\/uploads\/sites\/13\/2023\/03\/AdobeStock_128410642_adobespark-1.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"2000\" \/>\n\t<meta property=\"og:image:height\" content=\"1333\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"narnold\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"narnold\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/governance-risk-compliance\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/governance-risk-compliance\\\/\"},\"author\":{\"name\":\"narnold\",\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/#\\\/schema\\\/person\\\/4f1f5ecebcf730cc2be7b763a310a63c\"},\"headline\":\"How to tackle governance, risk, and compliance\",\"datePublished\":\"2021-08-12T20:56:00+00:00\",\"dateModified\":\"2023-05-17T02:04:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/governance-risk-compliance\\\/\"},\"wordCount\":1296,\"publisher\":{\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/governance-risk-compliance\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/wp-content\\\/uploads\\\/sites\\\/13\\\/2023\\\/03\\\/AdobeStock_128410642_adobespark-1.jpeg\",\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/governance-risk-compliance\\\/\",\"url\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/governance-risk-compliance\\\/\",\"name\":\"How to tackle governance, risk, and compliance - Pax8 Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/governance-risk-compliance\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/governance-risk-compliance\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/wp-content\\\/uploads\\\/sites\\\/13\\\/2023\\\/03\\\/AdobeStock_128410642_adobespark-1.jpeg\",\"datePublished\":\"2021-08-12T20:56:00+00:00\",\"dateModified\":\"2023-05-17T02:04:50+00:00\",\"description\":\"\u201cGovernance, risk, and compliance\u201d can sound intimidating, but we\u2019re here to break down these concepts and show you where to start.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/governance-risk-compliance\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.pax8.com\\\/blog\\\/governance-risk-compliance\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/governance-risk-compliance\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/wp-content\\\/uploads\\\/sites\\\/13\\\/2023\\\/03\\\/AdobeStock_128410642_adobespark-1.jpeg\",\"contentUrl\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/wp-content\\\/uploads\\\/sites\\\/13\\\/2023\\\/03\\\/AdobeStock_128410642_adobespark-1.jpeg\",\"width\":2000,\"height\":1333,\"caption\":\"Data governance and compliance\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/governance-risk-compliance\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to tackle governance, risk, and compliance\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/\",\"name\":\"Pax8 Blog\",\"description\":\"Where IT pros go to keep up with the cloud\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/#organization\",\"name\":\"Pax8 Blog\",\"url\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/wp-content\\\/uploads\\\/sites\\\/13\\\/2023\\\/03\\\/pax8-logo-white-blog-300x300-1.png\",\"contentUrl\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/wp-content\\\/uploads\\\/sites\\\/13\\\/2023\\\/03\\\/pax8-logo-white-blog-300x300-1.png\",\"width\":300,\"height\":300,\"caption\":\"Pax8 Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/#\\\/schema\\\/person\\\/4f1f5ecebcf730cc2be7b763a310a63c\",\"name\":\"narnold\",\"url\":\"https:\\\/\\\/www.pax8.com\\\/blog\\\/author\\\/narnold\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to tackle governance, risk, and compliance - Pax8 Blog","description":"\u201cGovernance, risk, and compliance\u201d can sound intimidating, but we\u2019re here to break down these concepts and show you where to start.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/","og_locale":"en_US","og_type":"article","og_title":"How to tackle governance, risk, and compliance - Pax8 Blog","og_description":"\u201cGovernance, risk, and compliance\u201d can sound intimidating, but we\u2019re here to break down these concepts and show you where to start.","og_url":"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/","og_site_name":"Pax8 Blog","article_published_time":"2021-08-12T20:56:00+00:00","article_modified_time":"2023-05-17T02:04:50+00:00","og_image":[{"width":2000,"height":1333,"url":"https:\/\/www.pax8.com\/blog\/wp-content\/uploads\/sites\/13\/2023\/03\/AdobeStock_128410642_adobespark-1.jpeg","type":"image\/jpeg"}],"author":"narnold","twitter_card":"summary_large_image","twitter_misc":{"Written by":"narnold","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/#article","isPartOf":{"@id":"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/"},"author":{"name":"narnold","@id":"https:\/\/www.pax8.com\/blog\/#\/schema\/person\/4f1f5ecebcf730cc2be7b763a310a63c"},"headline":"How to tackle governance, risk, and compliance","datePublished":"2021-08-12T20:56:00+00:00","dateModified":"2023-05-17T02:04:50+00:00","mainEntityOfPage":{"@id":"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/"},"wordCount":1296,"publisher":{"@id":"https:\/\/www.pax8.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/#primaryimage"},"thumbnailUrl":"https:\/\/www.pax8.com\/blog\/wp-content\/uploads\/sites\/13\/2023\/03\/AdobeStock_128410642_adobespark-1.jpeg","articleSection":["Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/","url":"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/","name":"How to tackle governance, risk, and compliance - Pax8 Blog","isPartOf":{"@id":"https:\/\/www.pax8.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/#primaryimage"},"image":{"@id":"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/#primaryimage"},"thumbnailUrl":"https:\/\/www.pax8.com\/blog\/wp-content\/uploads\/sites\/13\/2023\/03\/AdobeStock_128410642_adobespark-1.jpeg","datePublished":"2021-08-12T20:56:00+00:00","dateModified":"2023-05-17T02:04:50+00:00","description":"\u201cGovernance, risk, and compliance\u201d can sound intimidating, but we\u2019re here to break down these concepts and show you where to start.","breadcrumb":{"@id":"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/#primaryimage","url":"https:\/\/www.pax8.com\/blog\/wp-content\/uploads\/sites\/13\/2023\/03\/AdobeStock_128410642_adobespark-1.jpeg","contentUrl":"https:\/\/www.pax8.com\/blog\/wp-content\/uploads\/sites\/13\/2023\/03\/AdobeStock_128410642_adobespark-1.jpeg","width":2000,"height":1333,"caption":"Data governance and compliance"},{"@type":"BreadcrumbList","@id":"https:\/\/www.pax8.com\/blog\/governance-risk-compliance\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.pax8.com\/blog\/"},{"@type":"ListItem","position":2,"name":"How to tackle governance, risk, and compliance"}]},{"@type":"WebSite","@id":"https:\/\/www.pax8.com\/blog\/#website","url":"https:\/\/www.pax8.com\/blog\/","name":"Pax8 Blog","description":"Where IT pros go to keep up with the cloud","publisher":{"@id":"https:\/\/www.pax8.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.pax8.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.pax8.com\/blog\/#organization","name":"Pax8 Blog","url":"https:\/\/www.pax8.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.pax8.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.pax8.com\/blog\/wp-content\/uploads\/sites\/13\/2023\/03\/pax8-logo-white-blog-300x300-1.png","contentUrl":"https:\/\/www.pax8.com\/blog\/wp-content\/uploads\/sites\/13\/2023\/03\/pax8-logo-white-blog-300x300-1.png","width":300,"height":300,"caption":"Pax8 Blog"},"image":{"@id":"https:\/\/www.pax8.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.pax8.com\/blog\/#\/schema\/person\/4f1f5ecebcf730cc2be7b763a310a63c","name":"narnold","url":"https:\/\/www.pax8.com\/blog\/author\/narnold\/"}]}},"_links":{"self":[{"href":"https:\/\/www.pax8.com\/blog\/wp-json\/wp\/v2\/posts\/1432","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pax8.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pax8.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pax8.com\/blog\/wp-json\/wp\/v2\/users\/141"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pax8.com\/blog\/wp-json\/wp\/v2\/comments?post=1432"}],"version-history":[{"count":0,"href":"https:\/\/www.pax8.com\/blog\/wp-json\/wp\/v2\/posts\/1432\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.pax8.com\/blog\/wp-json\/wp\/v2\/media\/268"}],"wp:attachment":[{"href":"https:\/\/www.pax8.com\/blog\/wp-json\/wp\/v2\/media?parent=1432"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pax8.com\/blog\/wp-json\/wp\/v2\/categories?post=1432"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pax8.com\/blog\/wp-json\/wp\/v2\/tags?post=1432"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}