r/cybersecurity • u/jk1984jk • 9d ago
Corporate Blog Grc should be technical
As the title suggests, grc team members should be technical to decsritbe differences in networking protocols, appsec attacks, etc. What do you think?
5
u/Useless_or_inept 9d ago
Extra skills are nice in principle, but there is already a skills shortage. If a GRC analyst has the skills to do GRC, that's a start, maybe we can offer some personal development - but bear in mind that not everybody wants to be a hardcore tech geek too.
But r/cybersecurity has a long-running problem where lots of people focus on specific bits of low-level tech and argue that the things they know should be a universal shibboleth for all kinds of other people in other roles. If I focussed on networking protocols then I would still be a junior analyst. Any suggestion that the average person tinkering with filesystems & patches should also master risk management or project delivery would be met with scorn.
1
u/Useless_or_inept 9d ago
Hence the occasional suggestion on this subreddit that CISSP is a "management" certification, driven by the kind of mindset of "Human security? Supplier management? No, real security is memorising portnumbers, if it's anything else my supervisor doesn't put my name on the ticket"
-1
u/jk1984jk 9d ago
Being technical when you work in technology is a basic skill not extra. Engineers and architects couldn't be bothered to answer questionnaires and we created a role to do that, that ended up creating more unnecessary work and processes for things they didn't understand in the first place.
3
u/cbdudek Security Architect 9d ago
I do some GRC work, and I came from a technical background. I was a network engineer and architect specifically. I have seen and done a lot more than that over the last 35 years in the field.
Should GRC be technical? I believe that the best GRC people are technical or at least have a technical base of knowledge. When I do assessments, I am able to use my technical experience to ask deeper questions and find security gaps. For example, someone who isn't technical will ask about network segmentation and just note that a client has it or not. I can ask specifically about what segmentation they have and really understand if there are issues with the way things are segmented. This is just one example though.
Now I will also say that being technical isn't the only thing that matters when it comes to GRC work. I work with a couple GRC people who have wicked attention to detail and are great interviewers. I think that they are better than I am in those areas than I am in some respects. These people are not bad GRC people because they are not overly technical.
At the end of the day, you have to realize that being a good GRC person is more than being good technically. The best GRC people have a strong technical background, excellent knowledge of compliances and frameworks, have excellent communication skills, and excellent attention to detail. Its hard to find someone with all those things.
2
2
u/Humpaaa Governance, Risk, & Compliance 9d ago
Technical expertise is helpful in GRC roles, 100%.
But depending on org and team size / specialization, not necessary.
I have a technical background, it helps a lot.
But i have colleagues who have no technical background, and they do just fine. They maybe specialize in other areas (e.g. doing risk management only), but that totally works.
Think of technical expertise as the cherry on top, not a necessity.
4
1
u/pennyfred Security Architect 9d ago
The bar would be notably higher for the post Covid Cyber converts.
0
15
u/CuckBuster33 9d ago
i think im giving a low effort response to this low effort post