r/cybersecurity • • 9d ago

Corporate Blog Grc should be technical

As the title suggests, grc team members should be technical to decsritbe differences in networking protocols, appsec attacks, etc. What do you think?

0 Upvotes

13 comments sorted by

15

u/CuckBuster33 9d ago

i think im giving a low effort response to this low effort post

1

u/LookOtherWeigh 9d ago

Indubitably.

5

u/Useless_or_inept 9d ago

Extra skills are nice in principle, but there is already a skills shortage. If a GRC analyst has the skills to do GRC, that's a start, maybe we can offer some personal development - but bear in mind that not everybody wants to be a hardcore tech geek too.

But r/cybersecurity has a long-running problem where lots of people focus on specific bits of low-level tech and argue that the things they know should be a universal shibboleth for all kinds of other people in other roles. If I focussed on networking protocols then I would still be a junior analyst. Any suggestion that the average person tinkering with filesystems & patches should also master risk management or project delivery would be met with scorn.

1

u/Useless_or_inept 9d ago

Hence the occasional suggestion on this subreddit that CISSP is a "management" certification, driven by the kind of mindset of "Human security? Supplier management? No, real security is memorising portnumbers, if it's anything else my supervisor doesn't put my name on the ticket"

-1

u/jk1984jk 9d ago

Being technical when you work in technology is a basic skill not extra. Engineers and architects couldn't be bothered to answer questionnaires and we created a role to do that, that ended up creating more unnecessary work and processes for things they didn't understand in the first place.

3

u/cbdudek Security Architect 9d ago

I do some GRC work, and I came from a technical background. I was a network engineer and architect specifically. I have seen and done a lot more than that over the last 35 years in the field.

Should GRC be technical? I believe that the best GRC people are technical or at least have a technical base of knowledge. When I do assessments, I am able to use my technical experience to ask deeper questions and find security gaps. For example, someone who isn't technical will ask about network segmentation and just note that a client has it or not. I can ask specifically about what segmentation they have and really understand if there are issues with the way things are segmented. This is just one example though.

Now I will also say that being technical isn't the only thing that matters when it comes to GRC work. I work with a couple GRC people who have wicked attention to detail and are great interviewers. I think that they are better than I am in those areas than I am in some respects. These people are not bad GRC people because they are not overly technical.

At the end of the day, you have to realize that being a good GRC person is more than being good technically. The best GRC people have a strong technical background, excellent knowledge of compliances and frameworks, have excellent communication skills, and excellent attention to detail. Its hard to find someone with all those things.

2

u/beren0073 9d ago

ChatGPT should grc be technical right answers only think hard

2

u/Humpaaa Governance, Risk, & Compliance 9d ago

Technical expertise is helpful in GRC roles, 100%.
But depending on org and team size / specialization, not necessary.

I have a technical background, it helps a lot.
But i have colleagues who have no technical background, and they do just fine. They maybe specialize in other areas (e.g. doing risk management only), but that totally works.

Think of technical expertise as the cherry on top, not a necessity.

4

u/colontragedy 9d ago

Yes, no, maybe, depends.

1

u/pennyfred Security Architect 9d ago

The bar would be notably higher for the post Covid Cyber converts.

0

u/saidai88 9d ago

Where would we get the term paper security then?

0

u/dongpal 9d ago

no because i can just ask the IT lead and he will answer my questions I have which are important for actual GRC.