🏠 Home 📚 Resources Governance, Risk, & Compliance
📜 Security+ SY0-701 - Exam Objective 5

Governance, Risk, and Compliance

Master risk management frameworks, compliance requirements, security policies, and data privacy for the CompTIA Security+ SY0-701 exam

📅 Updated January 2025 📖 10 min read ✍️ By Security+ Team

This section covers Exam Objective 5 of the CompTIA Security+ SY0-701 exam. It focuses on the organizational side of security: managing risk, adhering to laws and regulations, and establishing effective policies.

⚖️ Risk Assessment

Risk management is the process of identifying, assessing, and prioritizing risks to minimize their impact.

📋 Compliance Frameworks

Organizations must adhere to various standards and regulations depending on their industry and location.

📜 Security Policies

Policies are high-level statements of management intent. They guide the behavior of employees and the configuration of systems.

🔒 Data Privacy

Protecting sensitive data is a core component of GRC. This involves classification, handling, and retention.

Data Types

  • PII: Personally Identifiable Information (Name, SSN).
  • PHI: Protected Health Information (Medical records).
  • IP: Intellectual Property (Trade secrets).

Controls

  • Classification: Labeling data (Public, Confidential, Restricted).
  • DLP: Data Loss Prevention tools to stop unauthorized exfiltration.
  • Sovereignty: Legal requirements that data is subject to the laws of the country it is located in.

📚 Additional Resources

🎯 Ready to Test Your Knowledge?

Take our free Security+ Practice Quiz and see how well you understand GRC!

Start Practice Quiz →