# GRC-Engineer/awesome-security-GRC

Curated list of resources for security Governance, Risk Management, Compliance and Audit professionals and enthusiasts (if they exist).

Repository: https://github.com/GRC-Engineer/awesome-security-GRC
Canonical: https://ross.abutalabs.com/products/awesome-security-grc
License Family: other
Topics: risk-management, grc, security, compliance, governance, audit
Last push: 2025-09-07T22:10:26+00:00

## Health v2 (maintenance only)
Score: 50/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 40, release rhythm 35, longevity 100
- inputs: {"age_days": 1987, "days_push": 360, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1077, forks 214 (observed 2026-08-28T04:03:29.543962+00:00)

## What it is
A curated list of resources for security Governance, Risk Management, Compliance, and Audit (GRC) professionals. It collects frameworks, books, talks, podcasts, certifications, and repositories relevant to the GRC field.

## Use cases
- find resources for learning security GRC
- prepare for a security compliance audit
- compare risk management frameworks like FAIR and ISO 27005
- find GRC podcasts and certifications
- onboard into a security governance or compliance role
- build a security compliance program from scratch

## When to choose
- you work in or are entering security governance, risk, or compliance
- you need a starting point of vetted GRC learning materials
- you want community-curated frameworks, books, and certifications in one place

## When to avoid
- you need software tooling to automate compliance workflows
- you want hands-on technical security resources like penetration testing
- you need an official or authoritative source rather than a curated list

## Facets
- artifact type: learning-resource
- maturity: active
- function: documentation, security
- domain: security, awesome-lists, education
- platform: -
- tags: awesome-list, grc, governance, risk-management, compliance, audit, curated-resources, web-server

## Member repositories
- GRC-Engineer/awesome-security-GRC (main) score 50

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:29.543962+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:53:12.981061+00:00, confidence not recorded.
  - readme: https://github.com/GRC-Engineer/awesome-security-GRC (fetched 2026-08-28T04:03:29.543962+00:00, sha c05fb0130b26)
- Data as of 2026-08-30T08:39:29.467469+00:00.
