eGRC vs. IT GRC

07.03.2011
Most analysts break the market down into two broad categories: and Enterprise GRC (eGRC). The vendors generally don't make it any easier for potential enterprise customers, as the IT GRC players often claim they do eGRC, and all the eGRC vendors saying they encompass IT as well.

To a degree, they're both right. RSA Archer, for example, generally regarded as something of a hybrid leaning more to the IT side, has had some success in the eGRC market.

"They're not mutually exclusive, and that's why it gets fuzzy," said Paul Proctor, Gartner vice president of security and risk management. "Each says they do the other, and, to some degree, they are all correct. They are separated because some are clearly better at the eGRC top-down look at everything, and some that are clearly from an IT background and better at IT."