CapGRC
CapGRC
Resource center

Free GRC Resources

Practical guides, templates and webinars to help you build your GRC program — whether you use CapGRC or not.

17+Articles and guides
4Free templates
2Webinars available

All resources

Search our guides, articles, webinars and templates

23 results
Article
Cybersecurity

Zero Trust: why zero-trust architecture is becoming essential in Canada

The traditional perimeter security model has reached its limits. With the proliferation of remote work, cloud services and third-party access, Canadian organizations must adopt a r

9 min
Guide
Law 25

Security incident management under Law 25: obligations and best practices

Since September 2023, Law 25 has imposed strict obligations on Quebec organizations regarding privacy incident notification. An unreported or poorly managed incident can result in

10 min
Article
ISO 27001

ISO 27001 vs SOC 2: which certification should your Canadian organization choose?

Facing increasing security requirements, many Canadian organizations must choose between ISO 27001 and SOC 2. Both certifications address similar objectives but target different ma

11 min
Guide
Law 25

How to map your information assets in compliance with Law 25

Information asset mapping is the foundation of any effective GRC program and a Law 25 requirement to demonstrate that you know what personal information you hold.

8 min
Article
DORA

DORA: how Canadian companies with European operations must prepare

The European DORA regulation came fully into force on January 17, 2025. Canadian financial institutions offering services in Europe or collaborating with European entities are dire

10 min
Article
Risks

The 10 essential risk indicators for your CISO dashboard

An effective GRC dashboard is not measured by the number of indicators displayed, but by their relevance to decision-making. Here are the 10 KRIs that every CISO should monitor as

7 min
Article
NIS2

NIS2 and the Canadian public sector: anticipating new digital resilience requirements

The European NIS2 directive came into application in October 2024. Its implications affect Canadian organizations partnering with European entities in critical sectors.

9 min
Article
Internal audit

Artificial intelligence and GRC internal audit: opportunities and risks for Canadian organizations

Artificial intelligence is profoundly transforming internal audit practices. AI tools enable analysis of massive data volumes and anomaly detection, but also introduce new risks.

11 min
Guide
Law 25

Complete Guide to Law 25: Obligations and Compliance

Everything you need to know about Quebec's Law 25: obligations, timelines and practical steps to bring your organization into compliance.

12 min
Guide
Risk management

How to Conduct a Risk Assessment for an SME

Practical method to identify, assess and treat security risks in a small or medium-sized enterprise.

8 min
Guide
Privacy

DPIA: Practical Guide for Privacy Officers

How to conduct a Privacy Impact Assessment compliant with Law 25, step by step.

10 min
Article
Audit

5 Common Mistakes in GRC Internal Auditing

The most frequent pitfalls in internal audit programs and how to avoid them to gain efficiency.

7 min
Article
GRC

Managing Multiple GRC Frameworks Simultaneously

Strategies to align ISO 27001, Law 25 and PCI-DSS in a unified GRC program without duplicating efforts.

9 min
Article
ISO 27001

ISO 27001 Certification in 6 Months: Lessons Learned

How a Quebec SME obtained its ISO 27001 certification in 6 months with CapGRC.

11 min
Article
PCI-DSS

PCI-DSS v4.0: What You Need to Know

Analysis of the major changes in PCI-DSS version 4.0 and their impact on Canadian organizations.

8 min
Article
Regulation

Understanding DORA: The European Digital Resilience Regulation

Complete guide to the Digital Operational Resilience Act (DORA): scope, obligations and impact on Canadian financial institutions.

14 min
Article
Regulation

Understanding PIPEDA: Canada's Federal Privacy Law

Complete guide to the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada.

12 min
Template
Template

Risk register template

Pre-configured Excel spreadsheet to start your security risk register.

XLSX
Template
Template

Law 25 PIA template

Structured Word template for your privacy impact assessments.

DOCX
Template
Template

Law 25 compliance checklist

Complete checklist of Law 25 obligations by implementation phase.

PDF
Template
Template

Internal audit plan template

Template to structure your annual risk-based audit plan.

XLSX
Webinar

Law 25 — Phase 3: what changes in September 2024

Analysis of phase 3 obligations and action plan for your organization.

Recording available
Webinar

How to choose your first GRC framework

Decision guide: ISO 27001, SOC 2, or start with Law 25?

Recording available

Articles and guides

Cybersecurity

Zero Trust: why zero-trust architecture is becoming essential in Canada

The traditional perimeter security model has reached its limits. With the proliferation of remote work, cloud services and third-party access, Canadian organizations must adopt a r

9 min de lecture

Law 25

Security incident management under Law 25: obligations and best practices

Since September 2023, Law 25 has imposed strict obligations on Quebec organizations regarding privacy incident notification. An unreported or poorly managed incident can result in

10 min de lecture

ISO 27001

ISO 27001 vs SOC 2: which certification should your Canadian organization choose?

Facing increasing security requirements, many Canadian organizations must choose between ISO 27001 and SOC 2. Both certifications address similar objectives but target different ma

11 min de lecture

Law 25

How to map your information assets in compliance with Law 25

Information asset mapping is the foundation of any effective GRC program and a Law 25 requirement to demonstrate that you know what personal information you hold.

8 min de lecture

DORA

DORA: how Canadian companies with European operations must prepare

The European DORA regulation came fully into force on January 17, 2025. Canadian financial institutions offering services in Europe or collaborating with European entities are dire

10 min de lecture

Risks

The 10 essential risk indicators for your CISO dashboard

An effective GRC dashboard is not measured by the number of indicators displayed, but by their relevance to decision-making. Here are the 10 KRIs that every CISO should monitor as

7 min de lecture

NIS2

NIS2 and the Canadian public sector: anticipating new digital resilience requirements

The European NIS2 directive came into application in October 2024. Its implications affect Canadian organizations partnering with European entities in critical sectors.

9 min de lecture

Internal audit

Artificial intelligence and GRC internal audit: opportunities and risks for Canadian organizations

Artificial intelligence is profoundly transforming internal audit practices. AI tools enable analysis of massive data volumes and anomaly detection, but also introduce new risks.

11 min de lecture

Law 25

Complete Guide to Law 25: Obligations and Compliance

Everything you need to know about Quebec's Law 25: obligations, timelines and practical steps to bring your organization into compliance.

12 min de lecture

Risk management

How to Conduct a Risk Assessment for an SME

Practical method to identify, assess and treat security risks in a small or medium-sized enterprise.

8 min de lecture

Privacy

DPIA: Practical Guide for Privacy Officers

How to conduct a Privacy Impact Assessment compliant with Law 25, step by step.

10 min de lecture

Audit

5 Common Mistakes in GRC Internal Auditing

The most frequent pitfalls in internal audit programs and how to avoid them to gain efficiency.

7 min de lecture

GRC

Managing Multiple GRC Frameworks Simultaneously

Strategies to align ISO 27001, Law 25 and PCI-DSS in a unified GRC program without duplicating efforts.

9 min de lecture

ISO 27001

ISO 27001 Certification in 6 Months: Lessons Learned

How a Quebec SME obtained its ISO 27001 certification in 6 months with CapGRC.

11 min de lecture

PCI-DSS

PCI-DSS v4.0: What You Need to Know

Analysis of the major changes in PCI-DSS version 4.0 and their impact on Canadian organizations.

8 min de lecture

Regulation

Understanding DORA: The European Digital Resilience Regulation

Complete guide to the Digital Operational Resilience Act (DORA): scope, obligations and impact on Canadian financial institutions.

14 min de lecture

Regulation

Understanding PIPEDA: Canada's Federal Privacy Law

Complete guide to the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada.

12 min de lecture

Want to go further?

See how CapGRC can help you structure your GRC program and automate your compliance.