What is governance, risk and compliance in security?
GRC organizes responsibilities, decisions and controls to manage risk and meet requirements. Taura supports policies, processes and evidence for references such as ISO/IEC 27001 and PCI DSS, obligations under the LGPD (Brazil's General Data Protection Law) and Central Bank of Brazil requirements, and helps set up the SOC that supports monitoring.
When you need to prove your controls
What we deliver
For institutions regulated by the Central Bank of Brazil
Financial and payment institutions must maintain a cybersecurity policy, controls and evidence aligned with Central Bank of Brazil resolutions, such as CMN Resolution 4,893 and BCB Resolution 85, amended in December 2025 by CMN Resolution 5,274 and BCB Resolution 538, in force since March 1, 2026. Among other points, the amendments require an annual penetration test conducted by independent professionals. Companies in their ecosystem, such as technology suppliers, often have to demonstrate controls by contract. Taura helps you understand what applies to your operation and keep the program running throughout the year.
A plan with owners and deadlines
Frequently asked questions
Does Taura issue certifications?
No. Taura prepares the company and supports implementation. ISO/IEC 27001 certification and PCI DSS validation follow their own processes and assessors, and no consulting service can guarantee approval.
What does setting up a SOC mean?
Here, SOC means security operations center. We help define detection use cases, monitoring and response processes, and integration with tools and providers. This is different from SOC 1 and SOC 2 reports, which are control assessments.
Which PCI DSS version should we follow?
The current version published by the PCI Security Standards Council, confirmed with your compliance lead and your assessor. The plan must take the company's cardholder data environment into account.
Does governance slow the company down?
It depends on how it is designed. Clear responsibilities and controls proportional to risk reduce rework and improvised decisions.