The specifications have been derived from our previous experience with Security and also Googling for GRC.
There might also be a Data Warehouse, which is very useful for providing data for Analysis, Enquiries, Reports and Business Intelligence.
Our Access Control Data Model is also relevant.