I want to understand what kind of policies or procedure, or risks are majorly handled through GRC. Is it all or few. e.g. HR policies, IT Security etc.