
Master governance, risk and compliance by designing, implementing, and managing GRC programs aligned with the NIST RMF; prepare for the 125-question CGR exam with seven core domains.
Master governance, risk, and compliance through the CGRC Certification Masterclass, aligned with the NIST Risk Management Framework, covering seven core domains, controls, assessments, audits, continuous monitoring, and exam readiness.
Discover how governance, risk management, and compliance form a unified GRC program, guided by maturity models, risk-based decisions, and integrated reporting to embed security across the organization.
Explore proven risk management and compliance frameworks, including NIST, Cobit, and ISO/IEC standards, and learn how to tailor them to your organization for governance, IT management, and security resilience.
Embed security and privacy throughout the SDLC, from planning to retirement, using defense in depth, security architecture, least privilege, secure coding, and comprehensive testing.
Navigate the information lifecycle by classifying data by sensitivity, implementing retention and disposal policies, mapping data flows, and labeling data to enforce security and privacy controls across the organization.
Explore the CIA triad plus non-repudiation and privacy. Learn how confidentiality, encryption, integrity, and availability guide threat evaluation, control selection, and security measurement.
Map your digital territory with a living asset inventory and defined system boundaries. Implement boundary protection, data classification, and data flow mapping across cloud and service provider boundaries.
Explore administrative, technical, physical security controls; learn control customization, assessment methods, and layered GRC deployment to meet regulatory requirements.
Define clear compliance roles, responsibilities, and role-based training across team structures, role definitions, responsibility assignment models, and training requirements to ensure accountability and align with the NIST Cybersecurity framework.
Develop a compliant program built on charters, resource planning, implementation roadmaps, KPIs, and stakeholder engagement, backed by executive sponsorship to protect the organization and enable growth.
Explore ISO/IEC frameworks, FedRAMP, PCI DSS, and CMMC, and learn how to select and integrate them to build a unified, risk-based security and privacy program.
Explore how FISMA, HIPAA, executive orders, and GDPR shape federal and global privacy programs through a risk-based, privacy-by-design approach with continuous monitoring and governance for regional laws.
Define system identification standards, naming conventions, and central system registration with metadata, owner, function, and security categorization. Inventory and classify system criticality and interdependencies to support governance and risk management.
Analyze business functions and critical processes to align IT and cybersecurity with business outcomes, perform the BIA, define mission essential functions, capture functional requirements, document architecture, and map user access.
Identify data types by distinguishing structured and unstructured data, analyze database content, inventory file systems, map data flows, and classify data by criteria to prioritize controls.
Categorize information systems with FIPS 199 to assess confidentiality, integrity, and availability and assign the system level. Map objectives to ISO 27001 controls; perform gap analyses, and address DPIA considerations.
Learn risk assessment methodology, distinguishing quantitative and qualitative approaches, and apply tools like threat modeling, vulnerability assessments to determine impact levels across business, financial, operational, and reputational criteria.
Learn how to select applicable security baselines through risk categorization, regulatory mapping, and industry standards, then identify common and system-specific controls with hybrid implementations and robust documentation.
Select and implement security enhancements using criteria, risk-based prioritization, cost-benefit analysis, and feasibility assessments; apply overlays, compensating controls when needed, and document all steps.
Develop a data handling policy with a classification matrix and procedures, enforcing least privilege, encryption, and secure disposal, plus data marking and data loss prevention controls.
Select the right system security plan (SSP) template, document control implementation statements, and record control status to convey the SSP's current security posture.
Assign control ownership by aligning criteria with subject matter expertise and daily responsibilities. Document roles, SLAs, MOUs, and a RACI, and tie ownership to KPIs within governance and risk programs.
Align security and privacy controls with enterprise architecture, business objectives, and digital transformation, mapping regulatory requirements and frameworks to deliver a risk-based, compliant, and culture-aware implementation.
Identify control types—technical, operational, and management—and assign implementation responsibility through categorization. Align evaluation with continuous monitoring and governance to support audits.
Develop a risk-based documentation review cadence from inventory to triggers, assign owners, ensure version control, and refresh updates for GDPR, HIPAA, and internal policies.
Plan and implement controls with a work breakdown structure, resource allocation, and a detailed schedule, then test, document, and validate technical, administrative, and physical deployments.
Learn how compensating controls fill gaps when primary controls fall short, assess equivalency, manage residual risk, and document deviations through risk acceptance and periodic reassessment.
prioritize risks with a plan of action and milestones to close gaps and stay aligned with security and compliance goals, while maintaining a dynamic risk register and milestone tracking.
Develop standardized policies and procedures with clear structure, approval, distribution, and exception handling, and document plans, evidence, and controls with versioned access and archiving.
Assemble a balanced audit team with a certified lead assessor and SMEs, ensuring independence, role clarity, stakeholder mapping, and alignment with NIST or ISO frameworks.
Define objectives, scope, and schedule for assessments, specify success criteria and deliverables, and plan resources, tools, and logistics to ensure actionable outcomes.
Identify and prioritize assets through a risk-based inventory, then tailor assessment methods and resources to testing, sampling, and tooling to ensure credible, efficient security and privacy evaluations.
Demonstrates how to leverage prior audits and evidence to anticipate auditor expectations and close gaps through remediation verification, trend analysis, and robust documentation.
Standardize plan documentation for security, privacy, and incident response by applying a consistent structure, purpose, scope, responsibilities, procedures, escalation, review cycles, and version control to ensure approvals and secure distribution.
Are you looking to become a Certified in Governance, Risk and Compliance (CGRC) professional?
The CGRC certification, offered by (ISC)², is a globally recognized credential that validates your ability to manage information security risk and ensure regulatory compliance across systems and organizations. It bridges the gap between cybersecurity and organizational governance.
This course is designed to help you master the CGRC Common Body of Knowledge (CBK) efficiently. Built around the official exam domains, it offers structured learning modules, real-world examples, and exam-focused strategies to help you prepare confidently for the CGRC exam.
What You’ll Learn:
Authorization and Risk Management Frameworks – Understand NIST RMF and other global approaches to security authorization and continuous monitoring.
Information System Lifecycle – Learn how to apply risk-based decision-making across the system development lifecycle.
Control Selection and Assessment – Master how to select, implement, and evaluate controls aligned with compliance requirements.
Continuous Monitoring and Reporting – Gain insights into maintaining security posture and compliance through ongoing oversight.
Exam Preparation and Application – Reinforce your understanding through practice scenarios and expert tips.
Who Should Enroll?
This course is ideal for information security professionals, system owners, risk managers, compliance officers, auditors, and consultants aiming to support secure and compliant IT systems.
Gain the skills and confidence to lead your organization’s GRC initiatives. Enroll today and take your first step toward becoming a CGRC-certified professional!