GRC for Security Professionals

Master GRC for Security Professionals

Turn security from a cost center into a strategic business enabler. Build effective Governance, Risk, and Compliance (GRC) programs that align security with business objectives, manage real risk, and demonstrate clear value to executives and auditors.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Design and implement a practical security governance framework that aligns with business objectives
✓Identify, assess, prioritize, and treat cybersecurity risks using industry-standard methodologies
✓Build and maintain effective compliance programs (ISO 27001, SOC 2, NIST, GDPR, HIPAA, etc.)
✓Create clear security policies, standards, and procedures that are actually followed
✓Develop meaningful security metrics and executive reporting that demonstrate value and risk reduction
✓Establish governance structures, roles, and processes that drive accountability and continuous improvement
GRC201 | Premium tier | 16 modules across 4 phases | 36–40 hours at your own pace | 40 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Phase 1: Foundations

Module 0Course OrientationCourse Preview

What GRC for Security Professionals teaches: build a working governance, risk, and compliance program, a risk register you actually work, policies people follow, controls mapped to ISO 27001, NIST CSF, SOC 2, GDPR, and CMMC, and audit evidence produced as a byproduct. The program you'll build, what you walk away with, and how the course is structured. Start here.

Show 6 lessonsHide lessons
  1. 0.10.1 The Problem with GRC TrainingPreview
  2. 0.20.2 Who This Course Is ForPreview
  3. 0.30.3 Course Structure and Module MapPreview
  4. 0.40.4 Prerequisites and What You NeedPreview
  5. 0.50.5 How to Learn from This CoursePreview
  6. 0.6Module SummaryPreview
Module 1What GRC Actually Is, and Why It Fails

The governance-risk-compliance triad as an operating system. How the three disciplines connect and reinforce each other. Why most GRC programs fail, with detailed case studies of each failure mode. Organizational positioning, reporting lines, and regulatory drivers.

Show 6 lessonsHide lessons
  1. 1.11.1 The GRC Triad as an Operating System
  2. 1.21.2 Why GRC Programs Fail: Case Studies
  3. 1.31.3 Organizational Positioning of GRC
  4. 1.41.4 Regulatory Drivers: Why Organizations Do GRC
  5. 1.5Module Summary
  6. 1.6Check My Knowledge
Module 2Building the Policy Framework

Policy as executable governance. The policy hierarchy and the enforcement test that separates its levels. Why policies become shelf-ware and how to write ones that hold. The minimum viable policy set. The policy lifecycle. Mapping policies to the controls that enforce them and the requirements they satisfy.

Show 7 lessonsHide lessons
  1. 2.12.1 The Policy Hierarchy
  2. 2.22.2 Why Policies Fail, and How to Write Ones That Work
  3. 2.32.3 The Minimum Viable Policy Set
  4. 2.42.4 The Policy Lifecycle
  5. 2.52.5 Mapping Policies to Controls and Regulations
  6. 2.6Module Summary
  7. 2.7Check My Knowledge

Phase 2: Risk Management

Module 3Risk Assessment Methodology

The risk engine the policy framework has been referencing. Vocabulary, four identification methods, calibrated scoring, appetite and tolerance, the register, and the evidence that keeps control effectiveness ratings honest.

Show 8 lessonsHide lessons
  1. 3.13.1 Risk Assessment Fundamentals
  2. 3.23.2 Risk Identification
  3. 3.33.3 Risk Analysis: Scoring and Calibration
  4. 3.43.4 Risk Appetite and Tolerance
  5. 3.53.5 Building the Risk Register
  6. 3.63.6 Evidence: Turning Telemetry into Register Entries
  7. 3.7Module Summary
  8. 3.8Check My Knowledge
Module 4Risk Treatment and Controls

Turning scored risks into decisions and controls. The four treatment options in the order you consider them, control selection on five criteria, the Statement of Applicability, treatment plans with targets, and the verification that measures whether any of it worked.

Show 7 lessonsHide lessons
  1. 4.14.1 The Four Treatment Options
  2. 4.24.2 Control Selection
  3. 4.34.3 The Statement of Applicability
  4. 4.44.4 Treatment Plans and Residual Risk
  5. 4.54.5 Verifying That Controls Operate
  6. 4.6Module Summary
  7. 4.7Check My Knowledge
Module 5Risk Monitoring and Reporting

Keeping the register true between reviews. Metrics that measure exposure as well as controls, dashboards for two audiences, board reporting in twenty minutes, escalation with written triggers, the quarterly review, and queries that produce trends rather than points.

Show 8 lessonsHide lessons
  1. 5.15.1 Risk Indicators and Control Metrics
  2. 5.25.2 Dashboards for Two Audiences
  3. 5.35.3 Board Reporting
  4. 5.45.4 Escalation
  5. 5.55.5 The Quarterly Review
  6. 5.65.6 Queries That Produce Trends
  7. 5.7Module Summary
  8. 5.8Check My Knowledge

Phase 3: Framework Implementation

Module 6ISO 27001 Implementation

Mapping the risk programme onto ISO 27001. The clauses are the engine and Annex A is the toolbox. Scope, context, planning, support, audit, improvement, the full Statement of Applicability, and certification through to surveillance.

Show 9 lessonsHide lessons
  1. 6.16.1 How the Standard Is Built
  2. 6.26.2 Context, Scope, and Leadership
  3. 6.36.3 Planning: Clause 6
  4. 6.46.4 Support and Operation
  5. 6.56.5 Performance and Improvement
  6. 6.66.6 Annex A and the Full SoA
  7. 6.76.7 Certification
  8. 6.8Module Summary
  9. 6.9Check My Knowledge
Module 7NIST CSF 2.0 Implementation

A framework you cannot be certified against, and why it earns its place next to one you can. Six functions, profiles with real targets, implementation tiers, and running CSF alongside ISO 27001 without collecting evidence twice.

Show 8 lessonsHide lessons
  1. 7.17.1 What CSF Is For
  2. 7.27.2 The Govern Function
  3. 7.37.3 The Five Operational Functions
  4. 7.47.4 Current and Target Profiles
  5. 7.57.5 Implementation Tiers
  6. 7.67.6 Running CSF Alongside ISO 27001
  7. 7.7Module Summary
  8. 7.8Check My Knowledge
Module 8SOC 2 Implementation

An attestation rather than a certification, tested against controls you write yourself. The system description, the criteria, evidence across an observation window, the examining firm, and using the report once you hold it.

Show 8 lessonsHide lessons
  1. 8.18.1 What a SOC 2 Report Is
  2. 8.28.2 The System Description
  3. 8.38.3 The Criteria and What They Test
  4. 8.48.4 Evidence Across the Window
  5. 8.58.5 Working with the Examining Firm
  6. 8.68.6 Using the Report
  7. 8.7Module Summary
  8. 8.8Check My Knowledge
Module 9Data Protection and Privacy

UK GDPR, the DPA 2018 and the Data (Use and Access) Act 2025 read together. Lawful bases including the new seventh, records of processing, impact assessments, individual rights and the new complaints obligation, breach notification, and transfers.

Show 9 lessonsHide lessons
  1. 9.19.1 The UK Regime as It Stands
  2. 9.29.2 Lawful Bases
  3. 9.39.3 Records of Processing
  4. 9.49.4 Impact Assessments
  5. 9.59.5 Individual Rights and Complaints
  6. 9.69.6 Breach Notification
  7. 9.79.7 Transfers and Accountability Roles
  8. 9.8Module Summary
  9. 9.9Check My Knowledge
Module 10CMMC Implementation

A certification regime attached to one customer, currently mid-reform. Identifying controlled information, the 110 requirements at objective grain, the plan and the score, assessment and affirmation, and the scoping decision that sets the cost.

Show 8 lessonsHide lessons
  1. 10.110.1 The Programme and Where It Stands
  2. 10.210.2 Identifying What You Hold
  3. 10.310.3 The 110 Requirements
  4. 10.410.4 The Plan, the Score, and What You Can Defer
  5. 10.510.5 Assessment and Affirmation
  6. 10.610.6 Scoping and the Enclave
  7. 10.7Module Summary
  8. 10.8Check My Knowledge

Phase 4: Governance Operations

Module 11Security Awareness

Every framework in this course requires awareness training and none tells you how to make it work. Behaviour rather than topics, friction rather than content, simulations that build detection rather than punish, and measurement that can detect its own failure.

Show 8 lessonsHide lessons
  1. 11.111.1 Why Awareness Programmes Fail
  2. 11.211.2 Designing Interventions That Work
  3. 11.311.3 Running Simulations
  4. 11.411.4 Role-Specific Training
  5. 11.511.5 The Champion Network
  6. 11.611.6 Measuring the Programme
  7. 11.7Module Summary
  8. 11.8Check My Knowledge
Module 12Audit Management

Running audits as a programme rather than a series of events. Internal audit that finds things, external audits that verify them, findings that close and stay closed, and several frameworks on one set of evidence.

Show 8 lessonsHide lessons
  1. 12.112.1 The Audit Landscape
  2. 12.212.2 Building the Internal Programme
  3. 12.312.3 Conducting the Audit
  4. 12.412.4 Managing the External Audit
  5. 12.512.5 The Finding Lifecycle
  6. 12.612.6 Running Several Audits at Once
  7. 12.7Module Summary
  8. 12.8Check My Knowledge
Module 13GRC Leadership

Running a function rather than a process. Translating risk into terms a board can compare, reporting that drives decisions, committees with real authority, budget arguments that survive a finance director, and delivering bad news early.

Show 7 lessonsHide lessons
  1. 13.113.1 Translating Risk for the Board
  2. 13.213.2 The Board Report
  3. 13.313.3 Committees and Where Decisions Get Taken
  4. 13.413.4 Budgeting and the Cost of Inaction
  5. 13.513.5 Delivering Bad News
  6. 13.6Module Summary
  7. 13.7Check My Knowledge
Module 14Regulatory Change Management

The discipline that keeps everything else from going quietly out of date. Watching primary sources, assessing what a change actually requires, absorbing it into the programme rather than beside it, and maintaining a scan that survives years.

Show 6 lessonsHide lessons
  1. 14.114.1 Watching for Change
  2. 14.214.2 Assessing What It Requires
  3. 14.314.3 Turning It Into Work
  4. 14.414.4 Keeping the Scan Working
  5. 14.5Module Summary
  6. 14.6Check My Knowledge
Module 15Building and Operating the GRC Function

Whether anybody actually has the capacity. Structure and the one activity that needs independence, the skills the work really requires, tooling as a sequencing question, cadences as the operating model, and what a maturity score can honestly support.

Show 7 lessonsHide lessons
  1. 15.115.1 Where the Function Sits
  2. 15.215.2 Who Does the Work
  3. 15.315.3 Tooling
  4. 15.415.4 The Operating Model
  5. 15.515.5 Assessing the Function
  6. 15.6Module Summary
  7. 15.7Check My Knowledge
Module 16Sector Governance and Emerging Requirements

What changes when obligations come from a sector regulator, company law, or an insurer rather than a general framework. Four audiences, one evidence structure, and where all of it is heading.

Show 6 lessonsHide lessons
  1. 16.116.1 When the Regulator Has a Sector View
  2. 16.216.2 When a Regulator Stops Asking About Policies
  3. 16.316.3 Obligations That Arrive Through Company Law
  4. 16.416.4 Underwriters, Emerging Requirements, and What You Do Next
  5. 16.5Module Summary
  6. 16.6Check My Knowledge

Phase 0: Course Resources

ResourcesCheatsheets

The scales, matrices, mappings and report skeletons, with what each instrument decides and where it misleads.

Show 6 lessonsHide lessons
  1. 1Scoring Risk Defensibly
  2. 2Frameworks and Cross-Mapping
  3. 3Privacy and Breach Notification
  4. 4Policies, Audits and Findings
  5. 5Metrics and the Board
  6. 6Running the Function
ResourcesCookbooks

Ordered procedures for the work a GRC function actually does: assessments, certifications, audits, breaches and board cycles.

Show 7 lessonsHide lessons
  1. 1Running a Risk Assessment
  2. 2Getting to a Certification
  3. 3Handling a Notifiable Breach
  4. 4Surviving an Audit
  5. 5Building a Policy Set
  6. 6Preparing the Board Report
  7. 7Absorbing a New Regulation
ResourcesLab Setup

A working register, policy set, control map and evidence pack, built from nothing and then tested against the failures that make them useless.

Show 3 lessonsHide lessons
  1. 1Building the Register
  2. 2Controls, Evidence and the Gaps
  3. 3Verify, and What the Lab Cannot Teach
ResourcesWalkthroughs

Six cases reasoned end to end, including the ones where every artifact was current and the function was achieving nothing.

Show 6 lessonsHide lessons
  1. 1The Dashboard That Was Ninety-Four Percent
  2. 2The Date That Was Already Impossible
  3. 3The Register Nobody Argued With
  4. 4The Notification Nobody Wanted to Make
  5. 5The Finding That Was Not One
  6. 6The Risk With No Owner
ResourcesPlaybooks

What to do when a regulator writes, an auditor raises a finding, a customer sends a questionnaire, or somebody asks for an exception.

Show 7 lessonsHide lessons
  1. 1A Regulator Has Written
  2. 2A Customer Questionnaire Arrives
  3. 3An Auditor Raises a Finding
  4. 4Somebody Wants an Exception
  5. 5A Data Subject Request Arrives
  6. 6A Supplier Has Been Breached
  7. 7Somebody Asks If We Are Compliant
ResourcesPlayground

The exam, the lab pack, the artifacts you built, and the two products this course bridges into.

ResourcesReferences & Further Reading

External sources this course draws on: frameworks, standards, regulator guidance and vendor documentation.

Show 1 lessonHide lessons
  1. 1References & Further Reading

Course Completion

CompletionCourse Exam

GRC for Security Professionals end-of-course exam: a simulation-based assessment testing whether you can establish what binds an organization, grade gaps against evidence that already exists, sequence work against a date you do not control, and take a board a decision it can act on.

Show 1 lessonHide lessons
  1. 1Course Completion. GRC for Security Professionals

Course overview

The GRC for Security Professionals course is built specifically for security professionals, GRC professionals, and security leaders responsible for building and maturing governance programs. You'll gain practical expertise to:

✓ Design and implement security governance frameworks that align with business goals
✓ Identify, assess, and manage cybersecurity risks in a structured, business-relevant way
✓ Build and maintain effective compliance programs (ISO 27001, SOC 2, NIST, GDPR, etc.)
✓ Create meaningful policies, metrics, and reporting that executives actually understand and support

By the end, you'll have the knowledge, frameworks, and tools to build a mature GRC program that reduces risk, improves security posture, and positions security as a trusted business partner.

How this course works

Most GRC fails by producing documents rather than changing anything. This course is built around the opposite loop, and runs it through every framework it implements.

1. Write the policy somebody can comply with. A policy nobody can follow is a finding waiting to be written against you. The test is whether an ordinary employee could act on it.

2. Assess risk against something real. A register scored from opinion produces an order nobody defends. Method first, then the scoring, then the register.

3. Treat the risk with a control that exists. A treatment decision with no owner, no date and no evidence is a treatment decision that has not been made.

4. Monitor the control, not the document. Controls decay silently. What proves a control still works, and who checks, is the difference between a program and a binder.

5. Report so somebody decides. A board paper that produces no decision is a status update. The reporting module is about the decision it is meant to cause.

The frameworks, ISO 27001, NIST CSF 2.0, SOC 2 and CMMC, are then implemented through that same loop rather than as separate checklists.

What this course assumes

No minimum experience and no prerequisite course. Every framework is introduced from what it asks for and why, and the course assumes you are a practitioner rather than an auditor.

What makes it go faster: an organization you are actually responsible for, because every exercise produces an artifact you can use. Not required.

What this course does not cover: legal advice, audit as a profession, and technical security controls in depth. This is building and running the governance function.

Who this course is for

You're a security professional, GRC professional, or security leader responsible for building or maturing governance, risk, and compliance programs. This course is built for you if you want to:

✓ Move from fragmented security activities to a structured, business-aligned GRC program
✓ Bridge the gap between technical security controls and executive/audit expectations
✓ Learn how to effectively manage risk, compliance, and governance without slowing down the business
✓ Gain the frameworks and practical skills needed to lead GRC initiatives

In short: if you want to build governance programs that are both effective and respected across the organization, this course is for you.

What you'll learn

By the end of this GRC for Security Professionals course you will be able to:

✓ Design and operate a security governance framework tailored to your organization's size and maturity
✓ Apply risk assessment methodologies (NIST RMF, ISO 31000, FAIR, etc.) to make informed decisions
✓ Build and manage compliance programs with practical controls and evidence management
✓ Develop, implement, and maintain security policies, standards, and guidelines
✓ Create meaningful KPIs, dashboards, and reporting for executives and board members
✓ Establish effective governance structures, oversight mechanisms, and continuous improvement processes

Key course takeaways

✓ Build a practical, business-aligned GRC program that delivers real value
✓ Master risk management techniques that help prioritize security efforts effectively
✓ Create compliance programs that are sustainable and audit-ready
✓ Develop clear policies and metrics that gain buy-in from leadership and technical teams
✓ Bridge the gap between security, legal, compliance, and business stakeholders
✓ Become a trusted GRC leader who transforms security governance from a burden into a strategic advantage

Things you need to know

What are the prerequisites for this course?

There are no prerequisites. The course teaches GRC from first principles. Familiarity with security operations or compliance work will help you move faster, but is not required. Every framework, methodology, and process is explained at first use.

What are the device requirements?

A device with a modern browser. No lab environment required. The course provides templates, frameworks, and worked examples you can apply directly to your organization.

How will the course benefit your career?

GRC capability is increasingly a requirement for security leadership, architecture, and engineering roles. Organizations need people who can translate security controls into business risk language, navigate compliance requirements, and build governance programs that executives support. This course gives you the practical skills to do that.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy policy templates, risk frameworks, and compliance tools in your organization. You may not redistribute course content or share account credentials.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.