GRC for Security Professionals
Master GRC for Security Professionals
Turn security from a cost center into a strategic business enabler. Build effective Governance, Risk, and Compliance (GRC) programs that align security with business objectives, manage real risk, and demonstrate clear value to executives and auditors.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Phase 1: Foundations
What GRC for Security Professionals teaches: build a working governance, risk, and compliance program, a risk register you actually work, policies people follow, controls mapped to ISO 27001, NIST CSF, SOC 2, GDPR, and CMMC, and audit evidence produced as a byproduct. The program you'll build, what you walk away with, and how the course is structured. Start here.
The governance-risk-compliance triad as an operating system. How the three disciplines connect and reinforce each other. Why most GRC programs fail, with detailed case studies of each failure mode. Organizational positioning, reporting lines, and regulatory drivers.
Policy as executable governance. The policy hierarchy and the enforcement test that separates its levels. Why policies become shelf-ware and how to write ones that hold. The minimum viable policy set. The policy lifecycle. Mapping policies to the controls that enforce them and the requirements they satisfy.
Phase 2: Risk Management
The risk engine the policy framework has been referencing. Vocabulary, four identification methods, calibrated scoring, appetite and tolerance, the register, and the evidence that keeps control effectiveness ratings honest.
Show 8 lessonsHide lessons
Turning scored risks into decisions and controls. The four treatment options in the order you consider them, control selection on five criteria, the Statement of Applicability, treatment plans with targets, and the verification that measures whether any of it worked.
Keeping the register true between reviews. Metrics that measure exposure as well as controls, dashboards for two audiences, board reporting in twenty minutes, escalation with written triggers, the quarterly review, and queries that produce trends rather than points.
Phase 3: Framework Implementation
Mapping the risk programme onto ISO 27001. The clauses are the engine and Annex A is the toolbox. Scope, context, planning, support, audit, improvement, the full Statement of Applicability, and certification through to surveillance.
A framework you cannot be certified against, and why it earns its place next to one you can. Six functions, profiles with real targets, implementation tiers, and running CSF alongside ISO 27001 without collecting evidence twice.
An attestation rather than a certification, tested against controls you write yourself. The system description, the criteria, evidence across an observation window, the examining firm, and using the report once you hold it.
UK GDPR, the DPA 2018 and the Data (Use and Access) Act 2025 read together. Lawful bases including the new seventh, records of processing, impact assessments, individual rights and the new complaints obligation, breach notification, and transfers.
A certification regime attached to one customer, currently mid-reform. Identifying controlled information, the 110 requirements at objective grain, the plan and the score, assessment and affirmation, and the scoping decision that sets the cost.
Phase 4: Governance Operations
Every framework in this course requires awareness training and none tells you how to make it work. Behaviour rather than topics, friction rather than content, simulations that build detection rather than punish, and measurement that can detect its own failure.
Running audits as a programme rather than a series of events. Internal audit that finds things, external audits that verify them, findings that close and stay closed, and several frameworks on one set of evidence.
Running a function rather than a process. Translating risk into terms a board can compare, reporting that drives decisions, committees with real authority, budget arguments that survive a finance director, and delivering bad news early.
The discipline that keeps everything else from going quietly out of date. Watching primary sources, assessing what a change actually requires, absorbing it into the programme rather than beside it, and maintaining a scan that survives years.
Whether anybody actually has the capacity. Structure and the one activity that needs independence, the skills the work really requires, tooling as a sequencing question, cadences as the operating model, and what a maturity score can honestly support.
What changes when obligations come from a sector regulator, company law, or an insurer rather than a general framework. Four audiences, one evidence structure, and where all of it is heading.
Phase 0: Course Resources
The scales, matrices, mappings and report skeletons, with what each instrument decides and where it misleads.
Ordered procedures for the work a GRC function actually does: assessments, certifications, audits, breaches and board cycles.
A working register, policy set, control map and evidence pack, built from nothing and then tested against the failures that make them useless.
Show 3 lessonsHide lessons
Six cases reasoned end to end, including the ones where every artifact was current and the function was achieving nothing.
What to do when a regulator writes, an auditor raises a finding, a customer sends a questionnaire, or somebody asks for an exception.
The exam, the lab pack, the artifacts you built, and the two products this course bridges into.
External sources this course draws on: frameworks, standards, regulator guidance and vendor documentation.
Show 1 lessonHide lessons
Course Completion
GRC for Security Professionals end-of-course exam: a simulation-based assessment testing whether you can establish what binds an organization, grade gaps against evidence that already exists, sequence work against a date you do not control, and take a board a decision it can act on.
Show 1 lessonHide lessons
Course overview
The GRC for Security Professionals course is built specifically for security professionals, GRC professionals, and security leaders responsible for building and maturing governance programs. You'll gain practical expertise to:
By the end, you'll have the knowledge, frameworks, and tools to build a mature GRC program that reduces risk, improves security posture, and positions security as a trusted business partner.
How this course works
Most GRC fails by producing documents rather than changing anything. This course is built around the opposite loop, and runs it through every framework it implements.
1. Write the policy somebody can comply with. A policy nobody can follow is a finding waiting to be written against you. The test is whether an ordinary employee could act on it.
2. Assess risk against something real. A register scored from opinion produces an order nobody defends. Method first, then the scoring, then the register.
3. Treat the risk with a control that exists. A treatment decision with no owner, no date and no evidence is a treatment decision that has not been made.
4. Monitor the control, not the document. Controls decay silently. What proves a control still works, and who checks, is the difference between a program and a binder.
5. Report so somebody decides. A board paper that produces no decision is a status update. The reporting module is about the decision it is meant to cause.
The frameworks, ISO 27001, NIST CSF 2.0, SOC 2 and CMMC, are then implemented through that same loop rather than as separate checklists.
What this course assumes
No minimum experience and no prerequisite course. Every framework is introduced from what it asks for and why, and the course assumes you are a practitioner rather than an auditor.
What makes it go faster: an organization you are actually responsible for, because every exercise produces an artifact you can use. Not required.
What this course does not cover: legal advice, audit as a profession, and technical security controls in depth. This is building and running the governance function.
Who this course is for
You're a security professional, GRC professional, or security leader responsible for building or maturing governance, risk, and compliance programs. This course is built for you if you want to:
In short: if you want to build governance programs that are both effective and respected across the organization, this course is for you.
What you'll learn
By the end of this GRC for Security Professionals course you will be able to:
Key course takeaways
Things you need to know
What are the prerequisites for this course?
There are no prerequisites. The course teaches GRC from first principles. Familiarity with security operations or compliance work will help you move faster, but is not required. Every framework, methodology, and process is explained at first use.
What are the device requirements?
A device with a modern browser. No lab environment required. The course provides templates, frameworks, and worked examples you can apply directly to your organization.
How will the course benefit your career?
GRC capability is increasingly a requirement for security leadership, architecture, and engineering roles. Organizations need people who can translate security controls into business risk language, navigate compliance requirements, and build governance programs that executives support. This course gives you the practical skills to do that.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy policy templates, risk frameworks, and compliance tools in your organization. You may not redistribute course content or share account credentials.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.