Skip to main content
Bootcamps · Combined GRC Program

GRC Implementer & Assessor Combined Bootcamp

Become job-ready across ISO 27001, RMF and Third-Party Risk.

Three flagship bootcamps in one self-paced, 6-week (42-day) program: run the full NIST RMF as an ISSO / security assessor, assess third-party vendors, then implement an ISO 27001 ISMS, with hands-on labs, three capstones, an integrated capstone, and a curated day-by-day plan.

4 modules20-seat cohortsHands-on labsCapstone + portfolio
$3,000$2,000/ seatLaunch discountSponsor a team seat
Track
Combined GRC Program
Format
Three ways to take it
Next cohort
Enroll anytime
Also runs
Self-paced · 6 weeks
Certificate
Yes, on completion

Choose how you learn

One bootcamp. Three ways to take it.

3

Same role-based outcome. Pick the format that fits your life. Read it at your own pace with graded feedback, watch the video track, or join the live quarterly cohort.

Coming soon

Instructor-led

Watch the instructor teach on video: a guided track with self-checks, per-module interview prep and a hands-on lab.

In development

In development
Available now

Self-paced

Read the full course in the portal at your own pace: lessons, graded quizzes and assignments your instructor reviews.

Available now in the Fourth Tech Hub

Quarterly

Live cohort

Real-time sessions with the practitioner on a quarterly schedule: accountable, interactive, and capped for attention. We open these as cohorts are scheduled.

Next cohort · Enroll anytime

How it works

Enroll once. Learn at your pace.

Enroll below and this bootcamp opens in your portal right away. Work through the modules, do the hands-on labs, and track your progress on your Schedule. Everything is self-paced.

Roles this prepares you for

  • GRC Analyst
  • ISO 27001 Implementer / Internal Auditor
  • ISSO / Security Control Assessor
  • Third-Party Risk Analyst

Standards & references

ISO 27001ISO 27002NIST RMFNIST SP 800-37800-53 / 800-53AFIPS 199 / 200SOC 2SSP / SAR / POA&M

You'll build a portfolio of

  • ISMS package (risk register, SoA, control evidence)
  • SSP + POA&M + authorization summary
  • Vendor risk assessment + decision package
  • Integrated GRC capstone across all three domains

The curriculum

The 4 modules

4
1

Phase 1: RMF / ISSO & Assessor (Weeks 1 to 2)

The ISSO role and RMF, categorize and select, implement and assess (SSP/SAR), authorize (ATO), continuous monitoring, toolkit and RMF capstone.

2

Phase 2: Third-Party Risk (Week 3)

TPRM foundations, intake and tiering, reviewing SOC 2 / ISO evidence, risk decisions, contracts and monitoring.

3

Phase 3: ISO 27001 (Weeks 4 to 5)

ISMS foundations, context and leadership, Annex A and the SoA, operating controls, internal audit, certification and ISMS capstone.

4

Phase 4: Integrated capstone and portfolio (Week 6)

Assess a vendor's ISMS, run an RMF-style assessment, produce a vendor decision package, and assemble a complete GRC portfolio.

Hands-on labs

You don't watch. You do.

4
ISO 27001 SoA & risk registerAtlas RMF workbench (SSP, SAR, POA&M)TPRM vendor assessment labIntegrated capstone build

Self-paced · start anytime

Secure your seat for $2,000.

Enroll and this bootcamp opens in your portal right away, to work through at your own pace.

See all bootcamps