ISSO & Security Assessor Bootcamp
Become an ISSO or Security Assessor.
A role-based bootcamp that walks you through the entire NIST Risk Management Framework, from Prepare to Monitor, building the real artifacts (SSP, SAP, SAR, POA&M) federal employers expect. Finish with a portfolio and the language of the job.
Choose how you learn
One bootcamp. Three ways to take it.
3Same role-based outcome. Pick the format that fits your life. Read it at your own pace with graded feedback, watch the video track, or join the live quarterly cohort.
Instructor-led
Watch the instructor teach on video: a guided track with self-checks, per-module interview prep and a hands-on lab.
Available now in the Fourth Tech Hub
Self-paced
Read the full course in the portal at your own pace: lessons, graded quizzes and assignments your instructor reviews.
Available now in the Fourth Tech Hub
Live cohort
Real-time sessions with the practitioner on a quarterly schedule: accountable, interactive, and capped for attention. We open these as cohorts are scheduled.
Next cohort · Jul 15, 2026
Roles this prepares you for
- Information System Security Officer (ISSO)
- Security Control Assessor / Security Assessor
- RMF Analyst
- Compliance Analyst
- Junior SCA support
Standards & references
You'll build a portfolio of
- Mini SSP
- Security categorization memo
- POA&M
- Sample finding
- Mock authorization summary
- Cloud boundary worksheet
The curriculum
The 12 modules
12Federal Cybersecurity & RMF
FISMA, why RMF exists, ATO concepts, the ISSO & assessor roles.
Roles, Governance & Docs
AO, ISSO, ISSM, SCA, and how SSP/POA&M/SAP/SAR connect.
RMF Step 1: Prepare
System boundaries, scoping, inheritance, readiness checklist.
RMF Step 2: Categorize
FIPS 199/200, 800-60, impact levels, categorization workshop.
RMF Step 3: Select
800-53 baselines, tailoring, overlays, control families.
RMF Step 4: Implement
Implementation statements, building the SSP, defensible narratives.
RMF Step 5: Assess
800-53A, Security Assessment Plan, findings, the SAR, mock assessment.
RMF Step 6: Authorize
Authorization package, POA&M, residual risk, executive risk summary.
RMF Step 7: Monitor
ConMon strategy, vulnerability management, SSP/POA&M updates, metrics.
ISSO & Assessor Job Readiness
Day-in-the-life, interview questions, deliverables, capstone briefing.
Cloud for RMF Professionals
Service/deployment models, shared responsibility, cloud boundaries.
FedRAMP for ISSOs & Assessors
FedRAMP roles, baselines, documents, continuous monitoring, inheritance.
Hands-on labs
You don't watch. You do.
9Next cohort · Jul 15, 2026
Secure your seat for $2,000.
Each cohort is capped at 20 seats. You're in as soon as you pay, and you'll see your day-by-day plan when the cohort starts.