Skip to main content
Course

CGRC Exam Prep

Work the full authorization and compliance lifecycle the way ISC2 tests it and walk into the CGRC exam ready to choose the BEST answer.

Intermediate

Level

8

Modules

23

Lessons

8

Graded quizzes

10 hours

Estimated time

What you will be able to do

  • You will be able to distinguish governance, risk management, and compliance roles and apply core risk-management terminology to exam scenarios.
  • You will be able to define an information system's authorization boundary and describe its environment, interconnections, and data flows.
  • You will be able to categorize a system, select and approve an appropriate control baseline, and tailor and document controls in a security and privacy plan.
  • You will be able to explain how security and privacy controls are implemented and documented so they are ready for assessment.
  • You will be able to plan and interpret a control assessment, distinguish testing methods, and analyze findings into a POA&M.
  • You will be able to describe how compliance documentation is compiled and submitted, how residual risk is determined, and how an authorization decision is reached and communicated.
  • You will be able to explain ongoing compliance maintenance, including change management, continuous monitoring, audits, and secure decommissioning.
  • You will be able to interpret BEST, MOST, and FIRST exam phrasing and select the strongest answer from close distractors.

What is inside

8 modules, 23 lessons. Each module ends in a graded quiz.

  1. 01

    Security and Privacy Governance, Risk Management, and Compliance Program

    Covers the (ISC)² CGRC, Certified in Governance, Risk and Compliance Security and Privacy Governance, Risk Management, and Compliance Program domain (about 16% of the exam), spanning 1.1, 1.2, 1.3. Each objective is taught as its own lesson with worked examples and exam-style checks.

    3 lessons · 15 quiz questions

  2. 02

    Scope of the System

    Covers the (ISC)² CGRC, Certified in Governance, Risk and Compliance Scope of the System domain (about 10% of the exam), spanning 2.1, 2.2. Each objective is taught as its own lesson with worked examples and exam-style checks.

    2 lessons · 15 quiz questions

  3. 03

    Selection and Approval of Framework, Security, and Privacy Controls

    Covers the (ISC)² CGRC, Certified in Governance, Risk and Compliance Selection and Approval of Framework, Security, and Privacy Controls domain (about 14% of the exam), spanning 3.1, 3.2. Each objective is taught as its own lesson with worked examples and exam-style checks.

    2 lessons · 15 quiz questions

  4. 04

    Implementation of Security and Privacy Controls

    Covers the (ISC)² CGRC, Certified in Governance, Risk and Compliance Implementation of Security and Privacy Controls domain (about 17% of the exam), spanning 4.1, 4.2. Each objective is taught as its own lesson with worked examples and exam-style checks.

    2 lessons · 15 quiz questions

  5. 05

    Assessment/Audit of Security and Privacy Controls

    Covers the (ISC)² CGRC, Certified in Governance, Risk and Compliance Assessment/Audit of Security and Privacy Controls domain (about 16% of the exam), spanning 5.1, 5.2, 5.3, 5.4, 5.5, 5.6. Each objective is taught as its own lesson with worked examples and exam-style checks.

    6 lessons · 15 quiz questions

  6. 06

    System Compliance

    Covers the (ISC)² CGRC, Certified in Governance, Risk and Compliance System Compliance domain (about 14% of the exam), spanning 6.1, 6.2, 6.3. Each objective is taught as its own lesson with worked examples and exam-style checks.

    3 lessons · 15 quiz questions

  7. 07

    Compliance Maintenance

    Covers the (ISC)² CGRC, Certified in Governance, Risk and Compliance Compliance Maintenance domain (about 13% of the exam), spanning 7.1, 7.2, 7.3, 7.4. Each objective is taught as its own lesson with worked examples and exam-style checks.

    4 lessons · 15 quiz questions

  8. 08

    Exam Readiness & Practice Exam

    Pulls the whole exam together: an exam-day strategy and key-term glossary, then a timed, domain-weighted practice exam written in the real exam style.

    1 lessons · 51 quiz questions