Skip to main content
◢ Course

Cybersecurity GRC Bootcamp: Fall 2026 Cohort

Twelve live sessions, two a week, over six weeks. Read it before class, then be taught it live.

Beginner

Level

12

Modules

62

Lessons

12

Graded quizzes

12

Assignments

36 hours

Estimated time

What you will be able to do

  • Explain what cybersecurity GRC is, and use the vocabulary precisely
  • Build and maintain a risk register, and treat risks deliberately
  • Categorise a system with FIPS 199 and select and tailor an 800-53 baseline
  • Work the NIST RMF end to end, from Prepare through to continuous monitoring
  • Apply the shared responsibility model to cloud services, and explain FedRAMP
  • Run a third-party risk assessment and read a SOC 2 report properly
  • Implement an ISMS to ISO 27001, and audit one
  • Apply GDPR, HIPAA and PCI DSS to real facts, and judge a notification decision
  • Talk about all of it in an interview, in your own words

What is inside

12 modules, 62 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    Cybersecurity Foundations

    Before we learn any framework, we learn the words. What cybersecurity actually is, the CIA triad, the vocabulary of asset, threat, vulnerability and risk, who attacks us and how, and where a GRC analyst fits.

    7 lessons · 12 quiz questions · assignment

  2. 02

    GRC and Risk Management, with Data Governance and Classification

    Governance, risk and compliance as three distinct jobs. The risk management cycle end to end, the terminology that trips people up, the four ways to treat a risk, and how data governance, classification and system boundaries decide what you are actually protecting.

    6 lessons · 12 quiz questions · assignment

  3. 03

    Compliance Landscape and Frameworks, with FISMA and NIST Publications

    What compliance actually demands beyond good security, the difference between a framework, a standard and a law, and the landscape you will meet. Then FISMA as the legal obligation and the NIST publications every GRC analyst is expected to know.

    4 lessons · 12 quiz questions · assignment

  4. 04

    NIST RMF part 1: Prepare, Categorize and Select

    The Risk Management Framework end to end in outline, then the first three steps in depth. Preparing at organisation and system level, categorising a system with FIPS 199 and the privacy documents that go with it, and selecting and tailoring an 800-53 baseline.

    5 lessons · 12 quiz questions · assignment

  5. 05

    NIST RMF part 2: Implement, Assess, Authorize and Monitor

    The second half of the framework. Implementing controls and documenting them in the SSP, assessing by examine, interview and test, writing the SAR and POA&M, the authorisation decision and the ATO package, then continuous monitoring and what sends you back round the cycle.

    5 lessons · 12 quiz questions · assignment

  6. 06

    Cloud Computing and FedRAMP

    What cloud actually is, the three service models, and the shared responsibility model that causes most cloud findings. Then FedRAMP: why it exists, its impact levels, the independent assessors, and the difference between a JAB provisional authorisation and an agency ATO.

    4 lessons · 12 quiz questions · assignment

  7. 07

    Third-Party Risk Management

    Why a supplier's weakness becomes your exposure, and the lifecycle that manages it. Inherent risk and criticality, proportionate due diligence, the security clauses that matter, ongoing monitoring and reassessment triggers, and offboarding that actually closes the exposure.

    5 lessons · 12 quiz questions · assignment

  8. 08

    SOC 2 and SOC Reports

    What SOC reports are and who they are written for. SOC 1, 2 and 3, Type I versus Type II, and the five trust services criteria. Then reading one properly: the anatomy, the opinion and exceptions, subservice organisations and carve-outs, and the CUECs that quietly transfer work back to you.

    4 lessons · 12 quiz questions · assignment

  9. 09

    ISO 27001: Implementer

    What an ISMS is and how ISO 27001 differs from SOC 2. The mandatory clauses 4 to 10, then Annex A and the Statement of Applicability, where risk decisions become an auditable record. Finally what an implementer actually does, and why they must not audit their own work.

    5 lessons · 12 quiz questions · assignment

  10. 10

    ISO 27001: Auditor

    Auditing an ISMS rather than building one. Internal audit and independence, the two-stage certification audit, classifying nonconformities, and the CAPA process including root cause and verification of effectiveness. Then how certification is maintained through surveillance and recertification.

    6 lessons · 12 quiz questions · assignment

  11. 11

    Privacy and Payment Laws

    The laws that decide what you may do with data and money. GDPR scope, controller versus processor, the principles, subject rights and the notification clock. HIPAA covered entities, business associates and the safeguard categories. HITRUST as a harmonising certification. Then PCI DSS: merchant levels, the requirements, validation routes and compensating controls.

    6 lessons · 12 quiz questions · assignment

  12. 12

    Interview Preparation

    Turning eleven sessions of work into answers you can defend. The capstone and what makes a portfolio artefact worth showing, how an interview is structured, telling your story with STAR without hiding your own contribution, and what the first ninety days in a GRC role actually look like.

    5 lessons · 12 quiz questions · assignment