Skip to main content
Course

GRC Cybersecurity Bootcamp

The full 9-week, job-focused GRC bootcamp, self-paced: frameworks, RMF, auditing, TPRM, ISO 27001, plus a portfolio and interview prep. No technical background needed.

Beginner

Level

9

Modules

35

Lessons

9

Graded quizzes

9

Assignments

24 hours

Estimated time

What you will be able to do

  • Explain GRC vocabulary and concepts in plain English
  • Build a risk register and apply risk treatment decisions
  • Test a control with the IOIR technique and document evidence in a workpaper
  • Complete a vendor risk assessment using SIG Lite and CAIQ
  • Write an ISO 27001 Statement of Applicability and prepare an audit evidence pack
  • Compare the six core frameworks (NIST CSF, NIST RMF, ISO 27001, SOC 2, GDPR, PCI DSS)
  • Produce interview-ready STAR answers and a public portfolio

What is inside

9 modules, 35 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    Foundations of Cybersecurity and GRC

    A plain-English foundation for the bootcamp: what Cybersecurity really is versus information security, the CIA triad, the core GRC vocabulary, risk basics, and a realistic day in the life of a junior GRC Analyst.

    4 lessons · 20 quiz questions · assignment

  2. 02

    Compliance and Frameworks Overview

    A self-paced tour of the nine compliance frameworks a junior GRC analyst meets on the job, what each one is, who needs it, and how to match the right framework to a business scenario. The goal this week is recognition, not mastery.

    4 lessons · 20 quiz questions · assignment

  3. 03

    Risk Management Framework Part 1: NIST RMF Steps 0 to 3 and Building a Risk Register

    A self-paced walk through the NIST Risk Management Framework, covering why it exists, the seven steps, FIPS 199 categorisation, control selection and the SSP, plus risk appetite, tolerance and capacity and how to build a working risk register. Anchored throughout by the Honeycomb Bakery loyalty system example.

    4 lessons · 20 quiz questions · assignment

  4. 04

    RMF Part 2 and IT Auditing: Assessment, SAR Authoring, and Evidence Discipline

    Step into the assessor's seat for RMF steps 4 through 6. You will learn how independent assessors test controls with Examine, Interview, and Test, rank evidence with the IOIR technique, build defensible workpapers, and write Security Assessment Report findings using the 5 Cs framework.

    4 lessons · 20 quiz questions · assignment

  5. 05

    Third-Party Risk Management Introduction

    An introduction to Third-Party Risk Management covering the five-stage TPRM lifecycle, risk-based vendor tiering, and how to read and review Due Diligence Questionnaires such as SIG-Lite and CAIQ. Built around the Honeycomb Bakery vendor portfolio used throughout the Fourth Tech GRC Bootcamp.

    4 lessons · 20 quiz questions · assignment

  6. 06

    Practical TPRM and the SOC 2 Case Study

    A hands-on week on reading a SOC 2 report end to end and turning that review into a decision. You learn the Trust Services Criteria, the anatomy of a SOC 2 Type II, exceptions, CUECs, scope and bridge letters, and how to write a one-page vendor Findings Memo.

    4 lessons · 20 quiz questions · assignment

  7. 07

    ISO 27001 Part 1: The ISMS, Clauses 4 to 10, Annex A, and the Statement of Applicability

    A practitioner walkthrough of ISO/IEC 27001:2022: what a certified Information Security Management System is, the mandatory management clauses 4 to 10, the 93 Annex A controls across four themes, and how the Statement of Applicability ties everything back to your ISMS. Culminates in building a mini-SoA for Honeycomb Bakery.

    4 lessons · 20 quiz questions · assignment

  8. 08

    ISO 27001 Part 2: Audit and Certification

    How an ISO 27001 certification actually runs end to end: internal audit under Clause 9.2, the Stage 1 and Stage 2 certification audits, finding classifications, the CAPA process for closing findings, and the three-year surveillance and recertification cycle. You will learn to write a CAPA memo using a real Honeycomb Bakery example.

    4 lessons · 20 quiz questions · assignment

  9. 09

    Final Interview Coaching and Graduation

    The capstone week that ties Weeks 1 to 8 together: a cumulative review across all eight GRC domains, STAR-structured interview answers, your portfolio and capstone walkthrough, and the comprehensive final exam required for your certificate.

    3 lessons · 40 quiz questions · assignment