Skip to main content
◢ Free Self-Paced Bootcamp

Cybersecurity GRC Bootcamp: Self-Paced (Video)

Two structured paths, 10-Day Intensive and 30-Day Steady, for learners completing the Fourth Tech GRC bootcamp on their own.

Price
Free
Video lessons
48
Modules
3
Total runtime
~5h 34m

Watch the first 2 lessons now

No account, no email, nothing to fill in. Judge the teaching for yourself before you decide anything.

1.1 Cybersecurity and Information Security

5 min

1.2 The Three Pillars of Cybersecurity

7 min

Everything in the track

All 48 lessons, in order. Nothing here is hidden from you.

Module 1: Cybersecurity Foundations

The vocabulary and mental models everything else is built on. Define cybersecurity vs. information security, the CIA triad, information classification, common threats, governance agreements, and AAA access control.

  • 1.1Cybersecurity and Information Securityplaying above5m
  • 1.2The Three Pillars of Cybersecurityplaying above7m
  • 1.3Security Objectives & Information Classification11m
  • 1.4Cyber Security Concepts10m
  • 1.5Information System Terminologies10m
  • 1.6Governance Agreements (BAA, DUA, MOU, ISA)7m
  • 1.7Cyber Security Terminologies5m
  • 1.8Cyber Threats10m
  • 1.9AAA Protocols7m

Module 2: GRC & Compliance Frameworks

Governance, risk, and the regulations a GRC professional lives in. Separate governance, risk, and compliance; apply risk appetite vs. tolerance; and compare ISO 27001, PCI DSS, SOC, GDPR, and HIPAA by purpose, scope, and who they protect.

  • 2.1Governance, Risk and Compliance9m
  • 2.2Risk Assessment4m
  • 2.3Risk Decision, Appetite & Tolerance8m
  • 2.4ISO Framework6m
  • 2.5PCI DSS13m
  • 2.6Service Organization Controls (SOC)6m
  • 2.7GDPR12m
  • 2.8HIPAA7m

Module 3: NIST Risk Management Framework (RMF) Lifecycle

The core of the program: taking an information system from preparation to an Authorization to Operate and beyond. Sequence the RMF steps, categorize systems, handle privacy artifacts, select and implement control families, drive assessment, build a POA&M, reach an ATO, and run continuous monitoring.

  • 3.1FISMA5m
  • 3.2RMF Overview 13m
  • 3.3RMF Overview 24m
  • 3.4Preparation6m
  • 3.5Categorization 12m
  • 3.6Categorization Practical10m
  • 3.7Categorization 26m
  • 3.8PTA & PIA7m
  • 3.9System of Record Notice3m
  • 3.10E-Authentication8m
  • 3.11Selection of Controls9m
  • 3.12Control Families11m
  • 3.13Control Classification5m
  • 3.14AC Controls10m
  • 3.15Control Implementation9m
  • 3.16SSP & CMP9m
  • 3.17Security Impact Analysis2m
  • 3.18Contingency Plan 110m
  • 3.19Contingency Plan 26m
  • 3.20Incident Response4m
  • 3.21Assessment 15m
  • 3.22Assessment 25m
  • 3.23Assessment 36m
  • 3.24POA&M12m
  • 3.25Authorization4m
  • 3.26Continuous Monitoring 15m
  • 3.27Continuous Monitoring 25m
  • 3.28Vulnerability Management7m
  • 3.29CVE & CVSS6m
  • 3.30Cloud Computing 18m
  • 3.31Cloud Computing 25m

Two ways to pace it

10-Day Intensive

75–90 min/day

You have focused time daily and want to be job-ready fast (e.g., between roles, or before interviews).

30-Day Steady

30–40 min/day

You are studying around a job or other commitments and prefer deeper retention with lighter daily load.

Create a free account to do the work

The videos are free either way. An account is what lets the platform remember you, so the rest of the track can actually function:

  • Your place saved, lesson by lesson, across devices
  • Self-check quizzes after each video, so you find out whether it landed
  • The hands-on lab: Develop the SSP & run the assessment: Atlas RMF lab
  • The assignment: Mini-SSP
  • Interview practice on what each module taught

Want it taught live instead?

This is the self-paced track: you set the pace and nobody is waiting on you. The live bootcamps run to a timetable with sessions, a cohort and someone to answer you. Same subject, different way of learning it.

See the live bootcamps