Cybersecurity GRC Bootcamp: Self-Paced (Video)
Two structured paths, 10-Day Intensive and 30-Day Steady, for learners completing the Fourth Tech GRC bootcamp on their own.
- Price
- Free
- Video lessons
- 48
- Modules
- 3
- Total runtime
- ~5h 34m
Watch the first 2 lessons now
No account, no email, nothing to fill in. Judge the teaching for yourself before you decide anything.
1.1 Cybersecurity and Information Security
5 min
1.2 The Three Pillars of Cybersecurity
7 min
Everything in the track
All 48 lessons, in order. Nothing here is hidden from you.
Module 1: Cybersecurity Foundations
The vocabulary and mental models everything else is built on. Define cybersecurity vs. information security, the CIA triad, information classification, common threats, governance agreements, and AAA access control.
- 1.1Cybersecurity and Information Securityplaying above5m
- 1.2The Three Pillars of Cybersecurityplaying above7m
- 1.3Security Objectives & Information Classification11m
- 1.4Cyber Security Concepts10m
- 1.5Information System Terminologies10m
- 1.6Governance Agreements (BAA, DUA, MOU, ISA)7m
- 1.7Cyber Security Terminologies5m
- 1.8Cyber Threats10m
- 1.9AAA Protocols7m
Module 2: GRC & Compliance Frameworks
Governance, risk, and the regulations a GRC professional lives in. Separate governance, risk, and compliance; apply risk appetite vs. tolerance; and compare ISO 27001, PCI DSS, SOC, GDPR, and HIPAA by purpose, scope, and who they protect.
- 2.1Governance, Risk and Compliance9m
- 2.2Risk Assessment4m
- 2.3Risk Decision, Appetite & Tolerance8m
- 2.4ISO Framework6m
- 2.5PCI DSS13m
- 2.6Service Organization Controls (SOC)6m
- 2.7GDPR12m
- 2.8HIPAA7m
Module 3: NIST Risk Management Framework (RMF) Lifecycle
The core of the program: taking an information system from preparation to an Authorization to Operate and beyond. Sequence the RMF steps, categorize systems, handle privacy artifacts, select and implement control families, drive assessment, build a POA&M, reach an ATO, and run continuous monitoring.
- 3.1FISMA5m
- 3.2RMF Overview 13m
- 3.3RMF Overview 24m
- 3.4Preparation6m
- 3.5Categorization 12m
- 3.6Categorization Practical10m
- 3.7Categorization 26m
- 3.8PTA & PIA7m
- 3.9System of Record Notice3m
- 3.10E-Authentication8m
- 3.11Selection of Controls9m
- 3.12Control Families11m
- 3.13Control Classification5m
- 3.14AC Controls10m
- 3.15Control Implementation9m
- 3.16SSP & CMP9m
- 3.17Security Impact Analysis2m
- 3.18Contingency Plan 110m
- 3.19Contingency Plan 26m
- 3.20Incident Response4m
- 3.21Assessment 15m
- 3.22Assessment 25m
- 3.23Assessment 36m
- 3.24POA&M12m
- 3.25Authorization4m
- 3.26Continuous Monitoring 15m
- 3.27Continuous Monitoring 25m
- 3.28Vulnerability Management7m
- 3.29CVE & CVSS6m
- 3.30Cloud Computing 18m
- 3.31Cloud Computing 25m
Two ways to pace it
10-Day Intensive
75–90 min/day
You have focused time daily and want to be job-ready fast (e.g., between roles, or before interviews).
30-Day Steady
30–40 min/day
You are studying around a job or other commitments and prefer deeper retention with lighter daily load.
Create a free account to do the work
The videos are free either way. An account is what lets the platform remember you, so the rest of the track can actually function:
- Your place saved, lesson by lesson, across devices
- Self-check quizzes after each video, so you find out whether it landed
- The hands-on lab: Develop the SSP & run the assessment: Atlas RMF lab
- The assignment: Mini-SSP
- Interview practice on what each module taught
Want it taught live instead?
This is the self-paced track: you set the pace and nobody is waiting on you. The live bootcamps run to a timetable with sessions, a cohort and someone to answer you. Same subject, different way of learning it.
See the live bootcamps