Certified in Governance, Risk and Compliance (CGRC)

Certified in Governance, Risk and Compliance (CGRC) Training Course

Build GRC Expertise

The Certified in Governance, Risk and Compliance (CGRC) Training Course provides professionals with comprehensive knowledge of governance, risk management, and compliance. In addition, the program develops practical skills for managing organizational risks while supporting regulatory and policy requirements.

Strengthen Organizational Compliance

Furthermore, participants gain a stronger understanding of how governance frameworks, risk management practices, and compliance processes work together. Through this integrated approach, professionals can better understand their role in supporting organizational requirements.

Apply Governance and Risk Practices

Moreover, the training helps participants develop practical knowledge that can be applied to organizational processes. As a result, they can contribute more effectively to security, accountability, risk management, and regulatory compliance.

Ultimately, the program supports professionals in strengthening their GRC capabilities while developing a more structured approach to organizational governance, risk, and compliance.

Overview

The Certified in Governance, Risk and Compliance (CGRC) Training develops practical knowledge of governance, risk management, and compliance. Participants learn how to apply governance frameworks, identify and manage organizational risks, and understand regulatory requirements.

Furthermore, the program strengthens ethical decision-making, strategic risk management, and stakeholder communication. As a result, participants can support informed business decisions, strengthen accountability, and promote effective compliance across the organization.

Target Audience for CGRC Training

  • Risk Management Professionals
  • Compliance Officers
  • Governance Professionals
  • Internal Auditors
  • Financial Officers
  • IT Security Professionals
  • Project Managers

To apply for the CGRC course certification, you need to

  • To qualify for this cybersecurity certification, you must pass the exam and have at least two years of cumulative work experience in one or more of the seven domains of the ISC2 CGRC Common Body of Knowledge (CBK). 
Exam Name  Certified in Governance, Risk and Compliance (CGRC)
Exam Type  Multiple-choice Questions 
Exam Cost  Exam Fee*: $599.00 + Application Fee: $150.00 
Total Questions  125 Questions 
Exam Duration  3 Hours (180 Minutes)
Languages  English, French, German, Brazilian, Portuguese, Spanish, Japanese 
COURSE SYLLABUS

1.1 Security and Privacy Governance, Risk Management, and Compliance

  • Governance, Risk Management, and Compliance Principles
  • Security and Privacy Frameworks and Standards
  • National Institute of Standards and Technology (NIST) Cybersecurity Framework
  • Control Objectives for Information and Related Technology (COBIT)
  • International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) Standards
  • System Development Life Cycle (SDLC) Requirements and Processes
  • Information Lifecycle and Data Management
  • Confidentiality, Integrity, Availability, and Privacy
  • System Assets and Security Boundaries
  • Security and Privacy Controls
  • Compliance Roles and Responsibilities

1.2 Compliance Program Processes

  • Establishing a Compliance Program
  • Applying Relevant Governance Frameworks
  • Managing Security and Privacy Requirements
  • Supporting Ongoing Compliance Activities

1.3 Compliance Frameworks, Regulations, and Requirements

  • ISO/IEC Compliance Frameworks
  • Federal Risk and Authorization Management Program (FedRAMP)
  • Payment Card Industry Data Security Standard (PCI DSS)
  • Cybersecurity Maturity Model Certification (CMMC)
  • Federal Information Security Modernization Act (FISMA)
  • Health Insurance Portability and Accountability Act (HIPAA)
  • General Data Protection Regulation (GDPR)
  • National and International Privacy Requirements

2.1 System Description

  • System Name and Scope
  • System Purpose and Functionality
  • System Boundaries and Components

2.2 Security Compliance Requirements

  • Information Types Processed, Stored, or Transmitted
  • Security Objectives for Each Information Type
  • National and International Security Requirements
  • Federal Information Processing Standards (FIPS)
  • International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) Standards
  • Data Protection Impact Assessments
  • System Risk Impact Levels
  • Security Compliance Framework Requirements

3.1 Identify and Document Controls

  • Identify Baseline Controls
  • Identify Inherited Controls
  • Document Applicable Controls

3.2 Select and Tailor Controls

  • Determine Applicable Baseline and Inherited Controls
  • Select Appropriate Control Enhancements
  • Identify Data Handling and Marking Requirements
  • Document Control Selection
  • Develop a Continued Compliance Strategy
  • Apply Continuous Monitoring and Vulnerability Management
  • Allocate Controls to Stakeholders
  • Establish Stakeholder Agreement

4.1 Develop an Implementation Strategy

  • Align Controls with Compliance Requirements
  • Plan Resources, Funding, and Timelines
  • Identify Management, Technical, Operational, and Common Controls
  • Establish Documentation Review and Training Frequency

4.2 Implement Selected Controls

  • Implement Controls Consistent with Requirements
  • Apply Compensating or Alternate Security Controls
  • Verify Control Effectiveness

4.3 Document Control Implementation

  • Document Residual Security Risks
  • Develop Plans of Action and Milestones (POA&M)
  • Maintain Risk Registers
  • Document Implemented Controls
  • Align Documentation with Organizational Purpose and Risk Profile

5.1 Prepare for Assessment and Audit

  • Establish Stakeholder Roles and Responsibilities
  • Define Objectives, Scope, Resources, and Schedule
  • Identify Assets, Methods, and Effort
  • Review Existing Compliance Evidence
  • Finalize the Assessment and Audit Plan

5.2 Conduct Assessment and Audit

  • Verify Compliance Capabilities
  • Apply Interview, Examination, and Testing Methods
  • Conduct Penetration and Vulnerability Testing
  • Verify and Validate Evidence

5.3 Prepare the Initial Report

  • Identify Assessment and Audit Risks
  • Summarize Risk Mitigation Actions
  • Document Preliminary Findings

5.4 Review Findings and Plan Responses

  • Assign Appropriate Risk Responses
  • Collaborate with Relevant Stakeholders
  • Reassess Corrective Actions
  • Validate Resolved Compliance Findings

5.5 Develop the Final Report

  • Document Final Compliance Status
  • Record Relevant Recommendations
  • Finalize the Assessment and Audit Report

5.6 Develop the Risk Response Plan

  • Identify Residual Risks and Deficiencies
  • Prioritize Identified Risks
  • Determine Required Financial, Personnel, and Technical Resources
  • Establish Risk Mitigation Timelines

6.1 Review and Submit Security and Privacy Documents

  • Compile Required Security and Privacy Documentation
  • Review Compliance Documentation
  • Submit Documentation for Compliance Decisions
  • Support Authorizing and Assessment Parties

6.2 Determine System Risk Posture

  • Establish System Risk Acceptance Criteria
  • Determine Residual Risk
  • Obtain Stakeholder Agreement on Risk Treatment
  • Document Residual Risks Formally

6.3 Document System Compliance

  • Document the Formal Compliance Decision
  • Issue Compliance Notifications
  • Share Decisions with Relevant Stakeholders

7.1 Perform System Change Management

  • Assess Changes Against Organizational Risk
  • Evaluate Operational and Compliance Impacts
  • Document and Approve Proposed Changes
  • Deploy Changes with Rollback Plans
  • Track Changes and Enforce Compliance

7.2 Perform Ongoing Compliance Activities

  • Establish Compliance Review Frequencies
  • Monitor Systems, Assets, and Personnel
  • Perform Incident Response Activities
  • Maintain Contingency and Recovery Measures
  • Apply Security Updates and Remediate Risks
  • Collect Evidence and Update Documentation
  • Conduct Security Awareness and Training
  • Review Monitoring Strategies Regularly
  • Align Monitoring with Updated Requirements

7.3 Engage in Compliance Audits

  • Perform Required Testing and Scanning
  • Conduct Personnel Interviews
  • Review and Update Documentation

7.4 Decommission Systems When Applicable

  • Review Decommissioning Requirements
  • Coordinate Decommissioning with Stakeholders
  • Remove Systems from Operations
  • Retain Relevant System Documentation
  • Share Decommissioning Records with Stakeholders

Benefits of CGRC Training

  • Holistic Understanding: Gain a comprehensive understanding of governance, risk management, and compliance principles.
  • Career Advancement: Strengthen career prospects by demonstrating expertise in governance, risk, and compliance.
  • Risk Mitigation: Develop skills to identify, assess, and mitigate organizational risks effectively.
  • Enhanced Decision-Making: Make informed decisions by integrating GRC considerations into business processes.
  • Professional Credibility: Build professional recognition through demonstrated GRC knowledge and capabilities.
  • Organizational Resilience: Support stronger governance, risk management, compliance, and organizational resilience.

Up-coming Schedule: 

Please contact us to know about the upcoming schedule.