Skip to Content

Certified in Governance, Risk and Compliance (CGRC)  


Request for price


Length: 5 day (40 hours)

 

Course objectives

After completing this course, students will be able to:

    • Execute the RMF: Master all seven steps of the NIST Risk Management Framework (Prepare $\rightarrow$ Categorize $\rightarrow$ Select $\rightarrow$ Implement $\rightarrow$ Assess $\rightarrow$ Authorize $\rightarrow$ Monitor).
    • Categorize Systems: Use FIPS 199 and NIST SP 800-60 to determine the impact levels (Low, Moderate, High) of information systems.
    • Tailor Security Controls: Select and customize security and privacy controls from NIST SP 800-53 based on risk assessment.
    • Draft Security Documentation: Create essential artifacts like the System Security Plan (SSP) and Plan of Action and Milestones (POA&M).
    • Evaluate Risk Posture: Determine residual risk and provide actionable data to stakeholders for informed authorization decisions.
    • Maintain Compliance: Implement automated and manual continuous monitoring strategies to ensure the system stays secure after launch.

.


Course outlines

    • Domain 1: Security and Privacy Governance, Risk Management, and Compliance Program
      • Principles of the CIA Triad and non-repudiation.
      • Understanding federal laws (FISMA, FedRAMP) and international standards (ISO 27001, GDPR).
      • Establishing roles and responsibilities (AO, ISSO, Scoping).
    • Domain 2: Scope of the System
      • Describing the information system purpose and boundaries.
      • Categorization: Identifying information types and determining security impact levels.
    • Domain 3: Selection and Approval of Framework, Security, and Privacy Controls
      • Identifying baseline and inherited (common) controls.
      • Tailoring: Applying overlays and selecting compensating controls.
      • Developing a continuous monitoring strategy.
    • Domain 4: Implementation of Security and Privacy Controls 
      • Aligning implementation with organizational and regulatory expectations.
      • Documenting the "as-implemented" state of technical, management, and operational controls.
    • Domain 5: Assessment/Audit of Security and Privacy Controls
      • Preparing the Security Assessment Plan (SAP).
      • Conducting tests, interviews, and examinations.
      • Analyzing results and identifying vulnerabilities in the Security Assessment Report (SAR).
    • Domain 6: System Compliance
      • Reviewing the "Security Authorization Package" (SSP, SAR, and POA&M).
      • Authorization Decision: Understanding ATO, ATU, and Denial of Authorization.
    • Domain 7: Compliance Maintenance 
      • Change Management: Assessing the security impact of system changes.
      • Performing ongoing assessments and reporting.
      • System Decommissioning: Securely removing systems from operation