Vendors

Gain the knowledge and practical skills required to implement Governance, Risk, and Compliance (GRC) principles with the ISC2 Certified in Governance, Risk and Compliance (CGRC) course.

This instructor-led training provides a structured learning experience covering the key domains of the CGRC Common Body of Knowledge (CBK).

Participants will learn how to integrate governance, risk management, performance management, and regulatory compliance into organizational security programs, while preparing for the ISC2 CGRC certification exam.

img-course-overview.jpg

What You'll Learn

  • Identify and describe the steps and tasks within the NIST Risk Management Framework (RMF).
  • Apply common elements of other risk management frameworks using the RMF as a guide.
  • Describe the roles associated with the RMF and how they are assigned to tasks within the RMF.
  • Execute tasks within the RMF process based on assignment to one or more RMF roles.
  • Explain organizational risk management and how it is supported by the RMF.

Who Should Attend

  • Cybersecurity Auditor
  • Cybersecurity Compliance Officer
  • GRC Architect
  • GRC Manager
  • Cybersecurity Risk & Compliance Project Manager
  • Cybersecurity Risk & Controls Analyst
  • Cybersecurity Third Party Risk Manager
  • Enterprise Risk Manager
  • GRC Analyst
  • GRC Director
  • Information Assurance Manager
img-who-should-learn.png

Prerequisites

To qualify for this cybersecurity certification, you must pass the exam and have at least two years of cumulative, paid work experience in one or more of the seven domains of the ISC2 CGRC Exam Outline.

Don’t have enough experience yet? You can still pass the CGRC exam and become an Associate of ISC2 while you earn the required work experience.

Learning Journey

Coming Soon...

Domain 1: Security and Privacy Governance, Risk Management, and Compliance Program

  • Demonstrate knowledge in security and privacy governance, risk management, and compliance program
  • Demonstrate knowledge in security and privacy governance, risk management and compliance program processes
  • Demonstrate knowledge of compliance frameworks, regulations, privacy, and security requirements

Domain 2: Scope of the System

  • Describe the system
  • Determine security compliance required

Domain 3: Selection and Approval of Framework, Security, and Privacy Controls

  • Identify and document baseline and inherited controls
  • Select and tailor controls

Domain 4: Implementation of Security and Privacy Controls

  • Develop implementation strategy (e.g., resourcing, funding, timeline, effectiveness)
  • Implement selected controls
  • Document control implementation

Domain 5: Assessment/Audit of Security and Privacy Controls

  • Prepare for assessment/audit
  • Conduct assessment/audit
  • Prepare the initial assessment/audit report
  • Review initial assessment/audit report and plan risk response actions
  • Develop final assessment/audit report
  • Develop risk response plan

Domain 6: System Compliance

  • Review and submit security/privacy documents
  • Determine system risk posture
  • Document system compliance

Domain 7: Compliance Maintenance

  • Perform system change management
  • Perform ongoing compliance activities based on requirements
  • Engage in audits activities based on compliance requirements
  • Decommission system when applicable

 

ISC2 CGRC Certification.

Capitalize on the rising demand for Governance, Risk and Compliance (GRC) expertise by earning the CGRC certification. The ISC2 CGRC is a proven way to demonstrate your knowledge and skills to integrate governance, performance management, risk management and regulatory compliance within your organization.

CGRC Examination Information

Length of exam: 3 hours
Number of items: 125
Item format: Multiple choice and advanced item types
Passing grade: 700 out of 1000 points
Exam language availability: English
Testing center: Pearson Testing Center

CGRC Examination Weights

  • Security and Privacy Governance, Risk Management, and Compliance Program: 16%
  • Scope of the System: 10%
  • Selection and Approval of Framework, Security, and Privacy Controls: 14%
  • Implementation of Security and Privacy Controls: 17%
  • Assessment/Audit of Security and Privacy Controls: 16%
  • System Compliance: 14%
  • Compliance Maintenance: 13%
Showcase advanced cybersecurity technical skills and knowledge to protect, authorize and maintain information systems within various risk management frameworks.
img-exam-cert

Frequently Asked Questions (FAQs)

  • Why get ISC2 certified?

    ISC2 certifications are globally recognized and demonstrate your expertise and commitment to the highest standards of cybersecurity practice.

    These certifications can enhance your career prospects, increase your earning potential, and open doors to leadership positions in the cybersecurity industry.


  • What to expect for the examination?

    ISC2 exams are comprehensive assessments that test your knowledge and understanding of cybersecurity concepts, principles, and best practices.

    Exam formats may include multiple-choice questions, scenario-based questions, and advanced innovative item types.

    Note: Certification requirements and policies may be updated by ISC2 from time to time. We apologize for any discrepancies; do get in touch with us if you have any questions.

  • How long is ISC2 certification valid for?

    ISC2 certifications are typically valid for three years.

    To maintain your certification, you must earn and submit Continuing Professional Education (CPE) credits annually. annual maintenance fee as well as complying with the annual CPE audit if selected.

    Note: Certification requirements and policies may be updated by ISC2 from time to time. We apologize for any discrepancies; do get in touch with us if you have any questions.

  • Why take this course with Trainocate?

    Here’s what sets us apart:

    - Global Reach, Localized Accessibility: Benefit from our geographically diverse training hubs in 24 countries (and counting!).

    - Top-Rated Instructors: Our team of subject matter experts (with high average CSAT and MTM scores) are passionate to help you accelerate your digital transformation.

    - Customized Training Solutions: Choose from on-site, virtual classrooms, or self-paced learning to fit your organization and individual needs.

    - Experiential Learning: Dive into interactive training with our curated lesson plans. Participate in hands-on labs, solve real-world challenges, and take on comprehensive assessments.

    - Learn From The Best: With 30+ authorized training partnerships and countless awards from Microsoft, AWS, Google – you're guaranteed learning from the industry's elite.

    - Your Bridge To Success: We provide up-to-date course materials, helpful exam guides, and dedicated support to validate your expertise and elevate your career."

Keep Exploring

Course Curriculum

Course Curriculum

Training Schedule

Training Schedule

Exam & Certification

Exam & Certification

FAQs

Frequently Asked Questions

img-improve-career.jpg

Improve yourself and your career by taking this course.

img-get-info.jpg

Ready to Take Your Business from Great to Awesome?

Level-up by partnering with Trainocate. Get in touch today.

Name*
Email*
Phone*
I'm inquiring for
Inquiry Details

By submitting this form, you consent to Trainocate processing your data to respond to your inquiry and provide you with relevant information about our training programs, including occasional emails with the latest news, exclusive events, and special offers.

You can unsubscribe from our marketing emails at any time. Our data handling practices are in accordance with our Privacy Policy.