Ready to start? Begin with Module 1.
A complete, free path through Governance, Risk, and Compliance.
Module 1 · GRC Core Foundations
Understand what GRC is, how governance, risk, and compliance work together, and master the core vocabulary every interviewer tests.
Your GRC Track
Thirteen modules. 51 lessons. One coherent journey from foundations to interview-ready.
GRC Core Foundations
Understand what GRC is, how governance, risk, and compliance work together, and master the core vocabulary every interviewer tests.
NIST Cybersecurity Framework 2.0
Master the six functions, the four tiers, profiles, and how to run a gap assessment.
NIST AI Risk Management Framework
Understand AI-specific risk: Govern, Map, Measure, Manage, plus bias, transparency, and explainability.
ISO 27001
Master the ISMS, the Annex A controls, and the Statement of Applicability.
SOC 2
Master the five Trust Services Criteria and the difference between Type I and Type II.
PCI DSS
Master the 12 requirements, the merchant levels, and QSA, SAQ, and ROC.
SOX ITGC
Master IT General Controls, segregation of duties, and change management.
HIPAA and HITECH
Master the three rules and the three safeguards.
HITRUST
Understand the HITRUST CSF and why healthcare vendors pursue it.
Third-Party Risk Management
Master the vendor lifecycle and the SIG and CAIQ questionnaires.
Vulnerability Management
Master CVE, CVSS, the CISA KEV list, EPSS, and risk-based patching.
Cloud and Modern Security
Master the shared responsibility model, Zero Trust, and identity and access management.
Interview Mastery
Walk into any GRC interview calm and confident.
Advanced GRC
Ten specialized modules. 35 lessons on privacy law, FedRAMP, AI governance, FAIR, GRC platforms, and audit prep. Best after GRC Mastery or with some field experience.
Data Privacy Laws, GDPR and CCPA
Master the global privacy landscape: GDPR, CCPA and CPRA, the growing patchwork of US state laws, and the core privacy principles every GRC professional must know.
Business Continuity and Disaster Recovery
Learn how organizations prepare for and recover from disruption, the BIA, RTO and RPO, ISO 22301, and how to build and test a continuity plan.
NIST SP 800-53 and FedRAMP
Master the federal control catalog and the cloud authorization program. Learn the 20 control families, the three baselines, and how FedRAMP builds on 800-53.
COBIT and IT Governance
Understand the leading IT governance framework, how COBIT separates governance from management, and where it fits alongside NIST and ISO.
ISO 42001 and the EU AI Act
Master the newest and fastest growing area in GRC: AI governance. Learn ISO 42001, the EU AI Act risk tiers, and how they work together.
Practical Policy Writing
Learn the real skill of writing clear, enforceable policies, standards, and procedures, and how to manage the full policy lifecycle.
Framework Cross-Mapping in Practice
Learn the daily GRC skill of mapping one set of controls to many frameworks at once, so a single control satisfies SOC 2, ISO 27001, and NIST together.
Quantitative Risk and FAIR
Move from high, medium, low to putting a real dollar value on risk. Learn the FAIR model and how to speak to executives in money.
GRC Tools and Platforms
Learn what the real GRC platforms do, how they differ, and how to speak about OneTrust, ServiceNow, Archer, LogicGate, Vanta, and Drata in an interview.
Audit Preparation and Evidence
Learn how audits really work, how to prepare, how to manage evidence, and how to respond to findings with confidence.