Ready to start? Begin with Module 1.

A complete, free path through Governance, Risk, and Compliance.

Continue Learning

Module 1 · GRC Core Foundations

Understand what GRC is, how governance, risk, and compliance work together, and master the core vocabulary every interviewer tests.

0% complete
Resume with ZEN
Modules Completed
0 / 13
Lessons Completed
0 / 51
Practice Score
0
Day Streak
0

Your GRC Track

Thirteen modules. 51 lessons. One coherent journey from foundations to interview-ready.

Module 1

GRC Core Foundations

Understand what GRC is, how governance, risk, and compliance work together, and master the core vocabulary every interviewer tests.

8 lessons · 0%~90mStart
Module 2

NIST Cybersecurity Framework 2.0

Master the six functions, the four tiers, profiles, and how to run a gap assessment.

4 lessons · 0%~60mStart
Module 3

NIST AI Risk Management Framework

Understand AI-specific risk: Govern, Map, Measure, Manage, plus bias, transparency, and explainability.

3 lessons · 0%~45mStart
Module 4

ISO 27001

Master the ISMS, the Annex A controls, and the Statement of Applicability.

4 lessons · 0%~75mStart
Module 5

SOC 2

Master the five Trust Services Criteria and the difference between Type I and Type II.

4 lessons · 0%~55mStart
Module 6

PCI DSS

Master the 12 requirements, the merchant levels, and QSA, SAQ, and ROC.

4 lessons · 0%~65mStart
Module 7

SOX ITGC

Master IT General Controls, segregation of duties, and change management.

4 lessons · 0%~50mStart
Module 8

HIPAA and HITECH

Master the three rules and the three safeguards.

4 lessons · 0%~50mStart
Module 9

HITRUST

Understand the HITRUST CSF and why healthcare vendors pursue it.

2 lessons · 0%~30mStart
Module 10

Third-Party Risk Management

Master the vendor lifecycle and the SIG and CAIQ questionnaires.

4 lessons · 0%~55mStart
Module 11

Vulnerability Management

Master CVE, CVSS, the CISA KEV list, EPSS, and risk-based patching.

3 lessons · 0%~40mStart
Module 12

Cloud and Modern Security

Master the shared responsibility model, Zero Trust, and identity and access management.

3 lessons · 0%~50mStart
Module 13

Interview Mastery

Walk into any GRC interview calm and confident.

4 lessons · 0%~45mStart
Advanced

Advanced GRC

Ten specialized modules. 35 lessons on privacy law, FedRAMP, AI governance, FAIR, GRC platforms, and audit prep. Best after GRC Mastery or with some field experience.

Module 1

Data Privacy Laws, GDPR and CCPA

Master the global privacy landscape: GDPR, CCPA and CPRA, the growing patchwork of US state laws, and the core privacy principles every GRC professional must know.

5 lessons · 0%~60mStart
Module 2

Business Continuity and Disaster Recovery

Learn how organizations prepare for and recover from disruption, the BIA, RTO and RPO, ISO 22301, and how to build and test a continuity plan.

4 lessons · 0%~50mStart
Module 3

NIST SP 800-53 and FedRAMP

Master the federal control catalog and the cloud authorization program. Learn the 20 control families, the three baselines, and how FedRAMP builds on 800-53.

4 lessons · 0%~55mStart
Module 4

COBIT and IT Governance

Understand the leading IT governance framework, how COBIT separates governance from management, and where it fits alongside NIST and ISO.

3 lessons · 0%~40mStart
Module 5

ISO 42001 and the EU AI Act

Master the newest and fastest growing area in GRC: AI governance. Learn ISO 42001, the EU AI Act risk tiers, and how they work together.

4 lessons · 0%~55mStart
Module 6

Practical Policy Writing

Learn the real skill of writing clear, enforceable policies, standards, and procedures, and how to manage the full policy lifecycle.

3 lessons · 0%~40mStart
Module 7

Framework Cross-Mapping in Practice

Learn the daily GRC skill of mapping one set of controls to many frameworks at once, so a single control satisfies SOC 2, ISO 27001, and NIST together.

3 lessons · 0%~40mStart
Module 8

Quantitative Risk and FAIR

Move from high, medium, low to putting a real dollar value on risk. Learn the FAIR model and how to speak to executives in money.

3 lessons · 0%~40mStart
Module 9

GRC Tools and Platforms

Learn what the real GRC platforms do, how they differ, and how to speak about OneTrust, ServiceNow, Archer, LogicGate, Vanta, and Drata in an interview.

3 lessons · 0%~40mStart
Module 10

Audit Preparation and Evidence

Learn how audits really work, how to prepare, how to manage evidence, and how to respond to findings with confidence.

3 lessons · 0%~45mStart