GRC Core Foundations
Understand what GRC is, how governance, risk, and compliance work together, and master the core vocabulary every interviewer tests.
Thirteen modules. 51 lessons. Taught by ZEN.
Course content last reviewed: June 2026.
All content reflects standards and frameworks as of June 2026, including PCI DSS 4.0.1, NIST CSF 2.0, ISO 27001:2022, and NIST AI RMF 1.0.
Understand what GRC is, how governance, risk, and compliance work together, and master the core vocabulary every interviewer tests.
Master the six functions, the four tiers, profiles, and how to run a gap assessment.
Understand AI-specific risk: Govern, Map, Measure, Manage, plus bias, transparency, and explainability.
Master the ISMS, the Annex A controls, and the Statement of Applicability.
Master the five Trust Services Criteria and the difference between Type I and Type II.
Master the 12 requirements, the merchant levels, and QSA, SAQ, and ROC.
Master IT General Controls, segregation of duties, and change management.
Master the three rules and the three safeguards.
Understand the HITRUST CSF and why healthcare vendors pursue it.
Master the vendor lifecycle and the SIG and CAIQ questionnaires.
Master CVE, CVSS, the CISA KEV list, EPSS, and risk-based patching.
Master the shared responsibility model, Zero Trust, and identity and access management.
Walk into any GRC interview calm and confident.