Cybersecurity Foundations: Governance, Risk, and Compliance (GRC)
1h 56mBeginner2025-04-23
Authors

AJ Yawn
Cybersecurity Expert, Founder and CEO at ByteChek
Course details
In an increasingly complex regulatory landscape, organizations must build strong Governance, Risk, and Compliance (GRC) programs to protect their assets and ensure long-term success. In this course, cybersecurity expert AJ Yawn provides a comprehensive overview of GRC principles, frameworks, and tools, helping you understand how to align cybersecurity and compliance initiatives with business goals. Learn how to build and scale a GRC program like a product, incorporating key frameworks such as ISO 27001, SOC 2, and ISO 27701 for privacy. Build your understanding of the growing importance of AI governance and gain practical insights into managing AI-related risks and adapting to emerging regulations like the ISO AI certification and NIST AI Risk Management Framework. Whether you’re a cybersecurity professional, risk manager, or business leader, this course will equip you with the skills to implement modern, scalable GRC programs that are ready for the future.
Learning objectives
Explain the fundamentals of Governance, Risk, and Compliance (GRC) and how these concepts intersect with cybersecurity to protect organizations from regulatory and security risks.
Develop a GRC program that aligns with organizational goals by treating it as a product, leveraging iterative improvement cycles, and using modern tools to automate processes.
Recognize and apply the most important GRC frameworks and standards, including NIST, SOC 2, ISO 27001, HIPAA, and PCI-DSS, to meet regulatory and industry requirements.
Explore how AI impacts GRC practices, identify AI-related risks, and implement AI governance frameworks, including the emerging ISO AI certification standards and NIST AI RMF.
Gain insight into how GRC tools can streamline risk management and compliance processes, improve reporting, and enable continuous monitoring.
Learning objectives
Explain the fundamentals of Governance, Risk, and Compliance (GRC) and how these concepts intersect with cybersecurity to protect organizations from regulatory and security risks.
Develop a GRC program that aligns with organizational goals by treating it as a product, leveraging iterative improvement cycles, and using modern tools to automate processes.
Recognize and apply the most important GRC frameworks and standards, including NIST, SOC 2, ISO 27001, HIPAA, and PCI-DSS, to meet regulatory and industry requirements.
Explore how AI impacts GRC practices, identify AI-related risks, and implement AI governance frameworks, including the emerging ISO AI certification standards and NIST AI RMF.
Gain insight into how GRC tools can streamline risk management and compliance processes, improve reporting, and enable continuous monitoring.
Skills covered
Governance, Risk, and ComplianceIncident ResponseFoundationsCybersecurity
Concepts
0. Introduction
- 01 - Get started in cyber with GRC
1. What Is GRC
- 02 - Origin of the GRC acronym
- 03 - What is governance
- 04 - What is risk
- 05 - What is compliance
- 06 - How do GRC and cybersecurity interact
2. Building a GRC Program
- 07 - Importance of GRC for companies
- 08 - Challenges of building GRC programs
- 09 - How can GRC tools help
- 10 - GRC capability model
- 11 - GRC tips and strategies
3. Frameworks to Know
- 12 - NIST 800-39
- 13 - SOC 2
- 14 - HIPAA
- 15 - PCI-DSS
- 16 - NIST CSF
- 17 - FedRAMP
- 18 - CSA STAR
- 19 - SOX
- 20 - GDPR
- 21 - ISO 27001
- 22 - ISO 27701
4. Treat Your GRC Program Like a Product
- 23 - What does it mean to treat your GRC program like a product
- 24 - Building a GRC program using product management principles
- 25 - Key metrics for measuring the success of your GRC program
- 26 - Agile GRC - Continuous improvement in risk and compliance
5. AI in GRC
- 27 - Introduction to AI in governance, risk, and compliance
- 28 - NIST AI risk management framework
- 29 - ISO 42001 - The new AI governance certification
- 30 - Ethical considerations and AI risks in GRC
6. GRC Career Tips
- 31 - Key certifications to earn
- 32 - Important soft skills for GRC professionals
- 33 - Importance of technical skills for GRC professionals
Conclusion
- 34 - Next steps