Only 4 days
Classroom / Online Live
07/07/2025 (Monday)
Overview
The Certified in Governance, Risk and Compliance (CGRC) is an information security practitioner who champions system security commensurate with an organization’s mission and risk tolerance, while meeting legal and regulatory requirements.
CGRC, is a vendor-neutral cybersecurity credential, demonstrates that you have the knowledge, skills and experience required for using various frameworks to manage risk and to authorize and maintain information systems.
At the end of this course, you’ll sit the ISC2 exam, and achieve your ISC2 Certified in Governance, Risk and Compliance (CGRC) certification.
Through Firebrand’s Lecture | Lab | Review methodology, you’ll get certified at twice the speed of the traditional training and get access to courseware, learn from certified instructors, and train in a distraction-free environment.
Audience
This course is ideal for:
- IT, information security and cybersecurity practitioners who manage risk in information systems.
- Any practitioner involved in authorizing and maintaining information systems.
- Any of the following roles:
- Authorizing Official
- Cyber GRC Manager
- Cybersecurity Auditor/Assessor
- Cybersecurity Compliance Officer
- Cybersecurity Architect
- GRC Architect
- GRC Information Technology Manager
- GRC Manager
- Cybersecurity Risk & Compliance Project Manager
- Cybersecurity Risk & Controls Analyst
- Cybersecurity Third Party Risk Manager
- Enterprise Risk Manager
- GRC Analyst
- GRC Director
- GRC Security Analyst
- System Security Manager
- System Security Officer
- Information Assurance Manager
- Cybersecurity Consultant
Curriculum
Domain 1: Security and Privacy Governance, Risk Management, and Compliance Program
1.1 - Demonstrate knowledge in security and privacy governance, risk management, and compliance program
1.2 - Demonstrate knowledge in security and privacy governance, risk management and compliance program processes
1.3 - Demonstrate knowledge of compliance frameworks, regulations, privacy, and security requirements
Domain 2: Scope of the System
2.1 - Describe the system
2.2 - Determine security compliance required
Domain 3: Selection and Approval of Framework, Security, and Privacy Controls
3.1 - Identify and document baseline and inherited controls
3.2 - Select and tailor controls
Domain 4: Implementation of Security and Privacy Controls
4.1 - Develop implementation strategy (e.g., resourcing, funding, timeline, effectiveness)
4.2 - Implement selected controls
4.3 - Document control implementation
Domain 5: Assessment/Audit of Security and Privacy Controls
5.1 - Prepare for assessment/audit
5.2 - Conduct assessment/audit
5.3 - Prepare the initial assessment/audit report
5.4 - Review initial assessment/audit report and plan risk response actions
5.5 - Develop final assessment/audit report
5.6 - Develop risk response plan
Domain 6: System Compliance
6.1 - Review and submit security/privacy documents
6.2 - Determine system risk posture
6.3 - Document system compliance
Domain 7: Compliance Maintenance
7.1 - Perform system change management
7.2 - Perform ongoing compliance activities based on requirements
7.3 - Engage in audits activities based on compliance requirements
7.4 - Decommission system when applicable
Exam Track
At the end of this accelerated course, you’ll sit the following exam at the Firebrand Training centre, covered by your Certification Guarantee:
ISC2 Certified in Governance, Risk and Compliance (CGRC) exam
- Duration: 3 hours
- Format: Multiple choice
- Number of questions: 125
- Passing score: 700 out of 1000 points
- Languages: English
- Domains:
- Security and Privacy Governance, Risk Management, and Compliance Program 16%
- Scope of the System 10%
- Selection and Approval of Framework, Security, and Privacy Controls 14%
- Implementation of Security and Privacy Controls 17%
- Assessment/Audit of Security and Privacy Controls 16%
- System Compliance 14%
- Compliance Maintenance 13%
Prerequisites
Before attending this accelerated course, you should have:
- To qualify for the CGRC, you must pass the exam and have at least two years of cumulative, paid work experience in one or more of the seven domains of the ISC2 CGRC Common Body of Knowledge (CBK®)
- If you don’t yet have the required experience, you may become an Associate of ISC2 after successfully passing the CGRC exam. The Associate of ISC2 will then have three years to earn the experience needed for the CGRC certification.
What's Included
Your accelerated course includes:
- Accommodation *
- Meals, unlimited snacks, beverages, tea and coffee *
- On-site exams **
- Exam vouchers **
- Practice tests **
- Certification Guarantee ***
- Courseware
- Up-to 12 hours of instructor-led training each day
- 24-hour lab access
- Digital courseware **
* For residential training only. Accommodation is included from the night before the course starts. This doesn't apply for online courses.
** Some exceptions apply. Please refer to the Exam Track or speak with our experts.
*** Pass first time or train again free as many times as it takes, unlimited for 1 year. Just pay for accommodation, exams, and incidental costs.
Benefits
Seven reasons why you should sit your course with Firebrand Training
- Two options of training. Choose between residential classroom-based, or online courses
- You'll be certified fast. With us, you’ll be trained in record time
- Our course is all-inclusive. A one-off fee covers all course materials, exams**, accommodation* and meals*. No hidden extras.
- Pass the first time or train again for free. This is our guarantee. We’re confident you’ll pass your course the first time. But if not, come back within a year and only pay for accommodation, exams and incidental costs
- You’ll learn more. A day with a traditional training provider generally runs from 9 am – 5 pm, with a nice long break for lunch. With Firebrand Training you’ll get at least 12 hours/day of quality learning time, with your instructor
- You’ll learn faster. Chances are, you’ll have a different learning style to those around you. We combine visual, auditory and tactile styles to deliver the material in a way that ensures you will learn faster and more easily
- You’ll be studying with the best. We’ve been named in the Training Industry’s “Top 20 IT Training Companies of the Year” every year since 2010. As well as winning many more awards, we’ve trained and certified over 135,000 professionals
*For residential training only. Doesn't apply for online courses
**Some exceptions apply. Please refer to the Exam Track or speak with our experts
Think you are ready for the course? Take a FREE practice test to assess your knowledge! Free Practice Test