Logo

ISC2 Certified in Governance, Risk and Compliance® (CGRC®)

Code: isc2cgrc

What you'll learn

ISC2 Premier Partner

The Certified in Governance, Risk and Compliance (CGRC) is an information security practitioner who champions system security commensurate with an organization's mission and risk tolerance, while meeting legal and regulatory requirements.

CGRC, is a vendor-neutral cybersecurity credential, demonstrates that you have the knowledge, skills and experience required for using various frameworks to manage risk and to authorize and maintain information systems.

At the end of this course, you'll sit the ISC2 exam, and achieve your ISC2 Certified in Governance, Risk and Compliance (CGRC) certification.

Through Firebrand's Lecture | Lab | Review methodology, you'll get certified at twice the speed of the traditional training and get access to courseware, learn from certified instructors, and train in a distraction-free environment.

Audience

This course is ideal for:

  • IT, information security and cybersecurity practitioners who manage risk in information systems.
  • Any practitioner involved in authorizing and maintaining information systems.
  • Any of the following roles:
    • Authorizing Official
    • Cyber GRC Manager
    • Cybersecurity Auditor/Assessor
    • Cybersecurity Compliance Officer
    • Cybersecurity Architect
    • GRC Architect
    • GRC Information Technology Manager
    • GRC Manager
    • Cybersecurity Risk & Compliance Project Manager
    • Cybersecurity Risk & Controls Analyst
    • Cybersecurity Third Party Risk Manager
    • ‚ÄÉ
    • Enterprise Risk Manager
    • GRC Analyst
    • GRC Director
    • GRC Security Analyst
    • System Security Manager
    • System Security Officer
    • Information Assurance Manager
    • Cybersecurity Consultant

ISC2 Premier Training Partner

At Firebrand, we are proud to be an Official Training Premier Partner of ISC2 for 2025 in recognition of our commitment to delivering world-class training, certification, and professional development opportunities for Cybersecurity professionals.

Curriculum

0 modules

Domain 1: Security and Privacy Governance, Risk Management, and Compliance Program

1.1 - Demonstrate knowledge in security and privacy governance, risk management, and compliance program
1.2 - Demonstrate knowledge in security and privacy governance, risk management and compliance program processes
1.3 - Demonstrate knowledge of compliance frameworks, regulations, privacy, and security requirements

Domain 2: Scope of the System

2.1 - Describe the system
2.2 - Determine security compliance required

Domain 3: Selection and Approval of Framework, Security, and Privacy Controls

3.1 - Identify and document baseline and inherited controls
3.2 - Select and tailor controls

Domain 4: Implementation of Security and Privacy Controls

4.1 - Develop implementation strategy (e.g., resourcing, funding, timeline, effectiveness)
4.2 - Implement selected controls
4.3 - Document control implementation

Domain 5: Assessment/Audit of Security and Privacy Controls

5.1 - Prepare for assessment/audit
5.2 - Conduct assessment/audit
5.3 - Prepare the initial assessment/audit report
5.4 - Review initial assessment/audit report and plan risk response actions
5.5 - Develop final assessment/audit report
5.6 - Develop risk response plan

Domain 6: System Compliance

6.1 - Review and submit security/privacy documents
6.2 - Determine system risk posture
6.3 - Document system compliance

Domain 7: Compliance Maintenance

7.1 - Perform system change management
7.2 - Perform ongoing compliance activities based on requirements
7.3 - Engage in audits activities based on compliance requirements
7.4 - Decommission system when applicable

Prerequisites

Before attending this accelerated course, you should have:

  • To qualify for the CGRC, you must pass the exam and have at least two years of cumulative, paid work experience in one or more of the seven domains of the ISC2 CGRC Common Body of Knowledge (CBK®)
  • If you don't yet have the required experience, you may become an Associate of ISC2 after successfully passing the CGRC exam. The Associate of ISC2 will then have three years to earn the experience needed for the CGRC certification.

Exam info

At the end of this accelerated course, you'll sit the following exam at the Firebrand Training centre, covered by your Certification Guarantee:

ISC2 Certified in Governance, Risk and Compliance (CGRC) exam

  • Duration: 3 hours
  • Format: Multiple choice
  • Number of questions: 125
  • Passing score: 700 out of 1000 points
  • Languages: English
  • Domains:
    • Security and Privacy Governance, Risk Management, and Compliance Program 16%
    • Scope of the System 10%
    • Selection and Approval of Framework, Security, and Privacy Controls 14%
    • Implementation of Security and Privacy Controls 17%
    • Assessment/Audit of Security and Privacy Controls 16%
    • System Compliance 14%
    • Compliance Maintenance 13%

Course Dates

Sorry, there are currently no dates available for this course. Please submit an enquiry and one of our team will contact you about potential future dates or alternative options.

FAQs

4 question

Yes, we do provide courses suitable for beginners. However, Firebrand's accelerated courses aren't easy and it's essential that you are interested and actively pursuing a career in IT.

Traditional training providers usually run their courses from 9am to 5pm. At Firebrand Training we maximise the number of learning hours to minimise the number of training days, so you’ll be back to your job as quickly as possible. You don’t waste time travelling to several courses and finding an exam centre after that.

Firebrand's accelerated courses are constantly reviewed. We ask our delegates for feedback after every course. We are official partners with leading vendors and therefore, we're provided with certification changes and updates, which we can then implement in our course delivery at a very early stage. This feedback is then analysed in view of changes or discrepancies. We will then address the topics mentioned and have a panel of subject matter experts provide us with valuable suggestions for improvement and solutions.

If you need to learn new skills and you want to be able to put them into practice quickly, then Firebrand is the right training company for you.

Our unique accelerated training method means that we are your fastest way to learn. By delivering training for up to 12 hours per day, seven days per week, with exam centres on-site, we ensure that you are trained and certified quicker than anywhere else, having spent less time out of the office away from the day job.

Can't find the answer you're looking for?

Our expert learning advisors are ready to help. Whether you need course recommendations, have technical queries, or want to discuss your learning goals, we're just a message away.

Related courses

All ISC2 Courses

Train your team

Since 2001 we've trained 134,561 employees from thousands of large and small organisations, saving them more than one million hours in training time.

Learn More