Training pathways
04 GRC
Governance, Risk & Compliance
Connect the control statement to the system that proves it.
Learn how governance, risk and compliance work becomes stronger when policies, access reviews, audit logs, incidents and technical evidence are understood together.
Discuss this pathwayRoles within this pathway
Where this capability can take shape
- 01GRC Analyst
- 02Cyber Risk Analyst
- 03Compliance Analyst
- 04Information Security Auditor
- 05ISMS Coordinator
- 06Third-Party Risk Analyst
- 07Security Assurance Analyst
- 08Privacy and Security Officer
Practical capability
What you work through
Risk identification and treatment planning
Control design, testing and evidence collection
Policy mapping and audit preparation
Identity governance and access reviews
Incident, vulnerability and compliance reporting
Communicating risk to technical and business teams
The precise sequence is adapted to prior experience, available hardware and the role outcome being pursued.
How practice works
A scenario should force more than one correct command.
- Observe
Establish what the environment is doing before deciding what is wrong.
- Reason
Form a testable explanation based on architecture, evidence and risk.
- Act
Configure, test, investigate or communicate the response required by the role.
- Defend
Explain the decision, its limitations and what should happen next.
No pathway works alone