Training pathways

04 GRC

Governance, Risk & Compliance

Connect the control statement to the system that proves it.

Learn how governance, risk and compliance work becomes stronger when policies, access reviews, audit logs, incidents and technical evidence are understood together.

Discuss this pathway

Roles within this pathway

Where this capability can take shape

  • 01GRC Analyst
  • 02Cyber Risk Analyst
  • 03Compliance Analyst
  • 04Information Security Auditor
  • 05ISMS Coordinator
  • 06Third-Party Risk Analyst
  • 07Security Assurance Analyst
  • 08Privacy and Security Officer

Practical capability

What you work through

Risk identification and treatment planning
Control design, testing and evidence collection
Policy mapping and audit preparation
Identity governance and access reviews
Incident, vulnerability and compliance reporting
Communicating risk to technical and business teams

The precise sequence is adapted to prior experience, available hardware and the role outcome being pursued.

How practice works

A scenario should force more than one correct command.

  1. Observe

    Establish what the environment is doing before deciding what is wrong.

  2. Reason

    Form a testable explanation based on architecture, evidence and risk.

  3. Act

    Configure, test, investigate or communicate the response required by the role.

  4. Defend

    Explain the decision, its limitations and what should happen next.

No pathway works alone

See how this role connects to the rest of security.