Course 1
Learning path
Governance / Risk / Compliance
Develop security program fluency, risk language, assurance practice, and compliance execution.
This path groups the courses for one direction. Use it to understand the sequence, then open the specific course you want to work through.
Courses
24
Modules
24
Lessons
156
Completion
0%
Courses in this path
Open the course you want to work through
This path groups related courses into one branch. Course pages stay focused on the lesson-by-lesson workspace.
Course 2
Networking Foundations
Course 3
Threat Landscape and Attacker Thinking
Course 4
Operating Systems for Defenders
Course 5
Cryptography Essentials
Course 6
Defensive Web Fundamentals
Course 7
Identity and Access Management
Course 8
System Hardening Fundamentals
Course 9
Logging, Monitoring, and Telemetry
Course 10
Blue Team Operations
Course 11
Security Governance and Program Foundations
Course 12
Cloud Security Foundations
Course 13
GRC Analyst Fundamentals
Course 14
Risk Management Fundamentals
Course 15
Audit and Assurance
Course 16
Security Frameworks and Control Mapping
Course 17
Policy Writing in Practice
Course 18
Security Awareness and Culture
Course 19
Business Continuity and Disaster Recovery Planning
Course 20
GRC Capstone: Building a Security Program
Course 21
Risk Quantification with FAIR
Course 22
Privacy Law and GDPR Practice
Course 23
Compliance Program Design and Operations
Course 24
Security Architecture Review
Module preview
What this path covers
Preview the modules and lesson sequence here, then use each course page when you want the full execution view.
Security Foundations
You are currently working through Security Purpose and Defensive Outcomes in this module.
Preview lessons
- Security Purpose and Defensive OutcomesCurrent
- Confidentiality, Integrity, and AvailabilityLocked
- Authentication, Authorization, and AccountabilityLocked
+5 more lessons in this module
Networking Foundations
Complete the lessons in sequence to move this path forward.
Preview lessons
- Network Layers and Why They MatterLocked
- Network Identity: IP Addresses, MAC Addresses, and AttributionLocked
- Ports, Protocols, and ServicesLocked
+5 more lessons in this module
Threat Landscape and Attacker Thinking
Complete the lessons in sequence to move this path forward.
Preview lessons
- Attacker Motivations and ObjectivesLocked
- The Shape of an ATT&CKLocked
- Initial Access PatternsLocked
+3 more lessons in this module
Operating Systems for Defenders
Complete the lessons in sequence to move this path forward.
Preview lessons
- Processes, Users, and the Idea of Security ContextLocked
- Windows Essentials for DefendersLocked
- Linux Essentials for DefendersLocked
+3 more lessons in this module
Cryptography Essentials
Complete the lessons in sequence to move this path forward.
Preview lessons
- Cryptography Purpose and Defender ContextLocked
- Symmetric CryptographyLocked
- Asymmetric CryptographyLocked
+4 more lessons in this module
Defensive Web Fundamentals
Complete the lessons in sequence to move this path forward.
Preview lessons
- Web Architecture and Request FlowLocked
- URLs, Domains, DNS, and HostingLocked
- HTTPS and TLS in the BrowserLocked
+5 more lessons in this module
Identity and Access Management
Complete the lessons in sequence to move this path forward.
Preview lessons
- Identity, Accounts, and the Identity LifecycleLocked
- Authentication Factors and Modern AuthenticationLocked
- Federated Identity: SSO, OAuth, and OpenID ConnectLocked
+4 more lessons in this module
System Hardening Fundamentals
Complete the lessons in sequence to move this path forward.
Preview lessons
- System Hardening Purpose and Defensive ValueLocked
- Configuration Baselines and BenchmarksLocked
- Patch ManagementLocked
+3 more lessons in this module
Logging, Monitoring, and Telemetry
Complete the lessons in sequence to move this path forward.
Preview lessons
- High-Quality Security TelemetryLocked
- The Major Log Sources Every Defender Should KnowLocked
- SIEM, Log Management, and the Detection PlatformLocked
+3 more lessons in this module
Blue Team Operations
Complete the lessons in sequence to move this path forward.
Preview lessons
- Blue Team Mission and Daily WorkLocked
- The Incident LifecycleLocked
- SOC Structure and Analyst RolesLocked
+3 more lessons in this module
Security Governance and Program Foundations
Complete the lessons in sequence to move this path forward.
Preview lessons
- Security Governance Purpose and Operating ModelLocked
- The Framework and Regulatory LandscapeLocked
- Risk Management: Identification, Assessment, and TreatmentLocked
+3 more lessons in this module
Cloud Security Foundations
Complete the lessons in sequence to move this path forward.
Preview lessons
- Cloud Security Model and Shared ResponsibilityLocked
- The Shared Responsibility ModelLocked
- Cloud Identity and Access ManagementLocked
+3 more lessons in this module
GRC Analyst Fundamentals
Complete the lessons in sequence to move this path forward.
Preview lessons
- The GRC Analyst Role and Program ContextLocked
- Risk Management MethodologyLocked
- Policy Development and ManagementLocked
+4 more lessons in this module
Risk Management Fundamentals
Complete the lessons in sequence to move this path forward.
Preview lessons
- The Risk Management Lifecycle in PracticeLocked
- Risk Identification TechniquesLocked
- Risk Analysis MethodologiesLocked
+4 more lessons in this module
Audit and Assurance
Complete the lessons in sequence to move this path forward.
Preview lessons
- The Audit Profession and Its DisciplineLocked
- Internal Audit OperationsLocked
- External Audit Cycles in DepthLocked
+4 more lessons in this module
Security Frameworks and Control Mapping
Complete the lessons in sequence to move this path forward.
Preview lessons
- The Framework LandscapeLocked
- NIST CSF and SP 800-53 in PracticeLocked
- ISO 27001 and SOC 2 as Trust MechanismsLocked
+3 more lessons in this module
Policy Writing in Practice
Complete the lessons in sequence to move this path forward.
Preview lessons
- Effective Security Policies and Why They FailLocked
- Policy Lifecycle and Library ManagementLocked
- Stakeholder Management and ApprovalLocked
+2 more lessons in this module
Security Awareness and Culture
Complete the lessons in sequence to move this path forward.
Preview lessons
- Security Awareness Programs: Failure Patterns and What WorksLocked
- Program Design and Phishing SimulationLocked
- Measuring Security CultureLocked
+1 more lessons in this module
Business Continuity and Disaster Recovery Planning
Complete the lessons in sequence to move this path forward.
Preview lessons
- BC/DR Foundations and Program Failure PatternsLocked
- Business Impact AnalysisLocked
- Backup Architecture and Recovery DesignLocked
+2 more lessons in this module
GRC Capstone: Building a Security Program
Complete the lessons in sequence to move this path forward.
Preview lessons
- Scoping the Security ProgramLocked
- Conducting the Risk AssessmentLocked
- Designing the Policy LibraryLocked
+8 more lessons in this module
Risk Quantification with FAIR
Complete the lessons in sequence to move this path forward.
Preview lessons
- Qualitative Risk Limits and Quantitative AlternativesLocked
- The FAIR OntologyLocked
- Estimating FAIR InputsLocked
+3 more lessons in this module
Privacy Law and GDPR Practice
Complete the lessons in sequence to move this path forward.
Preview lessons
- The Global Privacy LandscapeLocked
- Data Mapping at ScaleLocked
- Data Protection Impact AssessmentsLocked
+3 more lessons in this module
Compliance Program Design and Operations
Complete the lessons in sequence to move this path forward.
Preview lessons
- Compliance Program DesignLocked
- Compliance Automation ToolingLocked
- Continuous Evidence CollectionLocked
+3 more lessons in this module
Security Architecture Review
Complete the lessons in sequence to move this path forward.
Preview lessons
- Architecture Review MethodologyLocked
- Cloud Architecture Security ReviewLocked
- Microservices and API ArchitectureLocked
+3 more lessons in this module
