INTERMEDIATE6 lessons · 6 quizzes

GRC Capstone: Building a Security Program

This capstone applies governance, risk, compliance, policy, assurance, resilience, third-party risk, and executive communication to one fictional B2B software company. The goal is not to produce the biggest register or the longest policy. It is to create a traceable chain from business context and obligations to risk decisions, controls, evidence, accountable action, and leadership oversight.

0/6

Lessons

0%

Complete

Course syllabus

Lessons in sequence

Move through each lesson in order, then validate with the quiz where one is available.

01

Charter the Program and Establish Scope

Quiz included

Lesson 1 of 6

02

Assess Risk and Assign Decisions

Quiz included

Lesson 2 of 6

03

Translate Outcomes into a Control System

Quiz included

Lesson 3 of 6

04

Test Controls and Evaluate Evidence

Quiz included

Lesson 4 of 6

05

Resolve Findings and Govern Risk Treatment

Quiz included

Lesson 5 of 6

06

Report Residual Risk and Improve the Program

Quiz included

Lesson 6 of 6