Governance, Risk & Compliance
The most underrated cybersecurity career — non-technical OK
A 12-week non-technical-friendly bootcamp into GRC. Learn frameworks (NIST CSF 2.0, ISO 27001, SOC 2, PCI-DSS), risk management (FAIR, qualitative + quantitative), audit, and the business side of security. Designed so a finance major or law student can complete it. Maps to ISO 27001 LI, ISC2 CGRC, CISA prep.
Lessons
- What Is GRC and Why It Pays
- Risk Management Foundations
- NIST Cybersecurity Framework 2.0
- ISO/IEC 27001:2022 Part 1 — Clauses
- ISO/IEC 27001:2022 Part 2 — Annex A Controls
- SOC 2 & PCI-DSS
- Privacy & Data Protection (GDPR + DPDPA)
- Internal Audit & Evidence
- Third-Party Risk Management
- Policy, Procedure & Standard Writing
- Communicating Risk to Executives
- Capstone: ISO 27001 Implementation Project