Skip to content

Certified in Governance, Risk and Compliance (CGRC)

Professional training. Expert instructors. Better value. No compromises.

CY-008 Live Instructor-Led Training
ISC2 5 Days 40 Hours
$2,199

Expert Training. Better Value.

Why pay $3,990 elsewhere?

Pricing shown is for individual enrollment.

Training a Team?

Ask us about group pricing, custom scheduling, and focused delivery.

Contact Us

ISC2 Certified in Governance, Risk and Compliance (CGRC) develops the knowledge and practical skills required to manage security and privacy risk, apply regulatory and framework requirements, and support the authorization and continued operation of information systems. It is intended for professionals working in governance, risk management, compliance, assessment, and security authorization, as well as organizations responsible for demonstrating that systems meet defined security and privacy requirements.

The curriculum follows the full compliance lifecycle, from establishing a governance and risk management program through system scoping, control selection, implementation, assessment, authorization, and ongoing monitoring. Participants examine how frameworks and regulations are translated into system requirements, how security and privacy controls are tailored and documented, how assessments and audits are conducted, and how compliance is maintained as systems, threats, and organizational requirements change.

CGRC is most relevant to security and privacy officers, risk managers, compliance professionals, assessors, auditors, system owners, and others involved in information system authorization. ISC2 requires two years of relevant professional experience for certification. For organizations, the training helps establish consistent governance and assessment practices, improve the quality of authorization documentation, and strengthen coordination among technical teams, compliance functions, leadership, and other stakeholders.

Course Objectives

What you will learn

Domain 1: Security and Privacy Governance, Risk Management, and Compliance Program

  • Demonstrate knowledge in security and privacy governance, risk management, and compliance program.
  • Demonstrate knowledge in security and privacy governance, risk management and compliance program processes.
  • Demonstrate knowledge of compliance frameworks, regulations, privacy, and security requirements.

Domain 2: Scope of the System

  • Describe the system.
  • Determine security compliance required.

Domain 3: Selection and Approval of Framework, Security, and Privacy Controls

  • Identify and document baseline and inherited controls.
  • Select and tailor controls.

Domain 4: Implementation of Security and Privacy Controls

  • Develop implementation strategy (e.g., resourcing, funding, timeline, effectiveness).
  • Implement selected controls.
  • Document control implementation.

Domain 5: Assessment/Audit of Security and Privacy Controls

  • Prepare for assessment/audit.
  • Conduct assessment/audit.
  • Prepare the initial assessment/audit report.
  • Review initial assessment/audit report and plan risk response actions.
  • Develop final assessment/audit report.
  • Develop risk response plan.

Domain 6: System Compliance

  • Review and submit security/privacy documents.
  • Determine system risk posture.
  • Document system compliance.

Domain 7: Compliance Maintenance

  • Perform system change management.
  • Perform ongoing compliance activities based on requirements.
  • Engage in audits activities based on compliance requirements.
  • Decommission system when applicable.