GRC & Compliance
GRC & Compliance Foundation
Turn frameworks into controls, evidence and decisions leadership can use.
- 6 modules
- 10 labs
- ~12 hours
- Beginner

- Projects
- Certificate
- Beginner Friendly
Course overview
GRC done badly is paperwork. This course teaches the working version: risk that drives decisions, policies people follow, and control evidence that survives an audit.
You run a full risk assessment, write policy, build a control matrix mapped to recognised frameworks, and prepare an audit evidence pack.
What you will be able to do
- Run a structured risk assessment and score risk consistently
- Write policies and standards people can actually follow
- Map controls across NIST CSF, ISO 27001 and CIS
- Collect and organise audit evidence
- Communicate risk to non-technical stakeholders
Curriculum
- 1
Governance Foundations
Who decides what, and on what authority.
- Governance structures
- Policy hierarchy
- Roles and accountability
- 2
Risk Management
From register to decision.
- Risk identification
- Qualitative and quantitative scoring
- Treatment options
- Risk register hygiene
- 3
Control Frameworks
NIST, ISO and CIS without the confusion.
- NIST CSF
- ISO 27001 Annex A
- CIS Controls
- Cross-framework mapping
- 4
Policy & Standards Writing
Documents that change behaviour.
- Policy structure
- Standards vs procedures
- Exception handling
- 5
Audit & Evidence
Prove the control operates.
- Evidence types
- Sampling
- Audit preparation
- Findings and remediation plans
- 6
Third Party & AI Governance
Risk you do not directly control.
- Vendor risk assessment
- Contractual controls
- AI governance basics
Labs you will build
PrimeSec does not hand you a pre-built machine. You get professional lab guides and build the environment yourself — that is where the skill comes from.
- Build a risk register for a fictional organisation
- Score and prioritise ten realistic risks
- Draft an information security policy
- Create a control matrix mapped to NIST CSF and ISO 27001
- Assemble an audit evidence pack
- Complete a vendor risk assessment
Portfolio projects
- A full risk assessment report with treatment plan
- A policy set with mapped controls
- An audit readiness pack for a chosen framework
Frequently asked questions
Do you provide the lab environment?
No — and that is intentional. PrimeSec gives you professional lab guides that teach you to build and configure the environment yourself using your own machine, Hyper-V, VMware, VirtualBox, Docker, or a cloud free tier. Building and troubleshooting the environment is part of the skill.
Is this course self-paced?
GRC & Compliance Foundation is self-paced. Lessons, knowledge checks, labs and projects unlock in order so you always know what to do next.
Do I get a certificate?
You receive a PrimeSec course completion certificate once every module, lab and project requirement is met. It demonstrates completion and practical work — not an accredited industry certification.
Will cloud labs cost me money?
Labs are designed around free tiers and local virtualisation wherever possible, and every cloud lab includes cleanup steps so you do not leave billable resources running.
Related courses
Cybersecurity
SOC Analyst Level 1: Blue Team Fundamentals
Beginner · 12 modules · 18 labs
Network Security
Network Security Essentials
Beginner · 8 modules · 12 labs
Cloud Security
AWS Security Essentials
Beginner · 10 modules · 16 labs
