CGRC Training Course

Training course

This is a free, self-paced reading course for CGRC: Certified in Governance, Risk and Compliance, ISC2’s credential for the people who get systems authorized. Formerly CAP, it is the recognized certification for Risk Management Framework and FedRAMP work and sits on the U.S. DoD 8140 approved list. The exam does not ask you to configure anything. It asks whether you can categorize an information system, select and tailor its controls, prove they work, assemble the package that an authorizing official will sign, and keep the whole thing defensible for years afterward, which is a different skill from securing a system, and one this course is built to teach in that order.

The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. CGRC’s seven domains are unusually even, nothing is below 10% and nothing is above 17%, which means there is no domain you can safely skim, and the module weights are there to stop you from over-investing in the documentation you already write at work. The June 2024 refresh threaded AI governance through the whole outline, so the modules cover the NIST AI RMF, ISO/IEC 42001, and the EU AI Act where the outline places them rather than parking them in a separate chapter.

CGRC Professional level 7 modules Domain-weighted Self-paced Free account

What the course covers

Security and Privacy Governance, Risk Management, and Compliance Program

Module 1 · 16%

GRC principles and the frameworks that carry them (NIST, COBIT, ISO/IEC 27001) plus the SDLC, the information lifecycle, roles and responsibilities, and the regulatory landscape running from FISMA and HIPAA to GDPR, FedRAMP, PCI DSS, and CMMC. The 2024 refresh adds AI governance boards, the NIST AI RMF, and ISO/IEC 42001.

Scope of the System

Module 2 · 10%

Describing the system and drawing its authorization boundary: information types, FIPS 199 security objectives and the high water mark, impact levels, and privacy screening. Modern scoping extends to embedded algorithms inside COTS software and to the line between model training environments and inference endpoints.

Selection and Approval of Framework, Security, and Privacy Controls

Module 3 · 14%

Baselines and inherited controls, then tailoring (scoping considerations, compensating controls, organization-defined parameters, overlays, and enhancements) followed by control allocation, documentation, stakeholder agreement, and the continuous monitoring strategy that has to be written before anything is built.

Implementation of Security and Privacy Controls

Module 4 · 17%

The heaviest domain: implementation strategy across resourcing, funding, timeline, and effectiveness; control types; executing selected and compensating controls; and documenting all of it, as-built system security plan descriptions, POA&M entries, risk registers, and the policies and procedures that prove a control actually fits the organization.

Assessment/Audit of Security and Privacy Controls

Module 5 · 16%

Planning and conducting assessments with the interview, examine, and test methods; validating evidence; writing initial and final reports; dispositioning findings as compliant, non-compliant, or not applicable; choosing risk responses; reassessing corrected findings; and building the risk response plan.

System Compliance

Module 6 · 14%

The authorization decision itself: compiling and submitting the package, determining risk posture and residual risk against acceptance criteria, securing stakeholder concurrence, and the formal outcome (ATO, denial, interim authorization, or ongoing authorization) with its terms, conditions, and notifications.

Compliance Maintenance

Module 7 · 13%

Life after authorization: change management and security impact analysis, continuous monitoring, incident response and contingency exercises, security updates, evidence collection, awareness training, audits, revising the monitoring strategy as requirements shift, and eventually decommissioning the system properly.

How to use it

Read the modules in order. CGRC is one of the few exams where the published sequence is also the real-world sequence (you cannot select controls before you have scoped the boundary, and you cannot maintain compliance for a system nobody authorized) so reading out of order costs you the causal chain the questions are built on. After each module, take the matching portion of the CGRC practice exam to check whether you can apply the step rather than describe it. The page you are reading is open to everyone; the course lessons themselves open once you are signed in to a free Certifym account.

For exam logistics, the 125 items, the three-hour timer, advanced item types, the 700-of-1000 scaled pass mark, the two-year experience requirement and the Associate of ISC2 route, see the CGRC certification guide.

CGRC Training

The RMF life cycle for the ISC2 CGRC exam, one lesson at a time.

A domain-by-domain guide to the CGRC exam, organized around the NIST Risk Management Framework. Covers governance foundations, categorization, control selection, implementation, assessment, authorization, and continuous monitoring. Written for practitioners who authorize and maintain systems in RMF-aligned programs.

Module 1: Information Security Risk Management Program 16% of exam

The governance and program context inside which all authorization work happens: GRC foundations, the legal and regulatory landscape, the RMF at a glance, roles and responsibilities, risk management concepts, ERM integration, and the Prepare step.

  • 1.1 What CGRC Is: The RMF-Focused Practitioner Role 8 min Free preview
  • 1.2 Governance, Risk, and Compliance Foundations 7 min πŸ”’
  • 1.3 The Legal, Regulatory, and Standards Landscape 8 min πŸ”’
  • 1.4 The NIST Risk Management Framework at a Glance 8 min πŸ”’
  • 1.5 Roles and Responsibilities in Authorization 7 min πŸ”’
  • 1.6 Risk Management Concepts 8 min πŸ”’
  • 1.7 Enterprise Risk Management and Program Integration 6 min πŸ”’
  • 1.8 The Prepare Step in Depth 7 min πŸ”’

Module 2: Scope of the System 10% of exam

The Categorize step: FIPS 199 impact ratings, the high water mark rule, information types from SP 800-60, system and authorization boundary, common controls and inheritance, and categorization approval and registration.

  • 2.1 The Categorize Step Overview 7 min πŸ”’
  • 2.2 Information Types (FIPS 199, NIST SP 800-60) 6 min πŸ”’
  • 2.3 System Boundaries and Authorization Boundary 7 min πŸ”’
  • 2.4 System Description and the SSP 6 min πŸ”’
  • 2.5 Common Controls and Inheritance 6 min πŸ”’
  • 2.6 Categorization Approval and Registration 5 min πŸ”’

Module 3: Selection and Approval of Security and Privacy Controls 15% of exam

The Select step: SP 800-53 catalog structure, baselines from SP 800-53B, tailoring (scoping, parameter filling, supplementation), overlays for cloud, privacy, and other communities, control documentation in the SSP, continuous monitoring strategy, and the AO's plan approval.

  • 3.1 The Select Step Overview 6 min πŸ”’
  • 3.2 NIST SP 800-53 Control Catalog Structure 7 min πŸ”’
  • 3.3 Baseline Controls: Low, Moderate, High 5 min πŸ”’
  • 3.4 Tailoring the Baseline 7 min πŸ”’
  • 3.5 Overlays 5 min πŸ”’
  • 3.6 Documenting Selected Controls in the SSP 5 min πŸ”’
  • 3.7 Continuous Monitoring Strategy Definition 5 min πŸ”’
  • 3.8 Plan Approval by the AO 4 min πŸ”’

Module 4: Implementation of Security and Privacy Controls 15% of exam

The Implement step: turning documented controls into operating controls, common and hybrid control implementation, system-specific controls across technical/procedural/personnel dimensions, evidence package assembly, role coordination, and initial POA&M.

  • 4.1 The Implement Step Overview 6 min πŸ”’
  • 4.2 Common and Hybrid Controls in Practice 6 min πŸ”’
  • 4.3 System-Specific Controls Implementation 6 min πŸ”’
  • 4.4 Documenting Control Implementations 5 min πŸ”’
  • 4.5 Evidence Package Assembly 5 min πŸ”’
  • 4.6 Implementation Roles and Handoffs 4 min πŸ”’
  • 4.7 Managing Implementation Timelines and Initial POA&M 5 min πŸ”’

Module 5: Assessment/Audit of Security and Privacy Controls 15% of exam

The Assess step: selecting an independent assessor, the Security Assessment Plan, examine/interview/test methods, the Security Assessment Report, remediation and reassessment, and the distinction between assessment, audit, and IV&V.

  • 5.1 The Assess Step Overview 6 min πŸ”’
  • 5.2 Selecting the Assessor and Independence Requirements 6 min πŸ”’
  • 5.3 The Security Assessment Plan (SAP) 6 min πŸ”’
  • 5.4 Assessment Methods: Examine, Interview, Test 6 min πŸ”’
  • 5.5 The Security Assessment Report (SAR) 5 min πŸ”’
  • 5.6 IV&V, Audit, and Assessment Distinguished 5 min πŸ”’
  • 5.7 Remediation and Reassessment 5 min πŸ”’
  • 5.8 Third-Party Attestations: SOC, FedRAMP, ISO 6 min πŸ”’

Module 6: Authorization/Approval of Information System 13% of exam

The Authorize step: assembling the authorization package, risk determination and presentation, the four decision types (ATO/IATO/ATT/denial), ongoing authorization vs. traditional reauthorization, and records retention.

  • 6.1 The Authorize Step Overview 6 min πŸ”’
  • 6.2 Assembling the Authorization Package 6 min πŸ”’
  • 6.3 Risk Determination and Presentation 6 min πŸ”’
  • 6.4 Authorization Decision Types: ATO, IATO, ATT, Denial 6 min πŸ”’
  • 6.5 Ongoing Authorization vs. Traditional Reauthorization 5 min πŸ”’
  • 6.6 Documentation and Records Retention 4 min πŸ”’

Module 7: Continuous Monitoring 16% of exam

The Monitor step: the continuous monitoring strategy, control-level monitoring (automated and manual), vulnerability management with KEV/EPSS/CVSS, configuration management and drift, POA&M as living document, security impact analysis for changes, and reporting supporting ongoing authorization decisions.

  • 7.1 The Monitor Step Overview 6 min πŸ”’
  • 7.2 The Continuous Monitoring Strategy 6 min πŸ”’
  • 7.3 Control-Level Monitoring: Automated vs. Manual 5 min πŸ”’
  • 7.4 Vulnerability Management in the RMF Context 6 min πŸ”’
  • 7.5 Configuration Management and Baseline Drift 5 min πŸ”’
  • 7.6 POA&M Management as a Living Document 5 min πŸ”’
  • 7.7 Security Impact Analysis for Changes 5 min πŸ”’
  • 7.8 Reporting, Metrics, and Ongoing Authorization Decisions 6 min πŸ”’

Frequently asked questions about the CGRC training course

Is the CGRC training course free?

Yes. The course costs nothing to read. Opening the lessons requires a free Certifym account, and nothing beyond that, no payment, no trial. It is funded by the practice-exam catalogue it sits alongside.

How is the course structured?

One module per official CGRC domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. Within each module the material is broken into short lessons, followed by key terms and further reading.

Does this replace ISC2’s official training?

No. ISC2 publishes the authoritative exam outline and sells its own official training; this course is an independent study companion, written to be read quickly and to slot alongside practice questions. Download the current outline from isc2.org and treat it as the source of truth.

Do I need the two years of experience before studying?

No. The experience requirement applies to certification, not to study, and candidates who sit the exam without it enter as an Associate of ISC2 until they earn it. What does help before you start is having seen a real authorization package, an SSP, or a POA&M. The material lands differently once you have.

What should I do after finishing the course?

Move to the CGRC practice exam and work until you are clearing 70% consistently across all seven domains. Because the CGRC weights are so even, a strong score in Implementation will not carry a weak score in Scope of the System. Then book with Pearson VUE.

Is the course current?

The course is built against the outline refreshed effective June 15, 2024, the seven domains and the weights of 16%, 10%, 14%, 17%, 16%, 14%, and 13% published on the CGRC certification guide. That refresh is the one that embedded AI governance throughout the outline, so material written for the pre-2024 CAP or CGRC syllabus is out of date. ISC2 can revise the outline at any time; verify the current version at isc2.org before you schedule.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, CGRC®, CISSP®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these independent study materials are designed. The CGRC exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.

All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam format, domain weights, and eligibility criteria are set by ISC2 and may change; always verify current details at isc2.org before scheduling your exam.