Training course
This is a free, self-paced reading course for CGRC: Certified in Governance, Risk and Compliance, ISC2’s credential for the people who get systems authorized. Formerly CAP, it is the recognized certification for Risk Management Framework and FedRAMP work and sits on the U.S. DoD 8140 approved list. The exam does not ask you to configure anything. It asks whether you can categorize an information system, select and tailor its controls, prove they work, assemble the package that an authorizing official will sign, and keep the whole thing defensible for years afterward, which is a different skill from securing a system, and one this course is built to teach in that order.
The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. CGRC’s seven domains are unusually even, nothing is below 10% and nothing is above 17%, which means there is no domain you can safely skim, and the module weights are there to stop you from over-investing in the documentation you already write at work. The June 2024 refresh threaded AI governance through the whole outline, so the modules cover the NIST AI RMF, ISO/IEC 42001, and the EU AI Act where the outline places them rather than parking them in a separate chapter.
What the course covers
Security and Privacy Governance, Risk Management, and Compliance Program
Module 1 · 16%GRC principles and the frameworks that carry them (NIST, COBIT, ISO/IEC 27001) plus the SDLC, the information lifecycle, roles and responsibilities, and the regulatory landscape running from FISMA and HIPAA to GDPR, FedRAMP, PCI DSS, and CMMC. The 2024 refresh adds AI governance boards, the NIST AI RMF, and ISO/IEC 42001.
Scope of the System
Module 2 · 10%Describing the system and drawing its authorization boundary: information types, FIPS 199 security objectives and the high water mark, impact levels, and privacy screening. Modern scoping extends to embedded algorithms inside COTS software and to the line between model training environments and inference endpoints.
Selection and Approval of Framework, Security, and Privacy Controls
Module 3 · 14%Baselines and inherited controls, then tailoring (scoping considerations, compensating controls, organization-defined parameters, overlays, and enhancements) followed by control allocation, documentation, stakeholder agreement, and the continuous monitoring strategy that has to be written before anything is built.
Implementation of Security and Privacy Controls
Module 4 · 17%The heaviest domain: implementation strategy across resourcing, funding, timeline, and effectiveness; control types; executing selected and compensating controls; and documenting all of it, as-built system security plan descriptions, POA&M entries, risk registers, and the policies and procedures that prove a control actually fits the organization.
Assessment/Audit of Security and Privacy Controls
Module 5 · 16%Planning and conducting assessments with the interview, examine, and test methods; validating evidence; writing initial and final reports; dispositioning findings as compliant, non-compliant, or not applicable; choosing risk responses; reassessing corrected findings; and building the risk response plan.
System Compliance
Module 6 · 14%The authorization decision itself: compiling and submitting the package, determining risk posture and residual risk against acceptance criteria, securing stakeholder concurrence, and the formal outcome (ATO, denial, interim authorization, or ongoing authorization) with its terms, conditions, and notifications.
Compliance Maintenance
Module 7 · 13%Life after authorization: change management and security impact analysis, continuous monitoring, incident response and contingency exercises, security updates, evidence collection, awareness training, audits, revising the monitoring strategy as requirements shift, and eventually decommissioning the system properly.
How to use it
Read the modules in order. CGRC is one of the few exams where the published sequence is also the real-world sequence (you cannot select controls before you have scoped the boundary, and you cannot maintain compliance for a system nobody authorized) so reading out of order costs you the causal chain the questions are built on. After each module, take the matching portion of the CGRC practice exam to check whether you can apply the step rather than describe it. The page you are reading is open to everyone; the course lessons themselves open once you are signed in to a free Certifym account.
For exam logistics, the 125 items, the three-hour timer, advanced item types, the 700-of-1000 scaled pass mark, the two-year experience requirement and the Associate of ISC2 route, see the CGRC certification guide.
CGRC Training
The RMF life cycle for the ISC2 CGRC exam, one lesson at a time.
A domain-by-domain guide to the CGRC exam, organized around the NIST Risk Management Framework. Covers governance foundations, categorization, control selection, implementation, assessment, authorization, and continuous monitoring. Written for practitioners who authorize and maintain systems in RMF-aligned programs.
Module 1: Information Security Risk Management Program 16% of exam
The governance and program context inside which all authorization work happens: GRC foundations, the legal and regulatory landscape, the RMF at a glance, roles and responsibilities, risk management concepts, ERM integration, and the Prepare step.
- 1.1 What CGRC Is: The RMF-Focused Practitioner Role 8 min Free preview
- 1.2 Governance, Risk, and Compliance Foundations 7 min π
- 1.3 The Legal, Regulatory, and Standards Landscape 8 min π
- 1.4 The NIST Risk Management Framework at a Glance 8 min π
- 1.5 Roles and Responsibilities in Authorization 7 min π
- 1.6 Risk Management Concepts 8 min π
- 1.7 Enterprise Risk Management and Program Integration 6 min π
- 1.8 The Prepare Step in Depth 7 min π
Module 2: Scope of the System 10% of exam
The Categorize step: FIPS 199 impact ratings, the high water mark rule, information types from SP 800-60, system and authorization boundary, common controls and inheritance, and categorization approval and registration.
- 2.1 The Categorize Step Overview 7 min π
- 2.2 Information Types (FIPS 199, NIST SP 800-60) 6 min π
- 2.3 System Boundaries and Authorization Boundary 7 min π
- 2.4 System Description and the SSP 6 min π
- 2.5 Common Controls and Inheritance 6 min π
- 2.6 Categorization Approval and Registration 5 min π
Module 3: Selection and Approval of Security and Privacy Controls 15% of exam
The Select step: SP 800-53 catalog structure, baselines from SP 800-53B, tailoring (scoping, parameter filling, supplementation), overlays for cloud, privacy, and other communities, control documentation in the SSP, continuous monitoring strategy, and the AO's plan approval.
- 3.1 The Select Step Overview 6 min π
- 3.2 NIST SP 800-53 Control Catalog Structure 7 min π
- 3.3 Baseline Controls: Low, Moderate, High 5 min π
- 3.4 Tailoring the Baseline 7 min π
- 3.5 Overlays 5 min π
- 3.6 Documenting Selected Controls in the SSP 5 min π
- 3.7 Continuous Monitoring Strategy Definition 5 min π
- 3.8 Plan Approval by the AO 4 min π
Module 4: Implementation of Security and Privacy Controls 15% of exam
The Implement step: turning documented controls into operating controls, common and hybrid control implementation, system-specific controls across technical/procedural/personnel dimensions, evidence package assembly, role coordination, and initial POA&M.
- 4.1 The Implement Step Overview 6 min π
- 4.2 Common and Hybrid Controls in Practice 6 min π
- 4.3 System-Specific Controls Implementation 6 min π
- 4.4 Documenting Control Implementations 5 min π
- 4.5 Evidence Package Assembly 5 min π
- 4.6 Implementation Roles and Handoffs 4 min π
- 4.7 Managing Implementation Timelines and Initial POA&M 5 min π
Module 5: Assessment/Audit of Security and Privacy Controls 15% of exam
The Assess step: selecting an independent assessor, the Security Assessment Plan, examine/interview/test methods, the Security Assessment Report, remediation and reassessment, and the distinction between assessment, audit, and IV&V.
- 5.1 The Assess Step Overview 6 min π
- 5.2 Selecting the Assessor and Independence Requirements 6 min π
- 5.3 The Security Assessment Plan (SAP) 6 min π
- 5.4 Assessment Methods: Examine, Interview, Test 6 min π
- 5.5 The Security Assessment Report (SAR) 5 min π
- 5.6 IV&V, Audit, and Assessment Distinguished 5 min π
- 5.7 Remediation and Reassessment 5 min π
- 5.8 Third-Party Attestations: SOC, FedRAMP, ISO 6 min π
Module 6: Authorization/Approval of Information System 13% of exam
The Authorize step: assembling the authorization package, risk determination and presentation, the four decision types (ATO/IATO/ATT/denial), ongoing authorization vs. traditional reauthorization, and records retention.
- 6.1 The Authorize Step Overview 6 min π
- 6.2 Assembling the Authorization Package 6 min π
- 6.3 Risk Determination and Presentation 6 min π
- 6.4 Authorization Decision Types: ATO, IATO, ATT, Denial 6 min π
- 6.5 Ongoing Authorization vs. Traditional Reauthorization 5 min π
- 6.6 Documentation and Records Retention 4 min π
Module 7: Continuous Monitoring 16% of exam
The Monitor step: the continuous monitoring strategy, control-level monitoring (automated and manual), vulnerability management with KEV/EPSS/CVSS, configuration management and drift, POA&M as living document, security impact analysis for changes, and reporting supporting ongoing authorization decisions.
- 7.1 The Monitor Step Overview 6 min π
- 7.2 The Continuous Monitoring Strategy 6 min π
- 7.3 Control-Level Monitoring: Automated vs. Manual 5 min π
- 7.4 Vulnerability Management in the RMF Context 6 min π
- 7.5 Configuration Management and Baseline Drift 5 min π
- 7.6 POA&M Management as a Living Document 5 min π
- 7.7 Security Impact Analysis for Changes 5 min π
- 7.8 Reporting, Metrics, and Ongoing Authorization Decisions 6 min π
Frequently asked questions about the CGRC training course
Is the CGRC training course free?
Yes. The course costs nothing to read. Opening the lessons requires a free Certifym account, and nothing beyond that, no payment, no trial. It is funded by the practice-exam catalogue it sits alongside.
How is the course structured?
One module per official CGRC domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. Within each module the material is broken into short lessons, followed by key terms and further reading.
Does this replace ISC2’s official training?
No. ISC2 publishes the authoritative exam outline and sells its own official training; this course is an independent study companion, written to be read quickly and to slot alongside practice questions. Download the current outline from isc2.org and treat it as the source of truth.
Do I need the two years of experience before studying?
No. The experience requirement applies to certification, not to study, and candidates who sit the exam without it enter as an Associate of ISC2 until they earn it. What does help before you start is having seen a real authorization package, an SSP, or a POA&M. The material lands differently once you have.
What should I do after finishing the course?
Move to the CGRC practice exam and work until you are clearing 70% consistently across all seven domains. Because the CGRC weights are so even, a strong score in Implementation will not carry a weak score in Scope of the System. Then book with Pearson VUE.
Is the course current?
The course is built against the outline refreshed effective June 15, 2024, the seven domains and the weights of 16%, 10%, 14%, 17%, 16%, 14%, and 13% published on the CGRC certification guide. That refresh is the one that embedded AI governance throughout the outline, so material written for the pre-2024 CAP or CGRC syllabus is out of date. ISC2 can revise the outline at any time; verify the current version at isc2.org before you schedule.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, CGRC®, CISSP®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these independent study materials are designed. The CGRC exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.
All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam format, domain weights, and eligibility criteria are set by ISC2 and may change; always verify current details at isc2.org before scheduling your exam.
