Courses

Nine GRC frameworks and hands-on labs, walked one by one.

Pick a framework and walk it: the language, the controls, where it earns its keep, and what auditors actually look at. Each page is a preview — a full structured walk-through lives in the catalog. Pair that with a hands-on lab and you ship an artifact an interviewer can read: a risk register, a vendor review, a gap analysis, an incident response tabletop.

Framework
Framework
Advanced
Pro
CMMC

The DoD's Cybersecurity Maturity Model Certification — the gating posture assessment for defense contractors handling CUI.

Explore →
Framework
Framework
Intermediate
Pro
COBIT

ISACA's governance and management framework for enterprise IT — the language risk and audit committees speak.

Explore →
Framework
Regulation
Intermediate
Pro
GDPR

EU data protection. Lawful basis, data subject rights, DPIAs, and the 72-hour breach clock.

Explore →
Framework
Regulation
Intermediate
Pro
HIPAA

Privacy, Security, and Breach Notification rules for any US entity touching protected health information.

Explore →
Framework
Standard
Advanced
Pro
ISO 27001

The international ISMS standard. Annex A controls, certification audits, and the gold-stamp global enterprises ask for.

Explore →
Framework
Framework
Beginner
Pro
NIST CSF 2.0

A voluntary framework with the six functions Govern, Identify, Protect, Detect, Respond, Recover — language that maps to almost any other standard.

Explore →
Framework
Framework
Advanced
Pro
NIST RMF

The federal risk management lifecycle — Categorize, Select, Implement, Assess, Authorize, Monitor — and the playbook most US federal work runs on.

Explore →
Framework
Standard
Intermediate
Pro
PCI DSS

Cardholder data protection. Twelve requirements, four SAQ levels, and the only one with hard technical mandates.

Explore →
Framework
Audit
Intermediate
Pro
SOC 2

Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) — the SaaS default report in the US.

Explore →

Hands-on labs

Real company briefs, shippable artifacts.

Six guided labs anchored to a real company snapshot — a structured risk register, a vendor risk report, a SOC 2 / PCI gap analysis, a compliance checklist, an access control policy, or an incident response tabletop. Each prints an artifact you can hand to a hiring manager.

Hands-on
Risk
Beginner
40 min
Guided Risk Register — WovenCart

Build a structured 9-risk register for a mid-size D2C retailer using a guided form with 5×5 scoring and printable output.

Open lab →
Hands-on
Compliance
Beginner
40 min
Draft an Information Security Policy — pick AUP / IR / AC for WovenCart

Pick Acceptable Use, Incident Response, or Access Control; complete the per-type sections for WovenCart; receive an AI rubric review; print a polished policy document to record lab completion.

Open lab →
Hands-on
Compliance
Beginner
35 min
Compliance Checklist — WovenCart

Walk a 12–18 control statement checklist for HIPAA, PCI DSS, or GDPR and print a coverage scorecard with severity totals.

Open lab →
Hands-on
Controls
Intermediate
45 min
Gap Analysis — WovenCart

Score 10–14 control areas on a 0–3 maturity scale for NIST CSF 2.0, ISO 27001, or SOC 2 and print a Gap Analysis report (current vs target, average, remediation list low → high).

Open lab →
Hands-on
Controls
Intermediate
40 min
Vendor Risk Assessment — WovenCart

Score three realistic vendors across 8 yes/no/N-A risk dimensions and print a vendor risk report with a risk band (Low/Moderate/Elevated/High) and prioritized recommendations.

Open lab →
Hands-on
Controls
Intermediate
40 min
Incident Response Tabletop — Ransomware at Northbeam Analytics

Draft the first 90 minutes of an IR plan for a Friday-afternoon ransomware hit at a mid-size SaaS — roles, communication tree, containment decisions, and a recovery decision — score yourself against a four-criterion rubric and print the Tabletop Brief.

Open lab →