Course description
Our boot camp provides comprehensive coverage of the CGRC exam domains, including risk management framework, security authorization, and continuous monitoring, all delivered through hands-on, real-world scenarios. Led by experienced instructors who are CGRC-certified, the program includes official ISC2 courseware, practice exams, and access to exclusive resources.
Training Camp’s accelerated format is designed to maximize learning efficiency, allowing professionals to achieve certification in less time than traditional programs. We offer personalized support throughout the course to ensure each participant is fully prepared to pass the exam and enhance their career. With our proven expertise in governance, risk, and compliance training and our partnership with ISC2, Training Camp is the top choice for professionals pursuing the CGRC certification.
Upcoming start dates
Training content
CGRC Certification Exam Outline
CGRC DOMAIN 1: INFORMATION SECURITY RISK MANAGEMENT PROGRAM
- Understand the Foundation of an Organization-Wide Information Security Risk Management Program
- Understand Risk Management Program Processes
- Understand Regulatory and Legal Requirements
CGRC DOMAIN 2: CATEGORIZATION OF INFORMATION SYSTEMS (IS)
- Define the Information System (IS)
- Determine Categorization of the Information System (IS)
CGRC DOMAIN 3: SELECTION OF SECURITY CONTROLS
- Identify and Document Baseline and Inherited Controls
- Select and Tailor Security Controls
- Develop Security Control Monitoring Strategy
- Review and Approve Security Plan (SP)
CGRC DOMAIN 4: IMPLEMENTATION OF SECURITY CONTROLS
- Implement Selected Security Controls
- Document Security Control Implementation
CGRC DOMAIN 5: ASSESSMENT OF SECURITY CONTROLS
- Prepare for Security Control Assessment (SCA)
- Conduct Security Control Assessment (SCA)
- Prepare Initial Security Assessment Report (SAR)
- Review Interim Security Assessment Report (SAR) and Perform Initial Remediation Actions
- Develop Final Security Assessment Report (SAR) and Optional Addendum
CGRC DOMAIN 6: AUTHORIZATION OF INFORMATION SYSTEMS (IS)
- Develop Plan of Action and Milestones (POAM)
- Assemble Security Authorization Package
- Determine Information System (IS) Risk
- Make Security Authorization Decision
CGRC DOMAIN 7: CONTINUOUS MONITORING
- Determine Security Impact of Changes to Information Systems (IS) and Environment
- Perform Ongoing Security Control Assessments (SCA)
- Conduct Ongoing Remediation Actions (e.g., resulting from incidents, vulnerability scans, audits, and vendor updates)
- Update Documentation
- Perform Periodic Security Status Reporting
- Perform Ongoing Information System (IS) Risk Acceptance
- Decommission Information System (IS)
NIST/GOVERNANCE OVERVIEW
- NIST SP 800-37 rev 1/800-53 rev 4/800-53A rev 4
- FIPS 199/200
- CNSSI 1253
- NIST SP 800-30/800-39/800-60/800-64/800-115/800-137
- OMB A-123/A-130
ISC2 CGRC Certification Exam Review
- CGRC Exam Structure
- Exam Registration Process
- Time Management
- Topics and Concepts
- CAP Certification Question Structure
- Vendor Interpretation Techniques
Contact this provider
Training Camp
Training Camp is a leading provider of accelerated certification boot camps, known for our 25+ year partnership with ISC2 and our expertise in preparing professionals for the CISSP certification. Specializing in delivering immersive, hands-on training, we focus on quickly equipping...