Risk, Governance, and Compliance

Frameworks, audits, vendor risk, and vulnerability programs.

7 guides

Governance, risk, and compliance is the part of security that decides what gets done, in what order, and how you prove it happened. It has a reputation for being paperwork. In practice it is the reason anything gets funded.

These guides cover the frameworks that show up in real jobs: the CIS Critical Security Controls, the NIST Cybersecurity Framework 2.0, and the audit standards such as SOC 2, ISO 27001, and CMMC. They also cover the two programs that eat most of a security team's week: third party risk and vulnerability management.

Weeks 4 through 6 of the mentorship are entirely about this work, including a challenge where you have to produce clean evidence for an auditor out of messy data.

Learn This at HackRange

GRC roles are one of the most common ways people move into security without a technical background. The mentorship covers the frameworks and the evidence work side by side.