# Cyber Risk Management & GRC: From Risk to Assurance (Self-Paced)

Canonical URL: <https://www.nobledesktop.com/classes/cyber-risk-management-and-grc-self-paced>

## Overview

A full self-paced pass through governance, risk and compliance, written for whoever has to convert a technical finding into a risk decision that will survive being questioned. The course covers the arc end to end: defining governance and accountability, assessing risk, analyzing and prioritizing what comes out, picking a response, writing it into a register, mapping it to controls, validating through assessment, pushing it out to third parties, and carrying it upward to the people who decide. The NIST and commercial frameworks are taught side by side rather than one after the other, so NIST SP 800-30, 800-39 and the IR 8286 series appear next to COSO, ISO 31000, ISO/IEC 27005 and the EU Digital Operational Resilience Act — which makes the material as usable in a multinational as in a single-market business.

Quantification is where the course goes furthest. It works through the FAIR model, then applies a materiality determination against the SEC disclosure criteria in Item 1.05 of Form 8-K and Item 106 of Regulation S-K — the question boards are actually putting to their security teams, and a long way past the qualitative red, amber and green where most training stops. A closing workshop has you writing risk register entries for a fictional organization, judging whether a given scenario triggers a disclosure obligation, and arguing for a risk treatment recommendation. A scope note worth having up front: third-party content here is enterprise-level oversight and governance, and procurement-level supply chain work lives in its own course, [Cybersecurity Supply Chain Risk Management (C-SCRM) (Self-Paced)](https://www.nobledesktop.com/classes/cybersecurity-supply-chain-risk-management-c-scrm-self-paced).

## What you'll learn

- Define governance, risk and compliance, and distinguish cybersecurity risk from enterprise risk
- Establish governance structures, risk appetite and risk tolerance, and identify who holds decision authority
- Scope and conduct a cyber risk assessment, from threat sources through to documented risk
- Prioritize risk by organizational impact and select a defensible response
- Distinguish qualitative risk ratings from quantitative risk quantification, and apply the FAIR model
- Apply a materiality determination to an incident using the SEC disclosure criteria
- Build a cybersecurity risk register structured to NIST IR 8286A, and stage risks for enterprise oversight
- Map risks to security controls, and distinguish control implementation from control effectiveness
- Assess third-party and supply-chain risk at the enterprise-governance level
- Define key risk indicators, set thresholds, and communicate risk to nontechnical stakeholders

## Prerequisites

Foundational cybersecurity knowledge.

## Pricing

**Tuition:** $1049
