# Cyber GRC Certificate Program (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/certificates/cyber-grc-certificate-program-self-paced>

## Overview

Cybersecurity money gets approved in risk language, not technical language. This self-paced path is built for the person who has to make that translation, and it runs the whole arc rather than a slice of it. You define governance and accountability, assess risk, analyze and prioritize it, choose a response, record it in a register, map it to controls, and report it upward. The federal stack is taught next to its commercial and international counterparts throughout, so NIST SP 800-30, 800-39 and the IR 8286 series sit alongside COSO, ISO 31000 and ISO/IEC 27005.

Where most compliance training stops at red, amber and green, this path keeps going. You apply the FAIR model to real loss exposure and then work a materiality determination against the SEC disclosure criteria, which is the question boards are asking their security teams right now. The supply chain half goes equally deep, covering not SBOM as a buzzword but the artifacts you will be handed and asked to judge, and the underrated skill of checking whether a federal rule you are about to cite still applies at all. The path opens with CMMC 2.0, then steps up from practitioner to program work, so you finish knowing where an organization stands before an assessment rather than after one.

## What you'll learn

- Establish governance structures, decision rights and risk appetite, and identify who may accept risk; Scope and conduct a cyber risk assessment, from threat sources through to documented risk; Distinguish qualitative risk ratings from quantification, and apply the FAIR model
- Apply a materiality determination to an incident using the SEC disclosure criteria; Build a cybersecurity risk register structured to NIST IR 8286A and stage risks for enterprise oversight; Map risks to controls, and separate control implementation from control effectiveness
- Perform criticality and dependency analysis, and find single points of failure and concentration risk; Separate organization-level, mission-level and system-level C-SCRM, and escalate to the right decision-maker; Define security requirements before procurement and write them into agreements, including flow-down to subcontractors
- Apply the NIST SP 800-53 Supply Chain Risk Management control family, SR-1 through SR-12; Evaluate software supply chain risk using SBOM, VEX, build-integrity levels and project-health tooling; Assess AI and machine learning suppliers, including model and training-data provenance
- Verify whether a cited federal rule, clause or deadline is still current before relying on it; Separate program management from system-level operations, and cybersecurity risk from privacy risk; Separate the statutory duties of the CISO and Senior Agency Official for Privacy from those of the CIO and agency head
- Select and tailor a control baseline, and justify tailoring in terms that survive oversight; Map information flows across the lifecycle and determine when a Privacy Impact Assessment is required
- Read assessment findings, track remediation through POA&Ms, and turn results into leadership decisions; Determine when an incident is a PII breach and what reporting obligations follow
- Explain what CMMC 2.0 requires, who must comply, and the assessment and certification path; Deliver and defend a leadership risk briefing framed around a decision

## Curriculum
1. **Understanding CMMC 2.0 for Federal Contractors (Self-Paced)**
2. **Cyber Risk Management & GRC: From Risk to Assurance Course (Self-Paced)**
3. **Cybersecurity Supply Chain Risk Management (C-SCRM) Course (Self-Paced)**
4. **Security & Privacy Program Management: From Governance to Assurance Course (Self-Paced)**

## Pricing

**Tuition:** $3149
