# Cyber GRC Certificate Program

Canonical URL: <https://www.graduateschool.edu/certificates/cyber-grc-certificate-program>

## Overview

This certificate teaches you to turn technical findings into decisions leadership can act on. It runs the full governance, risk and compliance arc — defining accountability, assessing and prioritizing risk, choosing a response, recording it in a register, mapping it to controls, and reporting it upward — with the federal stack taught alongside its commercial and international parallels.

What sets it apart is depth in two places. Risk quantification goes past qualitative red, amber and green to the FAIR model and a materiality determination under SEC disclosure criteria, the question boards are asking now. Supply chain goes past naming SBOM to the artifacts you will actually be handed and asked to judge, and to the skill of checking whether a federal rule you are about to cite still applies. The path closes on program-level work and CMMC 2.0, so you finish knowing where an organization stands before an assessment rather than after.

## What you'll learn

- Establish governance structures, decision rights and risk appetite, and identify who may accept risk; Scope and conduct a cyber risk assessment, from threat sources through to documented risk; Distinguish qualitative risk ratings from quantification, and apply the FAIR model
- Apply a materiality determination to an incident using the SEC disclosure criteria; Build a cybersecurity risk register structured to NIST IR 8286A and stage risks for enterprise oversight; Map risks to controls, and separate control implementation from control effectiveness
- Perform criticality and dependency analysis, and find single points of failure and concentration risk; Separate organization-level, mission-level and system-level C-SCRM, and escalate to the right decision-maker; Define security requirements before procurement and write them into agreements, including flow-down to subcontractors
- Apply the NIST SP 800-53 Supply Chain Risk Management control family, SR-1 through SR-12; Evaluate software supply chain risk using SBOM, VEX, build-integrity levels and project-health tooling; Assess AI and machine learning suppliers, including model and training-data provenance
- Verify whether a cited federal rule, clause or deadline is still current before relying on it; Separate program management from system-level operations, and cybersecurity risk from privacy risk; Separate the statutory duties of the CISO and Senior Agency Official for Privacy from those of the CIO and agency head
- Select and tailor a control baseline, and justify tailoring in terms that survive oversight; Map information flows across the lifecycle and determine when a Privacy Impact Assessment is required
- Read assessment findings, track remediation through POA&Ms, and turn results into leadership decisions; Determine when an incident is a PII breach and what reporting obligations follow
- Explain what CMMC 2.0 requires, who must comply, and the assessment and certification path; Deliver and defend a leadership risk briefing framed around a decision

## Curriculum
1. **Understanding CMMC 2.0 for Federal Contractors**
2. **Cyber Risk Management & GRC: From Risk to Assurance Course**
3. **Cybersecurity Supply Chain Risk Management (C-SCRM) Course**
4. **Security & Privacy Program Management: From Governance to Assurance Course**

## Pricing

**Tuition:** $3149
