# Security Control Assessor (SCA) Practitioner: The Assessment Lifecycle (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/courses/security-control-assessor-sca-practitioner-self-paced>

## Overview

The security control assessor makes the independent judgment that an authorizing official relies on. This advanced course develops the assessor's craft end to end: establishing authority and independence, scoping the assessment, developing a Security Assessment Plan, tailoring NIST SP 800-53A procedures, and executing examine, interview, and test methods. 

Learners evaluate evidence across control types, handle common, inherited, and hybrid controls, validate technical results, and write findings that survive scrutiny. The capstone produces a complete Security Assessment Report.

## What you'll learn

- Explain SCA authority, independence, and professional judgment
- Scope an assessment and trace controls to requirements
- Develop a Security Assessment Plan and tailor SP 800-53A procedures
- Apply examine, interview, and test methods effectively
- Evaluate evidence sufficiency across control families and types
- Assess common, inherited, and hybrid controls
- Document findings, determine control effectiveness, and produce a Security Assessment Report

## Prerequisites

NIST 800-53 Advanced or a strong RMF and 800-53 background.

## Curriculum

#### Module 1: SCA Authority, Independence, and Professional Judgment

- Examine the security control assessor’s mandate, required independence, and responsibility to apply sound professional judgment.

#### Module 2: Assessment Scope, System Context, and Control Traceability

- Define the assessment scope, establish system context, and trace security controls to applicable requirements.

#### Module 3: Developing the Security Assessment Plan

- Build a Security Assessment Plan that documents the assessment approach, objectives, procedures, resources, and schedule.

#### Module 4: Tailoring Assessment Procedures, Depth, and Coverage

- Adapt NIST SP 800-53A assessment procedures, depth, and coverage to the system’s characteristics and risk profile.

#### Module 5: Executing Examine, Interview, and Test Procedures

- Apply examine, interview, and test methods to collect and validate assessment evidence.

#### Module 6: Evaluating Technical, Administrative, and Physical Evidence

- Evaluate the relevance, reliability, and sufficiency of technical, administrative, and physical evidence.

#### Module 7: Assessing Common, Inherited, and Hybrid Controls

- Assess shared control responsibilities across common, inherited, and hybrid control implementations.

#### Module 8: Validating Vulnerability and Technical-Test Results

- Confirm the accuracy, relevance, and potential impact of vulnerability scan results and other technical findings.

#### Module 9: Documenting Findings and Determining Control Effectiveness

- Write clear, evidence-based findings and determine whether controls are implemented correctly and operating effectively.

#### Module 10: Risk Analysis, Deficiency Prioritization, and POA&M Review

- Analyze risk, prioritize identified deficiencies, and review Plans of Action and Milestones for completeness and appropriateness.

#### Module 11: Developing the Security Assessment Report Capstone

- Produce a complete Security Assessment Report that documents assessment results, findings, risk implications, and supporting evidence.

## Instructors

### Wes Bryan — Instructor

Wes Bryan resides in Gainesville, Florida, and has built his career around technology, education, and helping others understand complex subjects. He values continuous learning, clear communication, and practical problem-solving. Outside of work, Wesley enjoys running, hiking, fishing, and spending time outdoors. He also has a strong interest in music and literature, enjoys reading both fiction and nonfiction, as well as playing guitar.

### Chuck Moore — Instructor

With more than 25 years of experience in IT and cybersecurity, Chuck has built a career on a strong foundation in security, networking, help desk operations, and technical training. He has helped organizations strengthen their security posture by identifying vulnerabilities, conducting threat assessments, implementing security controls, and ensuring compliance with industry standards. Combining extensive technical expertise with a passion for education, Chuck equips professionals with the knowledge and practical skills needed to recognize risks, risks and respond effectively.

## Pricing

**Tuition:** $1249
