Skip to content
CBT Nuggets
DemoBook a Demo

Enterprise GRC: Risk Management and Compliance Programs

This Governance, Risk and Compliance training covers how to manage your organization's compliance-related requirements and balance them with operational risks to provide cost-efficient and in-compliance results. For systems administrators and security professionals, compliance is much more than ensuring that the right people are getting the right data — this training shows you how to prove your work, verify data integrity, and more.

Updated March 2021

14Skills
90Videos
14hTotal

Who This Course Is For

This Governance, Risk and Compliance training is considered foundational training is valuable for technical and non-technical professionals and anyone looking to validate their risk management skills.

Skills Your Team Will Gain

  • Ensuring in-compliance fulfillment of organizational responsibilities
  • Identifying opportunities to simplifying compliance needs and associated costs
  • Uncovering governing bodies and acting within compliance policies
  • Applying risk management processes

Course Curriculum

One skill is free to watch — no signup needed. The other 13 premium skills unlock for your whole team with a CBT Nuggets plan.

Free skill preview

Organizational Governance

Bob SalmansDuration: 53m12 videos

Watch this complete skill free — the same trainer, videos, and labs your team gets with a plan.

Watch free skill
  • Organizational GovernanceFree53m · 12 videos
  • Premium skill.Risk Governance57m · 12 videos
  • Premium skill.Risk and Threat Identification1h 2m · 14 videos
  • Premium skill.IT Risk Analysis and Evaluation56m · 16 videos
  • Premium skill.Vulnerability Analysis and Risk Scenario Development1h 11m · 14 videos
  • Premium skill.Control Design and Implementation54m · 14 videos
  • Premium skill.Risk Response53m · 14 videos
  • Premium skill.The Incident Response Process48m · 16 videos
  • Premium skill.Managing and Mitigating Third Party Risk55m · 14 videos
  • Premium skill.Data Discovery, Classification and IRM1h 5m · 20 videos
  • Premium skill.Compliance Frameworks and Legal Considerations53m · 12 videos
  • Premium skill.IS Audit Execution1h 11m · 18 videos
  • Premium skill.Business Continuity and Disaster Recovery Planning56m · 14 videos
  • Premium skill.Risk Monitoring and Reporting1h 19m · 18 videos
Want to browse the locked skills?
with no purchase required. Already have an account?

An account gets you the full catalog to browse, pre-assessments, quiz questions on free skills, and IT Trainerbot, with every answer citing its source video.

Put this course to work for your team

Every plan includes this course plus the full library, virtual labs, and practice exams — or talk it through with sales.

For IT leaders

What IT leaders need to know before assigning this course

Compliance programs fail when risk decisions, control evidence, incident response, third-party oversight, and audit execution are managed as disconnected activities. IT teams complete this foundational Enterprise GRC training to build a shared approach to governance, risk management, and compliance that supports audit readiness and reduces operational risk.

The course is appropriate for mixed cohorts: IT Directors can assign it to security professionals, systems administrators, technical leads, audit-facing practitioners, and non-technical stakeholders who need to understand GRC responsibilities. Plan for about 14 hours per learner, with best results when Team Leads align modules to current initiatives such as control design, vendor risk reviews, data classification, incident response, or business continuity planning.

For change management, use the course to standardize language around risk analysis, risk response, compliance frameworks, evidence, and reporting before updating processes. CBT Nuggets Playlists can sequence training by role, and Team Reporting helps Training Managers track completion across assigned teams.

Team Impact

How this training helps your team succeed

This training helps IT teams connect compliance requirements to day-to-day risk decisions, so governance work produces evidence the organization can use during audits, incidents, and vendor reviews.

  • Improve audit readiness: Teams learn how IS audit execution, compliance frameworks, and legal considerations fit into a defensible GRC program.
  • Reduce operational risk: Practitioners work through risk and threat identification, IT risk analysis, vulnerability analysis, and risk scenario development.
  • Strengthen response planning: Security and operations teams align risk response with incident response, business continuity, and disaster recovery planning.
  • Manage third-party exposure: Teams address vendor and supplier risk as part of the overall enterprise risk program, not as a separate checklist.

After completion

Capabilities your team walks away with

Knowledge

  • Governance concepts that shape enterprise risk and compliance programs
  • How risk governance connects business objectives, IT operations, and security priorities
  • Methods for identifying threats, vulnerabilities, and risk scenarios
  • Control design, implementation, monitoring, and reporting concepts
  • Compliance framework, legal, IS audit, and data classification considerations
  • Business continuity, disaster recovery, incident response, and third-party risk fundamentals

Ability

  • Evaluate IT risks and translate findings into risk response options
  • Support vulnerability analysis and develop practical risk scenarios
  • Help design and document controls that align to compliance and operational needs
  • Participate in incident response, continuity, and disaster recovery planning discussions
  • Contribute evidence and context for audits, compliance reviews, and risk reporting
  • Apply data discovery, classification, and information rights management concepts to GRC work

Readiness check

Confirm prerequisite knowledge before training begins

A short placement assessment on the CBT Nuggets assessments platform measures whether a learner already has the foundation this course assumes. IT Directors use it to put the right people in the right training — and any learner can take it right now to make sure they'll get full value from day one.

  • Questions generated from this course's own video transcripts — what gets measured is exactly what gets taught
  • Instant, per-learner results that show whether the prerequisite foundation is in place
  • Results roll up into team readiness reporting, so training hours go where they change outcomes
Runs on assessments.cbtnuggets.com — sign in with an Adept account so results roll up into team readiness reporting. Need one?
.

If gaps show up, start here

ISACA CISM – Certified Information Security Manager

This CISM training prepares IT professionals to manage enterprise-level security governance, risk, and incident response. This online, self-paced course aligns with ISACA's latest Certified Information Security Manager exam and is ideal for roles lik...

~14h

This course is included with every subscription

Unlock this one course, or get one learner — or your whole team — access to all 287 courses, virtual labs, and practice exams.

Course Unlock

Just need this course?

$169one time

No subscription

One year of access to Enterprise GRC

  • Every skill in this course
  • Its virtual labs and practice exam
  • Ask IT Trainerbot about it — free

CBT Nuggets Individual

IT Trainerbot Pro

$49per month

Billed annually

Every course, for one learner

See Individual pricing
For IT teams

CBT Nuggets Teams

IT Trainerbot for Teams

$59per seat / mo

Billed annually

From 1 learner seat · unlimited admin seats

Checking your access

Need tenant hosting, reseller terms, or payment plans on a larger agreement? Book a Demo to discuss an Enterprise contract.

See plans and pricing for your team

Trusted by 23,000+ organizations

Frequently Asked Questions

What will you learn in this governance, risk and compliance training?

This course in governance, risk and compliance teaches administrators and IT professionals how to prove that a network is compliant with all applicable regulations. Every organization has a responsibility to know applicable regulations and to prove that the network is compliant. This training covers skills related to both.

Who should take this governance, risk and compliance course?

Compliance officers are the most obvious audience for this course on governance, risk, compliance and security, but IT professionals and cybersecurity professionals should also learn what's on this course. Managing governance, risk and compliance is tricky even under the best circumstances, but introduce the unique opportunities and security risks of the cloud, and executives and decision-makers responsible for operational strategy and governance have even more to deal with and understand.

Is this training in governance, risk and compliance associated with any certifications?

No, this training in governance, risk and compliance isn't associated with any certifications because it's more focused on getting administrators up to speed on maintaining network compliance. You'll learn practical steps to applying risk management and enforcing compliance needs as well as lowering costs associated with all of it.

What certification should you consider after taking this course in governance, risk and compliance?

This is an entry-level course in governance, risk and compliance, but if you want to make a career of regulations and network compliance, you might consider ISACA's Certified in Risk and Information Systems Control (CRISC). That enterprise risk management certification covers IT risk assessment, response, security and governance.

Why should you take this governance, risk and compliance training?

You should take this course because network health depends on more than configs and technical expertise. Administrators also have to know how to generate documentation that proves a network's operations are compliant with regulations. Learn how to take part in the process of proving your network's health and compliance.

Ready to upskill your team?

Talk to our sales team to find the right plan for your organization.