Hope Training Academy
ISC2 Governance, Risk, and Compliance Certification (CGRC) Training Boot Camp (previously CAP)
ISC2 Governance, Risk, and Compliance Certification (CGRC) Training Boot Camp (previously CAP)
Couldn't load pickup availability
Learn how to maintain and authorize information systems within the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF). You will leave this boot camp with the knowledge and domain expertise needed to pass the ISC2 CGRC exam, previously known as CAP.
- Code LBC102
- Open enrollment
- Self paced
Overview
The ISC2 Certified in Governance, Risk, and Compliance (CGRC™), previously known as Certified Authorization Professional (CAP®), teaches you the best practices, policies, and procedures used to authorize and maintain information systems. You will learn how to use the Risk Management Framework (RMF) to support your organization's operations while complying with legal and regulatory requirements.
The CGRC certification is sought after by civilian, state, and local governments, as well as system integrators supporting these organizations. Additionally, you will learn about the purpose of information systems security authorization, describing and deciding when systems authorization is employed, and defining systems authorization, roles, and responsibilities.
Upon boot camp completion, you will have a firm understanding of the legal and regulatory requirements for Assessment and Authorization (A&A), maintaining systems documentation, and much more. You will leave with the knowledge and skills necessary to earn your ISC2 CGRC™ certification, which verifies your ability to set up the formal processes used to assess risk and establish security requirements.
The exam cost for the ISC2 CGRC™ certification exam is included with your enrollment.
Our Certification Success Program, paired with our provided prep materials, boot camp sessions, and post-work, is designed to ease any concerns you may have when taking the certification exam. If your first attempt is unsuccessful, this program provides peace of mind that you may be eligible to take the certification exam a second time (if needed) at no additional fee.
*To qualify for a second certification exam voucher, students must:
- Attend at least 85% of each day of class
- Score a 90% or higher on their final practice exam
- Take the first exam within 90 days of class completion
- Upload your exam failure notice from your first exam attempt
Objective
What you will learn
- Initiating the authorization process
- Establishing authorization boundaries
- Determining security categorization
- Performing initial risk assessment
- Selecting and refining security controls
- Documenting security control
- Performing certification phase
- Assessing security control
- Documenting results
- Conducting final risk assessments
- Generating and presenting an authorization report
- Performing continuous monitoring
- Monitoring security controls
- Monitoring and assessing changes that affect the information system
- Performing security impact assessment as needed
- Documenting and monitoring results of impact assessments
How you will benefit
- Learn how to use the RMF to support your organization's operations while complying with legal and regulatory requirements
- Focus on preparing for the CGRC certification exam through drill sessions, review of the entire CAP Body of Knowledge, and practical question and answer scenarios—all following a high-energy seminar approach
- The CGRC is the only certification under the DoD8570 mandate that aligns with each RMF step
- Show employers you have the advanced technical skills and knowledge to authorize and maintain information systems within the RMF using best practices, policies, and procedures
- The CGRC certification is sought after by civilian, state, and local governments, as well as system integrators supporting these organizations.
- Leave with the knowledge and skills necessary to earn your ISC2 CGRC certification, which verifies your ability to set up the formal processes used to assess risk and establish security requirements
Outline
- Day 1
- Risk Management Framework
- Understanding the Risk Management Framework
- Categorization of information system
- Selection of security controls
- Security control implementation
- Security control assessment
- Information system authorization
- Monitoring of security controls
- Risk Management Framework Processes
- Risk Management Framework
- Day 2
- Categorize Information Systems
- Information system
- System security plan
- Categorize a system
- National security system
- Privacy activities
- System boundaries
- Register system
- Select Security Controls
- Establish the security control baseline
- Common controls and security controls inheritance
- Risk assessment as part of the Risk Management Framework (RMF)
- Categorize Information Systems
- Day 3
- Implement Security Controls
- Implement selected security controls
- Tailoring of security controls
- Document security control implementation
- Assess Security Controls
- Prepare for security control assessment
- Establish security control assessment plan (SAP)
- Determine security control effectiveness and perform testing
- Develop initial security assessment report (SAR)
- Perform initial remediation actions
- Develop final security assessment report and addendum
- Authorize Information Systems
- Develop plan of action and milestones (POAM)
- Assemble security authorization package
- Determine risk
- Determine the acceptability of risk
- Obtain security authorization decision
- Monitor Security State
- Determine security impact of changes to system and environment
- Perform ongoing security control assessments
- Conduct ongoing remediation actions
- Update key documentation
- Perform periodic security status reporting
- Perform ongoing risk determination and acceptance
- Decommission and remove system
- Implement Security Controls
Requirements
Requirements:
Hardware Requirements:
- This course can be taken on either a PC, Mac, or Chromebook.
- A microphone.
- Speakers.
- A webcam.
Software Requirements:
- PC: Windows 7 or later.
- Mac: macOS 12 or later.
- Browser: The latest version of Google Chrome or Mozilla Firefox is preferred. Microsoft Edge and Safari are also compatible.
- Microsoft Word Online
- Adobe Acrobat Reader
- Zoom Meetings
- Software must be installed and fully operational before the course begins.
Other:
- Email capabilities and access to a personal email account.
Instructional Material Requirements:
The student materials required for this course are included in enrollment and will be available online.
Prerequisites
Prerequisites:
This course is intended for information system security officers, senior system managers, system administrators, and IT and information security professionals who use the RMF.
Certification Requirements:
In order to meet the CGRC certification requirements, you must have at least two years of paid work experience in at least one of the seven domains listed in the ISC2 CGRC™ Common Body of Knowledge (CBK). However, you can become an Associate of ISC2 by passing the exam without the required work experience.
You've got questions.We're here to help.
Instructor
Boot camp
Boot camps are led by instructors that have years of industry experience and are recognized as subject matter experts.
FAQs
What is CGRC™ (previously CAP®)?
The Certified in Governance, Risk, and Compliance (CGRC), previously known as Certified Authorization Professional (CAP certification), is designed to help you demonstrate to employers that you have the skills to advocate for the security risk management of the organization in accordance with legal and regulatory requirements. This allows you to pursue information security authorization as an information security practitioner.
What salary can I expect as a Certified Authorization Professional?
According to Burning Glass Technologies, an analytics software company that provides real-time data on job growth, skills in demand, and labor market trends, the salary of IT professionals with Certified in Governance, Risk, and Compliance certification can vary based on location and experience level. However, once you have completed the CGRC (previously CAP) program, on average, you can expect to earn an annual salary of $88,450.
Does this course prepare you for a certification?
Yes, you will be prepared for the ISC2 CGRC™ –Certified in Governance, Risk, and Compliance exam. To sit for the exam, you will need to meet the following requirements:
- At least two years of paid work experience in at least one of the seven domains listed in the ISC2 CGRC Common Body of Knowledge (CBK)
- However, you can become an Associate of ISC2 by passing the exam without the required work experience.
When can I start this course?
You can register for the boot camp whenever you are ready. Our team will help you select the session that will best fit you.
How long does it take to complete this course?
The boot camp is 3 days in length. You will have 3 months from the completion of the boot camp to access all boot camp materials.
What kind of support will I receive?
The boot camp instructor will be available during the session to answer any questions. You will also have access to the Infosec Skills platform, where you will be able to create support requests as needed.
What happens when I complete the course?
Upon successful completion of your boot camp session, you will be awarded a certificate of completion from Infosec and the school or organization that you registered through.
Am I guaranteed a job?
Hope Training Academy courses will help you gain the skills and knowledge you need to take the next step in your career and stand out to potential employers. However, you should always research the job market in your area before enrolling.
Can I get financial assistance?
Hope Training Academy courses are non-credit, so they do not qualify for federal aid, FAFSA, and Pell Grant. In some states, vocational rehab or workforce development boards may provide funding to take our courses. Additionally, you may qualify for financial assistance if you meet certain requirements. Learn more about financial assistance.
How can I get more information about this course?
If you have questions that are not answered on our website, representatives are available by phone. You can also call us at 1-855-532-7642 during regular business hours to have your questions promptly answered. If you are visiting us during non-business hours, please send us a question using the "Contact Us."
ReviewsThe course was extremely helpful and provided exactly what we needed to know in order to successfully navigate the exam. Without this I am not confident I would have passed.
Very impressed with Infosec. My instructor did a great job delivering the information strategically and in a way for all to understand. I would definitely take another class/certification prep course.
The instructor was able to take material that prior to the class had made no sense, and explained it in real world scenarios that were able to be understood.
Share
Payment & Funding — you've got options
- Credit / Debit Card — Visa, Mastercard, Discover, Amex
- Shop Pay Installments — powered by Affirm, pay over time
- Workforce Funding — ask about eligibility
- Military Benefits — find out if your benefits apply
What's Included
Every paid course comes with the Hope Training Academy advantage — at no extra cost:
- SkillDNA Profile — your verified skills passport. Every certification and competency you earn is recorded and provable to employers.
- USDOL Registered Apprenticeship Pathway — courses map to nationally registered apprenticeship standards, so your training counts toward real credentials.
- Apprenticeship & Job Matching — your SkillDNA profile qualifies you for apprenticeship openings that match what you've actually learned.
- EverVerify Apprenticeships (launching soon) — verified employers, verified openings, verified salaries. No guessing: employers post real requirements and match them against your proven skills.
- Hands-On Labs — practice on real equipment at our Indianapolis lab, with partner sites forthcoming across Indiana and the country.
- A Mission Behind Every Course — Hope Training Academy is part of Video Game Palooza Inc., a 501(c)(3) public charity. Game donations and store proceeds fund scholarships and living-wage career training.
