Saltar al contenido

FieldsCybersecurityGRC Analyst

GRC Analyst

Keep the organization compliant, audited, and ahead of risk.

Career

Structure
8 modules, each ending in a milestone
Proof
Verified against real tasks from module 2
Ends in
A defended capstone and a high-assurance credential

Get early access

The journey

  1. Practised under observation

    1. Governance, risk and compliance: what this function is forThe discipline's purpose and its shared language: why organisations govern security, what the three letters actually mean, and the security literacy that makes the work real.Practised under observation
      MilestoneUnderstands the function and can talk to engineers

      Nothing an engineer tells you gets written down without being questioned first, and a document that produces no decision is named as what it is.

  2. From here, milestones are verified rather than practised.

    Verified against a real task

    1. Risk management as a disciplineThe core intellectual work: risk identified, assessed honestly, treated deliberately, and owned by somebody with the authority to act.Verified against a real task
      MilestoneRuns a risk program, not a spreadsheet

      A risk nobody had written down gets found by talking to people rather than by copying a template, every treatment carries a name and a date, and a number is refused where the data does not support one.

    2. Frameworks, regulations and the obligation landscapeWhat the organisation is actually required to do, with frameworks understood as tools rather than checklists and duplicated effort collapsed.Verified against a real task
      MilestoneMaps the obligations, collapses the duplication

      The obligations this organisation does not actually carry are ruled out rather than imported, and one control satisfies several frameworks so the evidence is collected once.

    3. Policy, standards and the control environmentTurning obligations into rules people follow: policy that is enforceable, standards that are testable, and a control environment that operates rather than decorates.Verified against a real task
      MilestonePolicy that holds, controls that operate

      Every rule is written so that breaking it can be detected, and a requirement nobody could actually meet is rewritten rather than published.

    4. Assessment, audit and evidenceFinding out whether it is true, with control testing done properly, evidence sampled honestly, and findings written to be fixed.Verified against a real task
      MilestoneTests the control, evidences the truth

      Asking whether a control happens is the weakest evidence there is and you do not stop there, the sample is one you can defend for its size and its selection, and the person who owns the control accepts the finding rather than fights it.

    5. Incident, privacy and business continuity obligationsWhen something goes wrong: the notification clock, the privacy obligations that outlast the incident, and the continuity plan that is tested rather than filed.Verified against a real task
      MilestoneMakes the determination, meets the clock

      The determination is made on the evidence available because the clock does not wait for certainty, and an exercise that reveals the plan does not work is reported as a success.

    6. Running the GRC programGovernance as a system rather than a person, with a program that scales, reporting that drives decisions, and technology that helps instead of adding process.Verified against a real task
      MilestoneRuns the program, reports the truth

      A board reads the report and states the real exposure back to you, and a measure that exists to reassure is replaced by one that shows whether the program works.

    7. The GRC Analyst in the organizationThe seat's integrity core: being useful without being captured, saying the unwelcome thing, and the honest difference between managing risk and documenting it.Verified against a real task
      MilestoneUseful, credible, and unwilling to say it is fine

      Compliant and safe are not the same sentence and you will say so, a certification that is not ready does not get signed off to be helpful, and a risk the business has been quietly accepting is put to somebody who can actually decide it.

    1. Capstone

      A program that knows the truth

      A complete governance, risk and compliance engagement for a realistic organisation, worked under observation, from a governance landscape analysis and a risk assessment through the obligation map, the policy and control environment, control testing and the incident, privacy and continuity obligations to the program design and the professional layer of the seat.

      Defence

      You walk an instructor through your own program: this organisation's top risks and who owns each, the risk you found that nobody had written down, whether the organisation is compliant and separately whether it is managing its risk, and what the organisation is quietly accepting without having decided to. The credential is not awarded if you cannot account for your own work.

    2. Credential

      High-assurance credential

      Evidence that you can tell whether an organisation is actually managing its risk, and say so when the answer is unwelcome. It does not claim seniority, and it does not oblige any employer to accept it.

      See how proof works

What is not live yet

The desktop app, consent-based observation, scoring, and credentials are in development. Nothing here implies they are live yet.

Get early access