GRC-260Governance, Risk & Compliance

Running a Security Awareness Program Auditors Accept

Auditors look for training evidence mapped to controls, not attendance counts. Run security awareness that satisfies them and actually changes behavior.

6 lessons About 2.5 hours 2 ALCs Certificate on completion

What you'll be able to do

  • Map training to the framework controls that require it
  • Design completion evidence auditors accept
  • Build role-specific modules for higher-risk roles
  • Measure whether behavior improves, not just completion
You finish with

A training plan mapped to controls

What's in it. A training plan mapped to framework controls, completion evidence design and role-specific modules.

You build it lesson by lesson, using your own organization, and submit it for your certificate. It's yours to keep and adapt.

Who it's for

Security awareness leads, GRC analysts and HR learning teams.

What's inside

  1. Part 1Where the requirement comes from 16 min
  2. Part 2How small teams and enterprises meet it 15 min
  3. Part 3The method, step by step 18 min
  4. Part 4Hands-on lab: small team choose one 60 min
  5. Part 5Hands-on lab: enterprise choose one 90 min
  6. Part 6Finish and submit your deliverable 16 min

Built for your size

The requirement is the same everywhere. How you meet it depends on who you have. You pick the lab that matches your organization.

Small team or early-stageOne course, everyone, tracked.
EnterpriseRole-tailoring, phishing programme, coverage matrix.

How you earn the certificate

Submit your finished deliverable, which is scored against a published rubric, and pass a short scenario quiz. Your certificate goes to your wallet and can be checked by anyone on the public register.

Ready to build a training plan mapped to controls?6 lessons, about 2.5 hours. Start whenever you're ready.
Join and enroll