Hacker AcademyHacker Academy

GRC and ISO 27001 training path

GRC & ISO 27001 Practitioner Path

A practical pathway for learners who want to build cyber security governance, risk, compliance, ISMS, ISO 27001, GDPR, and business continuity knowledge.

Path overview

Governance, risk, compliance, and ISO 27001

GRC fundamentals
ISMS and ISO 27001
Risk and control ownership
GDPR awareness
Business continuity concepts

This path is designed for learners moving into GRC, compliance, audit support, ISO 27001 implementation, or security management roles.

GRC and ISO 27001 training
ControlsEvidenceAudit readiness

Path snapshot

GRC & ISO 27001 Practitioner Path

Learn the governance, risk, compliance, and ISO 27001 concepts needed for security management roles.

Level

Beginner to Intermediate

Duration

8-12 weeks part-time

Modules

6 included

Who this is for

Designed for GRC, compliance, and security management learners

This path is suitable for learners who want to work with cyber security risk, governance, ISO 27001, compliance programmes, policy, audit evidence, and business-facing security activity.

Professionals moving into GRC or compliance roles

IT or business teams supporting ISO 27001 activities

Managers and coordinators involved in security governance

Modules included

Build practical governance, risk, and compliance capability

The path combines security awareness, GRC, ISO 27001, GDPR, and business continuity concepts into a structured practitioner-focused pathway.

Introduction to Cyber Security

Learn core cyber security concepts including threats, malware, CIA triad, attacker behaviour, cyber kill chain, and IAM concepts.

CIA triadMalwareKill chainIAM

GRC

Learn governance, risk, compliance, policy structures, control ownership, security management, and practical risk treatment concepts.

GovernanceRiskComplianceControls

ISO 27001

Understand ISO 27001 principles, ISMS structure, risk assessment, controls, evidence, continual improvement, and audit preparation.

ISMSRisk assessmentControlsAudit readiness

GDPR

Learn the security and compliance concepts connected to data protection, personal data handling, accountability, and organisational obligations.

Personal dataAccountabilitySecurityCompliance

Business Continuity

Understand business continuity and resilience concepts, including continuity planning, recovery thinking, and organisational preparedness.

BCMSResilienceRecoveryContinuity planning

Optional: Vulnerability Management Overview

Connect technical vulnerability findings to business risk, remediation ownership, compliance evidence, and management reporting.

Risk contextRemediationReportingEvidence

Practical work

Practical work you will do

This path makes governance and compliance tangible through controls, evidence, and communication.

Understand control ownership, evidence, and audit readiness
Translate technical issues into management-level risk language
Connect ISO 27001, GDPR, and continuity concepts to real workflows

Skills you will build

Practical GRC and ISO 27001 capability

The goal is to help learners understand how cyber security is governed, evidenced, improved, and communicated across an organisation.

Understand how governance, risk, and compliance fit into cyber security
Support ISO 27001 and ISMS-related activities
Understand risk ownership, control ownership, and evidence collection
Translate technical issues into management-level risk language
Support policy, audit readiness, and continual improvement activity
Understand GDPR and business continuity concepts in a security context

Prerequisites

Accessible for technical and non-technical learners

This path does not require deep technical experience. Technical overview modules can be added where needed so learners can work more confidently with security teams.

Recommended before starting

  • Basic business or IT awareness
  • Interest in governance, risk, and compliance
  • No deep technical background required

Add these if needed

  • Introduction to Cyber Security
  • Basic IT Fundamentals
  • Vulnerability Management overview

Useful optional modules

  • Network Fundamentals overview
  • Security Engineering overview
  • SOC / incident response awareness

Delivery model

Structured lessons, practical examples, and mentor support

Learners get access to structured training content, practical governance and compliance examples, and instructor support to help connect frameworks, risks, controls, and evidence to real organisational activity.