Back to Learning Paths
Governance

Security Frameworks and Compliance

Move from framework orientation into detailed control, assurance, and continuous-monitoring requirements across major security programs.

FamilyGovernance and Emerging Risk
LevelFoundational to intermediate
Courses18
Estimated time4.5-6 hours
Audience

Security engineers, Compliance teams, Technical leaders

Outcome

Move from framework orientation into detailed control, assurance, and continuous-monitoring requirements across major security programs.

Ordered sequence

Courses in this path

18 courses
Course 0110 modules
NIST CSF 2.0 Fundamentals

A practical introduction to using NIST CSF 2.0 as a flexible cybersecurity risk management framework for outcomes, profiles, tiers, governance, communication, and continuous improvement.

Launch Course
Course 0210 modules
What Are the CIS Controls?

Open course in the Explainers catalog: What Are the CIS Controls?.

Launch Course
Course 0313 modules
OWASP Top 10 2025 Mapped to CIS Critical Security Controls

Open course in the Governance, Risk, and Compliance catalog: OWASP Top 10 2025 Mapped to CIS Critical Security Controls.

Launch Course
Course 0410 modules
What Is Zero Trust?

Open course in the Explainers catalog: What Is Zero Trust?.

Launch Course
Course 0510 modules
What Is NIST SP 800-53?

Open course in the Explainers catalog: What Is NIST SP 800-53?.

Launch Course
Course 0613 modules
OWASP Top 10 2025 Mapped to NIST SP 800-53 Rev. 5

Open course in the Governance, Risk, and Compliance catalog: OWASP Top 10 2025 Mapped to NIST SP 800-53 Rev. 5.

Launch Course
Course 0710 modules
What Is RMF?

Open course in the Explainers catalog: What Is RMF?.

Launch Course
Course 0810 modules
What Is FedRAMP?

Open course in the Explainers catalog: What Is FedRAMP?.

Launch Course
Course 0910 modules
What Is CMMC 2.0?

Open course in the Explainers catalog: What Is CMMC 2.0?.

Launch Course
Course 1013 modules
OWASP Top 10 2025 Mapped to CMMC 2.0 Practices

Open course in the Governance, Risk, and Compliance catalog: OWASP Top 10 2025 Mapped to CMMC 2.0 Practices.

Launch Course
Course 1110 modules
What Is SOC 2?

Open course in the Explainers catalog: What Is SOC 2?.

Launch Course
Course 1210 modules
SOC 2 Type I vs Type II

A practical course on the difference between SOC 2 Type I and Type II reports, evidence, scope, and sustainable readiness.

Launch Course
Course 1313 modules
OWASP Top 10 2025 Mapped to SOC 2 Trust Services Criteria

Open course in the Governance, Risk, and Compliance catalog: OWASP Top 10 2025 Mapped to SOC 2 Trust Services Criteria.

Launch Course
Course 1413 modules
OWASP Top 10 2025 Mapped to ISO/IEC 27001 and ISO/IEC 27002 Controls

Open course in the Governance, Risk, and Compliance catalog: OWASP Top 10 2025 Mapped to ISO/IEC 27001 and ISO/IEC 27002 Controls.

Launch Course
Course 1513 modules
OWASP Top 10 2025 Mapped to PCI DSS v4.0 Requirements

Open course in the Governance, Risk, and Compliance catalog: OWASP Top 10 2025 Mapped to PCI DSS v4.0 Requirements.

Launch Course
Course 1613 modules
OWASP Top 10 2025 Mapped to HIPAA Security Rule Safeguards

Open course in the Governance, Risk, and Compliance catalog: OWASP Top 10 2025 Mapped to HIPAA Security Rule Safeguards.

Launch Course
Course 1710 modules
What Is SBOM?

Open course in the Explainers catalog: What Is SBOM?.

Launch Course
Course 1810 modules
What is Continuous Monitoring?

Open course in the Explainers catalog: What is Continuous Monitoring?.

Launch Course
Related routes
Next steps