Group Purchasing
Group Purchasing
AI-FOCUSEDMAJOR UPDATES

LDR519: Cybersecurity Governance, Risk, and Compliance (GRC)

LDR519Cybersecurity Leadership, Artificial Intelligence
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
James Tarala
James Tarala
LDR519: Cybersecurity Risk Management and Compliance
Course authored by:
James Tarala
James Tarala
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 16 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Empower yourself to take command of the full GRC lifecycle: build threat models, assess risk, prioritize safeguards, and apply AI-assisted tools to drive cybersecurity decisions that deliver results.

Course Overview

This course prepares students to manage cybersecurity risk across the full governance, risk, and compliance (GRC) lifecycle using proven practices. Students learn to establish governance structures, build threats and safeguard inventories, implement and validate controls, and communicate outcomes to both technical and executive stakeholders. Through case studies and the SANS Cyber42 simulation, they gain hands-on experience aligning security measures with business goals. Designed for assessors, auditors, and second-line professionals, the course builds the technical and organizational skills needed to lead resilient, compliant GRC programs.

Strategic Risk Governance: Enterprise Security Beyond Compliance

Master the essentials of governance, risk management, and compliance with Cybersecurity Governance, Risk, and Compliance (GRC). This course equips cybersecurity professionals to address the complex landscape of organizational risk by combining structured governance practices with hands-on risk assessment and compliance implementation. Taking a systematic approach, students will learn to:

  • Develop threat models
  • Conduct risk assessments
  • Implement safeguards that meet regulatory requirements and strengthen enterprise resilience.

The course emphasizes practical methodologies and industry best practices, giving students a thorough understanding of how to apply the full GRC lifecycle in real-world environments. Through case studies and interactive simulations, students practice building threat inventories, prioritizing defenses, validating safeguards, and aligning security measures with business objectives. The curriculum incorporates established frameworks such as the Cybersecurity Risk Foundation’s Governance and Risk Model (CRF-GRM) and the NIST Risk Management Framework (RMF), providing a repeatable, structured approach to managing cybersecurity risks and demonstrating compliance. It is ideal for auditors, assessors, and second-line GRC professionals preparing for certification or seeking to validate and expand their knowledge.

Enroll in the LDR519 course to transform your cybersecurity strategy by building defensible governance programs, enhancing risk management capabilities, and demonstrating compliance with confidence. With a focus on practical application and strategic planning, this course empowers you to implement effective safeguards, measure their impact, and communicate risks persuasively to stakeholders across the enterprise.

Author Statement

"Every organization must prioritize cybersecurity governance, risk management, and compliance to protect its digital assets and ensure operational continuity. In today's rapidly evolving landscape, structured GRC practices and regular risk assessments are essential for identifying necessary safeguards and communicating vulnerabilities to stakeholders effectively.

The LDR519 course was designed to give students a comprehensive understanding of how to assess, manage, and govern cybersecurity risks systematically. Students will gain practical skills in applying a step-by-step GRC lifecycle—establishing governance structures, performing risk assessments, validating safeguards, and communicating results to leadership.

I developed this course to empower students with the knowledge, tools, and templates needed to strengthen their organization’s GRC program. Throughout the course, students learn to navigate established frameworks, validate safeguards, and integrate threat intelligence into their risk models, all while aligning cybersecurity with business objectives. My goal is for students to leave equipped to enhance their organization’s governance, proactively address risks, and persuasively communicate critical findings. Ultimately, I want students to be able to make a tangible impact on both the maturity of their organization’s cybersecurity program and its overall resilience against evolving threats."

- James Tarala

What You’ll Learn

  • Establish governance structures for cybersecurity decisions
  • Build threat and safeguard inventories
  • Select and prioritize safeguards using frameworks and threat modeling
  • Operationalize GRC through policy and program management
  • Design and execute risk assessments
  • Use AI and continuous monitoring to measure controls
  • Communicate risk to executive and technical stakeholders

Business Takeaways

  • Apply a repeatable, end-to-end GRC lifecycle
  • Improve visibility into cybersecurity risk
  • Align security efforts with business goals
  • Make defensible, evidence-based decisions
  • Increase efficiency with AI and automation
  • Strengthen consistency across teams and environments
  • Enhance resilience and audit readiness

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in LDR519: Cybersecurity Governance, Risk, and Compliance (GRC).

Section 1Foundations of Cybersecurity Governance and Risk

This section builds the foundation for a cybersecurity GRC program. Students learn how governance and risk decisions align with business goals, explore risk models, tooling, and Artificial Intelligence (AI), and apply these concepts through the Initiate and Inventory phases to define program structure, ownership, and scope.

Topics covered

  • Cybersecurity Governance and Program Foundations
  • Risk Management Models and Frameworks
  • GRC Program Structure and Decision-Making
  • GRC tooling and AI in Practice
  • Asset Inventory and Business Impact Analysis (BIA)

Labs

  • Cyber42 Case Study: Selecting a Risk Model
  • Cyber42 Case Study: Choosing a GRC Tool
  • Cyber42 Case Study: Approving a Business Impact Analysis

Overview

This section introduces the foundational concepts for building an effective cybersecurity GRC program, with a focus on practical application rather than theory. Students begin by understanding the business purpose of cybersecurity—how governance and risk management enable organizations to achieve their mission, rather than operate as isolated technical functions. The section emphasizes that cybersecurity decisions are ultimately business decisions that require alignment with organizational goals, resource constraints, and stakeholder expectations.

Students then explore cybersecurity governance and risk models, including how different frameworks approach decision-making, prioritization, and program structure. Rather than treating these models as abstract concepts, the course focuses on how they influence real-world outcomes—particularly in selecting and prioritizing safeguards. The Cybersecurity Risk Foundation’s Governance and Risk Model (CRF-GRM) is introduced as a structured, end-to-end approach that connects governance, risk management, and program execution across a defined lifecycle.

The section also examines the role of tooling in cybersecurity GRC. Students learn how organizations evolve from simple tools such as spreadsheets to more advanced GRC platforms, business intelligence systems, and integrated data environments. Emphasis is placed on selecting tools that align with program maturity and operational needs, rather than defaulting to complex platforms without a clear use case. The section further introduces AI in a practical context, focusing on where it improves efficiency—such as analysis, documentation, and pattern recognition—and where human decision-making remains essential.

Finally, students work through the first two phases of the GRC roadmap: Initiate and Inventory. They learn how to formally establish a cybersecurity program through executive sponsorship, charters, and governance structures, and how to define scope through asset inventory and Business Impact Analysis (BIA). These activities provide the foundation for all subsequent risk management decisions, ensuring that cybersecurity efforts are aligned with business priorities and focused on the systems and data that matter most.

Full Lab Details

  • Cyber42 Case Study 1.1: Selecting a Risk Model
  • Cyber42 Case Study 1.2: Choosing a GRC Tool
  • Cyber42 Case Study 1.3: Approving a Business Impact Analysis (BIA)

Full Topic Details

  • Cybersecurity Governance and Business Context
  • GRC Foundations
  • Cybersecurity Risk Management Models
  • Choosing and Adopting a Risk Model
  • GRC Tooling and Program Enablement
  • AI in Cybersecurity GRC
  • GRC Roadmap Step #1: Initiate
  • GRC Roadmap Step #2: Inventory

Section 2Selecting and Prioritizing Cybersecurity Safeguards

This section focuses on selecting and prioritizing cybersecurity safeguards to address risk and support business goals. Students evaluate frameworks, navigate multi-framework environments and apply threat modeling to map threats to safeguards. The result is a structured, defensible approach to safeguard selection based on likelihood, impact and business need.

Topics covered

  • Cybersecurity Framework Landscape and Comparison
  • Framework Selection and Adoption
  • Multi-Framework and Control Integration
  • Threat Modeling Concepts and Methods
  • Threat-Based Safeguard Prioritization

Labs

  • Cyber42 Case Study: Business-Driven Cybersecurity Framework Selection
  • Cyber42 Case Study: Categorizing Cybersecurity Safeguard Frameworks
  • Cyber42 Case Study: Creating a Cybersecurity Threat Model

Overview

This section transitions from foundational cybersecurity governance concepts into the practical process of selecting and prioritizing cybersecurity safeguards. After establishing program structure and inventorying assets, organizations must determine how to protect those assets. This requires selecting a set of safeguards that are aligned with business objectives, regulatory requirements, and the organization’s specific threat landscape. The emphasis in this section is on making defensible decisions—not simply adopting frameworks or checklists without context.

Students begin by exploring the cybersecurity safeguard framework landscape, including widely used models such as NIST, CIS Controls, and ISO standards. The course highlights that these frameworks are not interchangeable and vary significantly in scope, purpose, and technical depth. Students learn to evaluate frameworks by their coverage, applicability, and alignment with organizational needs, rather than selecting them based on familiarity or popularity.

The section then examines the reality that most organizations operate in a multi-framework environment. Instead of relying on a single standard, organizations often align with multiple frameworks simultaneously to meet regulatory, contractual, and operational requirements. Students are introduced to aggregate safeguard models—such as CRF Safeguards and other consolidated frameworks—which help simplify this complexity by normalizing and prioritizing controls across multiple standards.

A core focus of this section is integrating cybersecurity threat modeling into safeguard selection. Students learn to develop threat inventories, classify threats, and assess their likelihood and severity. The course emphasizes a safeguard-centric approach, where the goal is not to identify attackers but to understand attack capabilities and implement safeguards that prevent those capabilities from being effective. This approach provides a practical method for prioritizing cybersecurity efforts based on actual risk.

Finally, students learn how to map prioritized threats to cybersecurity safeguards to create a prioritized safeguard architecture. This mapping process ensures that safeguards are selected intentionally and aligned with the organization’s risk profile, rather than implemented in isolation. The outcome of this section is a structured, defensible approach to selecting and prioritizing cybersecurity safeguards that directly support business objectives and risk management goals.

Full Lab Details

  • Cyber Cyber42 Case Study 2.4: Business-Driven Cybersecurity Framework Selection
  • Cyber42 Case Study 2.5: Categorizing Cybersecurity Safeguard Frameworks
  • Cyber42 Case Study 2.6: Creating a Cybersecurity Threat Model

Full Topic Details

  • Cybersecurity Safeguard Framework Landscape
  • Comparing Cybersecurity Frameworks (NIST, CIS, ISO, and Others)
  • Selecting and Adopting Cybersecurity Frameworks
  • Aggregate Cybersecurity Frameworks and Safeguards
  • Operating in a Multi-Framework Environment
  • Cybersecurity Threat Modeling Concepts
  • Threat Inventory Development and Classification
  • Prioritizing Threats by Severity and Likelihood
  • Mapping Threats to Cybersecurity Safeguards

Section 3Cybersecurity GRC Program Management

This section focuses on operationalizing cybersecurity decisions by translating safeguards into governance, documentation, education, and implementation. Students learn to formalize policy, assign ownership, enable the workforce, and manage execution. The focus is on consistent, organization-wide execution that turns decisions into measurable outcomes.

Topics covered

  • Cybersecurity Governance Through Policy and Documentation
  • AI-Enabled Documentation and Governance
  • Workforce Enablement and Program Execution
  • GRC Program Management and Operational Visibility
  • Extending Governance to Third-Party and Cloud Environments

Labs

  • Cyber42 Case Study: Governing Cybersecurity Documentation
  • Cyber42 Case Study: Managing Visibility with a Risk Register
  • Cyber42 Case Study: Governing Third-Party AI Risk

Overview

This section marks a critical transition in the course—from making cybersecurity decisions to operationalizing them. Up to this point, the organization has defined its business context, inventoried assets, modeled threats, and selected safeguards. However, these decisions do not create value until they are formalized, communicated, and implemented consistently across the organization.

The section begins by addressing one of the most common failure points in cybersecurity programs: documentation. Most organizations have policies, but they are often fragmented, outdated, or disconnected from actual safeguards. Students learn how to structure cybersecurity documentation into layered components—including program charters, board-level policies, tactical policies, and procedures—and how these artifacts should reflect real decisions rather than generic best practices. A key emphasis is that documentation is not the starting point—it is the output of safeguard selection.

AI is introduced as a tool to accelerate documentation, not replace decision-making. Students explore how AI can improve clarity, consistency, and structure, while also understanding its limitations. AI-generated content often reflects common patterns rather than organizational reality, which can lead to incomplete or misleading outputs if not validated. The section reinforces that AI should be treated as a technical writer and research assistant, with human ownership and accountability remaining central to the process.

The section then moves into GRC Roadmap Step 4: Educate. Students learn that cybersecurity programs fail when workforce members do not understand or follow safeguards. Education is framed not as compliance training, but as enabling secure behavior across the organization. This includes general awareness, policy understanding, and role-specific training tailored to how different workforce members interact with systems and data. The goal is to align individual behavior with organizational cybersecurity intentions.

Next, the section covers GRC Roadmap Step 5: Implement, where strategy becomes action. Students learn how to operationalize safeguards through structured project management, resource allocation, and execution tracking. Implementation is presented as a non-linear process that requires managing exceptions, tracking issues, and maintaining visibility into progress. The section emphasizes that organizations often fail not because they choose the wrong safeguards, but because they fail to implement them effectively or consistently.

Finally, the section expands governance beyond internal operations to include third-party risk, cloud environments, and AI systems. Students explore how governance principles apply to external partners, shared responsibility models, and emerging technologies. This includes managing third-party dependencies, assessing cloud providers, and applying traditional GRC concepts to AI usage. Across all of these areas, the central theme remains consistent: cybersecurity governance is about maintaining visibility, accountability, and control over how safeguards are implemented and operated in real environments.

Full Lab Details

  • Cyber42 Case Study 3.7: Governing Cybersecurity Documentation
  • Cyber42 Case Study 3.8: Managing Visibility with a Risk Register
  • Cyber42 Case Study 3.9: Governing Third-Party AI Risk

Full Topic Details

  • Where We Are in the Journey
  • Using AI for Safeguard Selection
  • Governing Safeguard Decisions Through Policy
  • AI as a Documentation Accelerator: Capabilities and Constraints
  • GRC Roadmap Step #4: Educate
  • GRC Roadmap Step #5: Implement
  • Extending Cybersecurity Governance to Third Parties
  • Case Study: Governing Cybersecurity Risk in Cloud Environments
  • Case Study: AI Governance

Section 4Validating Cybersecurity Safeguards

This section focuses on validating whether cybersecurity safeguards are implemented and operating as intended. Students learn to design and execute risk assessments, including scoping, reviewing documentation, evaluating technical controls, and analyzing evidence. The focus is on making defensible decisions based on multiple forms of evidence.

Topics covered

  • GRC Validation and Assessment Planning
  • Assessment Scope and Stakeholder Definition
  • Evidence Collection and Evaluation Methods
  • Technical Safeguard Validation and Analysis
  • AI-Enabled and Defensible Decision-Making

Labs

  • Cyber42 Case Study: Scoping Who Will Perform a Cybersecurity Risk Assessment
  • Cyber42 Case Study: Evaluating Cybersecurity Documentation
  • Cyber42 Case Study: Validating Multi-Factor Authentication
  • Cyber42 Case Study: Prioritizing Cybersecurity Safeguards

Overview

This section focuses on one of the most critical and often misunderstood phases of a cybersecurity program—validation. After selecting and implementing safeguards, organizations must determine whether those safeguards are actually in place and functioning as intended. Validation is the process that turns assumptions into evidence and provides confidence that cybersecurity controls are achieving their intended purpose.

Students begin by learning how to scope cybersecurity risk assessments. This includes defining what is being assessed, who will perform the assessment, the assessment's quality level, and which safeguards are in scope. The section emphasizes that poorly scoped assessments lead to unclear results, wasted effort, and misaligned expectations. A structured scoping approach ensures that assessments are relevant, actionable, and aligned with business priorities.

The section then introduces risk assessment quality levels and evidence collection methods. Students learn that not all assessments provide the same level of assurance and that the quality of an assessment is driven by how evidence is gathered. These methods range from basic attestations and documentation review to direct observation, continuous monitoring, and effectiveness testing, such as penetration testing. The goal is to match the level of validation effort to the criticality of the systems and safeguards being assessed.

A significant portion of the section focuses on evaluating cybersecurity documentation. Students learn how to assess whether documentation is complete, aligned with selected safeguards, approved by appropriate stakeholders, and communicated effectively to the workforce. The section reinforces that documentation reflects intent, but does not prove implementation, and must be validated against real-world evidence.

Students then move into validating technical safeguards through direct observation, interviews, and evidence review. The section emphasizes that no single artifact—such as a policy, screenshot, or tool output—is sufficient on its own. Instead, assessors must combine multiple forms of evidence, including configurations, logs, system outputs, and stakeholder input, to determine whether safeguards are implemented and operating as expected.

The section also introduces the role of AI in safeguard validation. AI is positioned as a tool to accelerate analysis, organize large volumes of evidence, and identify patterns or inconsistencies. However, the section emphasizes that AI does not replace validation procedures or human judgment. Students learn to use AI responsibly while avoiding overconfidence in AI-generated outputs.

Finally, students learn how to analyze evidence and make defensible decisions. Validation ultimately requires assessors to interpret incomplete and sometimes conflicting information and determine the degree to which safeguards are implemented. The outcome of this process is not a collection of artifacts, but a clear, structured, and defensible conclusion that can be communicated to stakeholders.

Full Lab Details

  • Cyber42 Case Study 4.10: Scoping Who Will Perform a Cybersecurity Risk Assessment
  • Cyber42 Case Study 4.11: Evaluating Cybersecurity Documentation
  • Cyber42 Case Study 4.12: Validating Multi-Factor Authentication
  • Cyber42 Case Study 4.13: Prioritizing Cybersecurity Safeguards

Full Topic Details

  • Where We Are in the Journey
  • GRC Roadmap Step 6: Validate
    • Step #1: Scope the Subject of the Risk Assessment
    • Step #2: Scope Who Will Perform the Risk Assessment
    • Step #3: Scope the Quality Level of the Risk Assessment
    • Step #4: Scope the Safeguards for the Risk Assessment
    • Step #5: Evaluate Cybersecurity Documentation
    • Step #6: Evaluating Cybersecurity Safeguards
    • Step #7: Analyzing and Interpreting Evidence
  • AI for Safeguard Validation

Section 5GRC Engineering for AI-Enabled Continuous Monitoring and Risk Reporting

This section focuses on GRC engineering: turning cybersecurity risk management from periodic assessments into continuous, data-driven monitoring and reporting. Students learn to use business intelligence, automation, and AI to measure safeguards, reduce uncertainty, and support decisions. Focus is on continuous measurement, analysis, communication, and response.

Topics covered

  • GRC Engineering for Continuous Monitoring and Risk Measurement
  • Cybersecurity Data and Business Intelligence
  • Data Integration and Risk Visibility
  • Metrics and Risk Communication
  • Risk Response and Lifecycle Management

Labs

  • Cyber42 Case Study: Asset-Oriented Risk Assessment
  • Cyber42 Case Study: Managing a Cybersecurity Risk Register
  • Cyber42 Case Study: Capstone Project – International Program Expansion

Overview

This section represents the transition from validating cybersecurity safeguards to operationalizing cybersecurity risk management through continuous monitoring and reporting. After identifying and validating safeguards, organizations must continuously measure their effectiveness and communicate results to stakeholders. The section emphasizes that cybersecurity risk management is an ongoing process that requires consistent visibility into the state of safeguards across the organization.

Students begin by learning how cybersecurity programs evolve from manual assessments to automated, data-driven analytics. The section introduces the concept that cybersecurity is increasingly a measurable discipline, in which organizations can define the safeguards they expect to implement and then systematically measure whether those safeguards are in place and operating effectively.

The section then introduces the CRF Business Intelligence Model (BIM), which provides a structured approach to transforming safeguard data into actionable insights. Students learn how to move from selecting safeguards, to mapping tools and vendors, to collecting and aggregating data, and ultimately to measuring and reporting on cybersecurity risk. This model reinforces the idea that effective measurement requires alignment among safeguards, data sources, and business objectives.

A key focus of the section is data collection and aggregation. Students learn how cybersecurity tools generate both safeguard-centric and event-centric data, including information from protective systems (such as EDR and application control), detective systems (such as SIEM and vulnerability management), IT service management tools, and audit or penetration testing results. The section emphasizes that no single tool provides a complete view of risk—organizations must aggregate data across multiple sources to build a comprehensive picture.

The section also explores the practical challenges of implementing continuous monitoring. Students learn how to collect data via APIs and exports, normalize and aggregate it into centralized platforms, and build dashboards and reporting systems to support decision-making. The concept of a “single pane of glass” is introduced as an aspirational goal, where organizations can view cybersecurity risk across systems, safeguards, and business units in a unified way.

Students then learn how to define meaningful metrics, including Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs). The section emphasizes that metrics should be driven by prioritized safeguards, not by what is easiest to measure. Effective metrics reduce uncertainty and enable organizations to make better decisions about resource allocation, risk prioritization, and program effectiveness.

The section transitions into communicating cybersecurity risk to stakeholders. Students learn how to tailor reporting to different audiences, including executive leadership, business stakeholders, and technical teams. The section reinforces that the purpose of reporting is not to present data, but to enable decisions. Communication methods include written reports, presentations, and dashboards, each tailored to the audience's needs and expectations.

Finally, the section addresses how organizations respond to cybersecurity risk and track it over time. Students learn the common response options—accept, mitigate, remediate, transfer, or ignore risk—and the importance of documenting and tracking risks in a cybersecurity risk register. The section emphasizes that cybersecurity risk is ultimately a business responsibility, with cybersecurity professionals acting as advisors to support informed decision-making.

Full Lab Details

  • Cyber42 Case Study 5.14: Asset-Oriented Risk Assessment
  • Cyber42 Case Study 5.15: Managing a Cybersecurity Risk Register
  • Cyber42 Case Study 5.16: Capstone Project – International Program Expansion

Full Topic Details

  • Where We Are in the Journey
  • AI and Continuous Monitoring
  • Continuous Monitoring and Asset-Centric Risk Management
  • Penetration Testing and Safeguard Validation
  • Present Cybersecurity Risk to Stakeholders
  • Managing a Cybersecurity Risk Register
  • Cybersecurity Risk Remediation and Response
  • Course Summary

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all the specified requirements.

This is common sense, but back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Requirements

  • Processor: CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class or Apple Mac systems using the M1/M2/M3 processor.
  • Memory: 8GB of RAM or more is required.
  • Free Disk Space: 20GB of free storage space or more is required.
  • Wireless 802.11 capability: There is no wired Internet access in the classroom.
  • USB-A read / write capability: This is recommended in case students need to exchange large files during class. At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Host Operating System: Latest version of Windows 10, Windows 11, or macOS 10.15.x or newer. Fully patch your host operating system prior to the course to ensure you have the right drivers and patches installed.
  • Local Administrator Rights: Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • Endpoint Protection Software: You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Operating System Updates: Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux Workstations: Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials.
  • Microsoft Office: Microsoft Office (any currently supported version) installed on your host. Note that you can download Office Trial Software online (free for 30 days). Open Office is NOT supported for this course.
  • Web Browser: A web browser you feel comfortable using during class. Microsoft Edge, Googler Chrome, or Mozilla Firefox will all be supported in class. If you choose to use a different browser on your host, you are solely responsible for configuring it to work with the course materials.

If you have additional questions about the laptop specifications, please contact customer service.

LDR519 training is recommended for a diverse range of individuals, including:

  • Risk Management Professionals
  • Governance, Risk, Compliance Professionals
  • Second-Line GRC Teams
  • Directors of Security Compliance
  • Information Assurance Management
  • System Administrators / Engineers

  • Printed and electronic courseware
  • Cybersecurity risk assessment templates, tools, and checklists
  • Access to the Cyber42 security leadership simulation web app
  • MP3 audio files of the complete course lecture
  • Exercise workbook and electronic workbook with detailed step-by-step instructions for case studies covered in class

A basic understanding of cybersecurity concepts and business risk management is helpful but not required. Experience with frameworks such as NIST, ISO, or CIS will be beneficial. LDR519 is designed for assessors, auditors, and second-line GRC professionals looking to build the technical and organizational skills needed to own and operationalize a full GRC program.

LDR519 is part of the Cybersecurity Leadership Curriculum and is one of three courses that make up the Cyber Risk Officer Triad. The Cyber Risk Officer Triad equips you to build effective security programs, strengthen governance, manage incidents, and demonstrate compliance. This path develops the skills needed to lead and manage cybersecurity risk as a core business function.

Cybersecurity GRC is the integrated practice of governing security programs, managing risk systematically, and validating compliance so that cybersecurity decisions are defensible and aligned with business outcomes. Effective GRC ensures that security investments are prioritized based on real business risk, accountability is clearly defined, and the organization can demonstrate compliance with confidence.

GRC engineering is the practice of turning governance, risk, and compliance into repeatable operational workflows. In LDR519, students learn how to apply that approach through safeguard selection, policy and documentation, validation, AI-assisted analysis, continuous monitoring, data integration, metrics, dashboards, and risk reporting. The result is a more measurable, defensible, and sustainable way to run a GRC program.

LDR519 builds the hands-on skills that separate GRC practitioners who execute tasks from those who own and lead programs. You will leave equipped to build governance structures, conduct defensible risk assessments, govern third-party and AI-related risk, and communicate cybersecurity outcomes in business terms—capabilities that are increasingly critical for senior GRC, audit, and compliance roles.

Relevant Job Roles

Cyber Risk Officer

Cybersecurity Leadership

Lead cybersecurity risk strategy at the highest level.

Explore learning path

Cyber Legal, Policy & Compliance Officer

European Cybersecurity Skills Framework

Manages compliance with cybersecurity-related standards, legal and regulatory frameworks based on the organisation’s strategy and legal requirements.

Explore learning path

Risk Management (BURM)

Skills Framework for the Information Age

Analysis of threats, vulnerabilities, and potential impacts to support prioritised risk mitigation. Outputs inform investment decisions and align cyber risk with business tolerance levels.

Explore learning path

Senior Security Leader

Cybersecurity Leadership

Daily focus is on the oversight of technical teams while aligning them to overall business strategies. Includes titles such as Technical Director, Information Security Officer, and CISO.

Explore learning path

Governance (GOVN)

Skills Framework for the Information Age

Development of frameworks that align technology use with business objectives and regulatory requirements. Focus areas include policy design, risk controls, and enterprise accountability structures.

Explore learning path

Cybersecurity Risk Manager

European Cybersecurity Skills Framework

Manage the organisation's cybersecurity-related risks aligned to the organisation’s strategy. Develop, maintain and communicate the risk management processes and reports.

Explore learning path

Enterprise Architecture (OPM 651)

NICE: Design and Development

Responsible for developing and maintaining business, systems, and information processes to support enterprise mission needs. Develops technology rules and requirements that describe baseline and target architectures.

Explore learning path

Governance, Risk, and Compliance

SCyWF: Governance, Risk, Compliance And Laws

This role governs cybersecurity structures and processes. Find the SANS courses that map to the Governance, Risk, and Compliance SCyWF Work Role.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 22

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources