Enterprise Compliance Frameworks & Audit Readiness

Deep-dive audit readiness across AICPA SOC, ISO Management Systems, and NIST

Master the enterprise audit lifecycle. Deconstruct AICPA SOC 1 and SOC 2 Type I & II audits, formulate legally sound system descriptions, implement ISO 27001:2022 along with companion standards (ISO 27701, 27017, 27018, 22301, 31000), and navigate US Federal NIST standards (SP 800-53, SP 800-171, RMF) and emerging NIST AI Risk Management Frameworks.

$119 $24 80% OFF
2 CEU Credits
20 Study Hours (4 Weeks)
Intermediate
3 Modules
17 Hands-on Labs
Course Tuition
$119 $24 80% OFF
CEU Credits 2 CEUs
Study Workload Breakdown (20 Hours):
Architectural Reading & Theory: 6.3 hrs
Hands-on Labs & Coding Drills: 12.8 hrs
Live Mentorship Cohort $150

Prefer live accountability? Join a guided 4–6 week cohort with weekly live faculty calls, 1-on-1 code reviews & capstone grading. Subsidized by Savadub Limited CSR.

Join Cohort ($150)
Subsidized Tuition: This course is made accessible at $24 through the Corporate Social Responsibility (CSR) endowment from Savadub Limited and partner sponsors.

Course Prerequisites

Part of Academy Track:
Enterprise GRC & Information Security Engineering Stage 2 of 5 Courses in this track progression.
Access Lab Materials on LMS
Competency Matrix

What You Will Master

Draft audit-proof System Descriptions adhering to DC Section 200 guidelines
Lead external auditors through SOC 2 Type II testing periods without qualified opinions
Establish an ISO 27001 Information Security Management System (ISMS) from scratch
Apply the NIST AI Risk Management Framework (AI RMF 1.0) to generative systems
Detailed Syllabus

Curriculum Modules (3 Modules)

Explore the structured module breakdown, lesson outcomes, and practical lab exercises.

01

Module 1: AICPA SOC 1 & SOC 2 Audit Readiness

4 Lessons • ~4.9 Study Hours (0.49 CEUs)
~4.9 hrs 0.49 CEUs

Welcome to Module 1: AICPA SOC 1 & SOC 2 Audit Readiness. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: A complete guide to SOC 1 Type I β€” what ICFR means, which service organisations need it, how the SSAE 18 standard works, and how to achieve a clean audit opinion that satisfies your clients' financial auditors.; A deep-dive into SOC 1 Type II β€” how the observation period works, what auditors test, how to maintain effective ICFR controls year-round, and how to produce a clean report that satisfies your clients' financial auditors.; A complete guide to SOC 2 Type I β€” what it is, what it covers, who needs it, the step-by-step readiness journey, what auditors look for, and how to achieve attestation without derailing your engineering team..

01
SOC 1 Type I β€” Internal Controls Over Financial Reporting

A complete guide to SOC 1 Type I β€” what ICFR means, which service organisations need it, how the SSAE 18 standard works, and how to achieve a clean audit opinion that satisfies your clients' financial auditors.

~70 min Lab Exercise
02
SOC 1 Type II β€” Sustaining Financial Reporting Controls

A deep-dive into SOC 1 Type II β€” how the observation period works, what auditors test, how to maintain effective ICFR controls year-round, and how to produce a clean report that satisfies your clients' financial auditors.

~65 min Lab Exercise
03
SOC 2 Type I β€” Trust Services Criteria & Point-in-Time Audit

A complete guide to SOC 2 Type I β€” what it is, what it covers, who needs it, the step-by-step readiness journey, what auditors look for, and how to achieve attestation without derailing your engineering team.

~85 min Lab Exercise
04
SOC 2 Type II β€” Sustained Operating Effectiveness & Evidence

Everything you need to know about SOC 2 Type II β€” from the observation period and evidence collection to what auditors test, how to maintain year-round readiness, and how to use your Type II report to close enterprise deals.

~75 min Lab Exercise
Automated Code Evaluations & Lab Grading in LMS Launch in LMS Playground

Welcome to Module 2: ISO Management Systems & Certifications. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: A comprehensive guide to ISO/IEC 27001 β€” the global standard for information security management systems. Learn what it covers, who needs it, how to build an ISMS, what the certification audit involves, and how to maintain certification year after year.; Understand ISO/IEC 27701, the international standard extending ISO 27001 with privacy controls. Learn how to build a PIMS, satisfy GDPR accountability requirements, and achieve certification.; A complete guide to ISO/IEC 27017 β€” the international code of practice for cloud security controls. Learn how cloud providers and customers use ISO 27017 to manage shared responsibility and demonstrate cloud security assurance..

01
ISO/IEC 27001 β€” Information Security Management System (ISMS)

A comprehensive guide to ISO/IEC 27001 β€” the global standard for information security management systems. Learn what it covers, who needs it, how to build an ISMS, what the certification audit involves, and how to maintain certification year after year.

~70 min Lab Exercise
02
ISO/IEC 27701 β€” Privacy Information Management System (PIMS)

Understand ISO/IEC 27701, the international standard extending ISO 27001 with privacy controls. Learn how to build a PIMS, satisfy GDPR accountability requirements, and achieve certification.

~65 min Lab Exercise
03
ISO/IEC 27017 β€” Cloud Security Controls & Provider Assurance

A complete guide to ISO/IEC 27017 β€” the international code of practice for cloud security controls. Learn how cloud providers and customers use ISO 27017 to manage shared responsibility and demonstrate cloud security assurance.

~65 min Lab Exercise
04
ISO/IEC 27018 β€” Protecting Personal Data in Public Clouds

Learn how ISO/IEC 27018 extends cloud security with privacy controls for personally identifiable information (PII) in public clouds β€” and why it matters for GDPR compliance and enterprise trust.

~65 min Lab Exercise
05
ISO 22301 β€” Business Continuity Management Systems (BCMS)

A complete guide to ISO 22301, the international standard for business continuity management. Learn how to build a BCMS, conduct BIA, develop recovery plans, and achieve certification that satisfies regulators and enterprise buyers.

~65 min Lab Exercise
06
ISO 31000 β€” Enterprise Risk Management Principles & Guidelines

A comprehensive guide to ISO 31000, the international standard for risk management principles and guidelines. Learn how to implement a risk management framework that integrates with ISO 27001, COSO ERM, and your governance structure.

~65 min Lab Exercise
07
ISO/IEC 20000-1 β€” IT Service Management Systems (ITSMS)

A complete guide to ISO/IEC 20000-1, the international standard for IT service management. Learn how to build an SMS that improves service quality, satisfies enterprise clients, and achieves certification.

~65 min Lab Exercise
08
ISO 9001 β€” Quality Management System Certification & Engineering Integration

Learn how ISO 9001:2015 helps organisations build quality management systems that improve customer satisfaction, reduce waste, and meet supply chain requirements. Includes gap assessment, implementation, and audit guidance.

~65 min Lab Exercise
Automated Code Evaluations & Lab Grading in LMS Launch in LMS Playground

Welcome to Module 3: NIST Standards, Federal Controls & AI Governance. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: Everything you need to know about NIST CSF 2.0 β€” the six functions, how to conduct a CSF assessment, build a target profile, prioritise improvements, and use the framework for board-level risk communication.; A deep dive into the NIST Risk Management Framework β€” the seven steps from categorisation to monitoring, how it connects to NIST SP 800-53, and how organisations use it to achieve and maintain ATO for federal systems.; An in-depth guide to NIST SP 800-53 Revision 5 β€” the 20 control families, how to select and tailor control baselines, how to implement the most critical controls, and how SP 800-53 relates to FedRAMP, FISMA, and CMMC..

01
NIST Cybersecurity Framework (CSF 2.0) β€” Implementation Guide

Everything you need to know about NIST CSF 2.0 β€” the six functions, how to conduct a CSF assessment, build a target profile, prioritise improvements, and use the framework for board-level risk communication.

~65 min Lab Exercise
02
NIST Risk Management Framework (RMF) β€” The 7-Step Process

A deep dive into the NIST Risk Management Framework β€” the seven steps from categorisation to monitoring, how it connects to NIST SP 800-53, and how organisations use it to achieve and maintain ATO for federal systems.

~65 min Lab Exercise
03
NIST SP 800-53 Rev 5 β€” Federal Security & Privacy Controls Catalog

An in-depth guide to NIST SP 800-53 Revision 5 β€” the 20 control families, how to select and tailor control baselines, how to implement the most critical controls, and how SP 800-53 relates to FedRAMP, FISMA, and CMMC.

~65 min Lab Exercise
04
NIST SP 800-171 β€” Protecting Controlled Unclassified Information (CUI)

A complete guide to NIST SP 800-171 Rev 3 β€” the 110 security requirements for protecting CUI in non-federal systems, how they map to CMMC, the self-assessment process, and how to close gaps before your next DoD contract.

~65 min Lab Exercise
05
NIST AI RMF 1.0 β€” Managing AI Risks & Trustworthy AI Systems

A practical guide to the NIST AI Risk Management Framework (AI RMF 1.0) β€” the four core functions, how to apply them to AI system development and deployment, and how AI RMF aligns with the EU AI Act and emerging AI governance requirements.

~65 min Lab Exercise
Automated Code Evaluations & Lab Grading in LMS Launch in LMS Playground

GRC & Information Security Progression

Continue advancing through the sequential curriculum stages of this academy track:

Enroll in GRC-201 on LMS