Enterprise Compliance Frameworks & Audit Readiness
Deep-dive audit readiness across AICPA SOC, ISO Management Systems, and NIST
Master the enterprise audit lifecycle. Deconstruct AICPA SOC 1 and SOC 2 Type I & II audits, formulate legally sound system descriptions, implement ISO 27001:2022 along with companion standards (ISO 27701, 27017, 27018, 22301, 31000), and navigate US Federal NIST standards (SP 800-53, SP 800-171, RMF) and emerging NIST AI Risk Management Frameworks.
Course Prerequisites
- Technical GRC & Information Security Engineering or equivalent technical compliance familiarity.
Part of Academy Track:
What You Will Master
Curriculum Modules (3 Modules)
Explore the structured module breakdown, lesson outcomes, and practical lab exercises.
Module 1: AICPA SOC 1 & SOC 2 Audit Readiness
4 Lessons • ~4.9 Study Hours (0.49 CEUs)Welcome to Module 1: AICPA SOC 1 & SOC 2 Audit Readiness. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: A complete guide to SOC 1 Type I β what ICFR means, which service organisations need it, how the SSAE 18 standard works, and how to achieve a clean audit opinion that satisfies your clients' financial auditors.; A deep-dive into SOC 1 Type II β how the observation period works, what auditors test, how to maintain effective ICFR controls year-round, and how to produce a clean report that satisfies your clients' financial auditors.; A complete guide to SOC 2 Type I β what it is, what it covers, who needs it, the step-by-step readiness journey, what auditors look for, and how to achieve attestation without derailing your engineering team..
SOC 1 Type I β Internal Controls Over Financial Reporting
A complete guide to SOC 1 Type I β what ICFR means, which service organisations need it, how the SSAE 18 standard works, and how to achieve a clean audit opinion that satisfies your clients' financial auditors.
SOC 1 Type II β Sustaining Financial Reporting Controls
A deep-dive into SOC 1 Type II β how the observation period works, what auditors test, how to maintain effective ICFR controls year-round, and how to produce a clean report that satisfies your clients' financial auditors.
SOC 2 Type I β Trust Services Criteria & Point-in-Time Audit
A complete guide to SOC 2 Type I β what it is, what it covers, who needs it, the step-by-step readiness journey, what auditors look for, and how to achieve attestation without derailing your engineering team.
SOC 2 Type II β Sustained Operating Effectiveness & Evidence
Everything you need to know about SOC 2 Type II β from the observation period and evidence collection to what auditors test, how to maintain year-round readiness, and how to use your Type II report to close enterprise deals.
Module 2: ISO Management Systems & Certifications
8 Lessons • ~8.8 Study Hours (0.88 CEUs)Welcome to Module 2: ISO Management Systems & Certifications. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: A comprehensive guide to ISO/IEC 27001 β the global standard for information security management systems. Learn what it covers, who needs it, how to build an ISMS, what the certification audit involves, and how to maintain certification year after year.; Understand ISO/IEC 27701, the international standard extending ISO 27001 with privacy controls. Learn how to build a PIMS, satisfy GDPR accountability requirements, and achieve certification.; A complete guide to ISO/IEC 27017 β the international code of practice for cloud security controls. Learn how cloud providers and customers use ISO 27017 to manage shared responsibility and demonstrate cloud security assurance..
ISO/IEC 27001 β Information Security Management System (ISMS)
A comprehensive guide to ISO/IEC 27001 β the global standard for information security management systems. Learn what it covers, who needs it, how to build an ISMS, what the certification audit involves, and how to maintain certification year after year.
ISO/IEC 27701 β Privacy Information Management System (PIMS)
Understand ISO/IEC 27701, the international standard extending ISO 27001 with privacy controls. Learn how to build a PIMS, satisfy GDPR accountability requirements, and achieve certification.
ISO/IEC 27017 β Cloud Security Controls & Provider Assurance
A complete guide to ISO/IEC 27017 β the international code of practice for cloud security controls. Learn how cloud providers and customers use ISO 27017 to manage shared responsibility and demonstrate cloud security assurance.
ISO/IEC 27018 β Protecting Personal Data in Public Clouds
Learn how ISO/IEC 27018 extends cloud security with privacy controls for personally identifiable information (PII) in public clouds β and why it matters for GDPR compliance and enterprise trust.
ISO 22301 β Business Continuity Management Systems (BCMS)
A complete guide to ISO 22301, the international standard for business continuity management. Learn how to build a BCMS, conduct BIA, develop recovery plans, and achieve certification that satisfies regulators and enterprise buyers.
ISO 31000 β Enterprise Risk Management Principles & Guidelines
A comprehensive guide to ISO 31000, the international standard for risk management principles and guidelines. Learn how to implement a risk management framework that integrates with ISO 27001, COSO ERM, and your governance structure.
ISO/IEC 20000-1 β IT Service Management Systems (ITSMS)
A complete guide to ISO/IEC 20000-1, the international standard for IT service management. Learn how to build an SMS that improves service quality, satisfies enterprise clients, and achieves certification.
ISO 9001 β Quality Management System Certification & Engineering Integration
Learn how ISO 9001:2015 helps organisations build quality management systems that improve customer satisfaction, reduce waste, and meet supply chain requirements. Includes gap assessment, implementation, and audit guidance.
Module 3: NIST Standards, Federal Controls & AI Governance
5 Lessons • ~5.4 Study Hours (0.54 CEUs)Welcome to Module 3: NIST Standards, Federal Controls & AI Governance. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: Everything you need to know about NIST CSF 2.0 β the six functions, how to conduct a CSF assessment, build a target profile, prioritise improvements, and use the framework for board-level risk communication.; A deep dive into the NIST Risk Management Framework β the seven steps from categorisation to monitoring, how it connects to NIST SP 800-53, and how organisations use it to achieve and maintain ATO for federal systems.; An in-depth guide to NIST SP 800-53 Revision 5 β the 20 control families, how to select and tailor control baselines, how to implement the most critical controls, and how SP 800-53 relates to FedRAMP, FISMA, and CMMC..
NIST Cybersecurity Framework (CSF 2.0) β Implementation Guide
Everything you need to know about NIST CSF 2.0 β the six functions, how to conduct a CSF assessment, build a target profile, prioritise improvements, and use the framework for board-level risk communication.
NIST Risk Management Framework (RMF) β The 7-Step Process
A deep dive into the NIST Risk Management Framework β the seven steps from categorisation to monitoring, how it connects to NIST SP 800-53, and how organisations use it to achieve and maintain ATO for federal systems.
NIST SP 800-53 Rev 5 β Federal Security & Privacy Controls Catalog
An in-depth guide to NIST SP 800-53 Revision 5 β the 20 control families, how to select and tailor control baselines, how to implement the most critical controls, and how SP 800-53 relates to FedRAMP, FISMA, and CMMC.
NIST SP 800-171 β Protecting Controlled Unclassified Information (CUI)
A complete guide to NIST SP 800-171 Rev 3 β the 110 security requirements for protecting CUI in non-federal systems, how they map to CMMC, the self-assessment process, and how to close gaps before your next DoD contract.
NIST AI RMF 1.0 β Managing AI Risks & Trustworthy AI Systems
A practical guide to the NIST AI Risk Management Framework (AI RMF 1.0) β the four core functions, how to apply them to AI system development and deployment, and how AI RMF aligns with the EU AI Act and emerging AI governance requirements.
GRC & Information Security Progression
Continue advancing through the sequential curriculum stages of this academy track: