Unit 12: Risk Management, Governance, and Compliance (GRC)
Lesson at a glance
| Item | Detail | | --------------------- | --------------------------------------------------------------------------------------------------------- | | Suggested length | 4 × 60 minutes | | Recommended placement | Week 18 | | Prerequisite | Cyber I Unit 2 | | Materials | NIST CSF 2.0 reference, CIS Controls v8 reference, sample risk register template, sample policy templates |
Safety: Standard course safety; no lab attacks in this unit.
Standards & credential alignment
- NIST CSF 2.0 core functions: Govern, Identify, Protect, Detect, Respond, Recover.
- ISO/IEC 27001:2022 introduction.
- CIS Controls v8 Implementation Group 1 (IG1).
- HIPAA / PCI DSS / SOC 2 / FERPA / GDPR / CCPA awareness.
Learning objectives
By the end of this unit, students can:
- Calculate qualitative and quantitative risk: Risk = Likelihood × Impact (and SLE/ARO/ALE for quant).
- Build a 10-row risk register with treatment decisions (accept / mitigate / transfer / avoid).
- Map controls to NIST CSF 2.0 functions and categories.
- Identify which regulation applies to which industry/data type.
- Read a security policy critically and propose improvements.
Vocabulary
- Risk - The effect of uncertainty on objectives. Often Likelihood × Impact.
- Threat / vulnerability / risk / impact - review from Cyber I.
- SLE / ARO / ALE - Single Loss Expectancy / Annualized Rate of Occurrence / Annualized Loss Expectancy.
- Risk treatment - Accept, Mitigate, Transfer, Avoid.
- Control - Safeguard reducing risk (technical, administrative, physical).
- Policy / Standard / Procedure / Guideline - Strategic → Tactical → Step-by-step → Recommended.
- Audit / Assessment - External structured review / internal point-in-time check.
Teacher background (read this before the lesson)
GRC fails in a cyber class when it becomes a list of acronyms. Make every framework answer a decision: treat this risk, pick this control, write this policy so a human can follow it.
Scenario to keep on the board all week (Northlake District / Northlake Clinic — fictional):
A student information system and a small clinic share a vendor. A ransomware incident encrypts the vendor. Grades are down. Appointments are on paper. Leadership wants to know: what was the risk, who owned it, which regulation applies, and what policy would have made the next 24 hours less chaotic?
If learners treat this as "just compliance," send them back to the risk register. Compliance is the floor. The register is the work.
Materials checklist
- [ ] NIST CSF 2.0 function one-pager
- [ ] CIS Controls v8 IG1 one-pager
- [ ] Blank 10-row risk register
- [ ] Deliberately weak password policy for Day 4
- [ ] 12 regulation-matching scenarios (include FERPA, HIPAA, PCI, SOC 2, GDPR)
Pacing
| Day | Focus | Deliverable | | --- | ------------------------------------ | ---------------------------------------- | | 1 | Risk math + register | 10-row risk register | | 2 | Frameworks: NIST CSF, ISO 27001, CIS | Control mapping for 5 risks | | 3 | Regulations | Regulation-to-scenario matching exercise | | 4 | Policy critique + writing | Rewrite a weak policy |
Day 1 - Risk math
Qualitative grid (5×5):
| | Negligible | Minor | Moderate | Major | Catastrophic | | -------------- | ---------- | ----- | -------- | ----- | ------------ | | Almost certain | M | H | H | C | C | | Likely | M | M | H | H | C | | Possible | L | M | M | H | H | | Unlikely | L | L | M | M | H | | Rare | L | L | L | M | M |
Quantitative example:
Asset: Customer DB (replacement value $500K)
Threat: Ransomware
Exposure factor: 30% → SLE = $500K × 0.30 = $150K
ARO: 0.2 (once every 5 years) → ALE = $150K × 0.2 = $30K/year
Control under consideration: Immutable backups + EDR → Costs $25K/year, reduces ARO to 0.05
New ALE = $7.5K/year → Annual benefit = $22.5K, control cost $25K
Decision: marginal. Push for vendor negotiation or include other risks the same control reduces.
Risk register columns: ID, Description, Asset, Threat, Vulnerability, Likelihood, Impact, Inherent Risk, Existing Controls, Residual Risk, Treatment, Owner, Due Date.
Day 2 - Frameworks
NIST CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, Recover.
CIS Controls v8 IG1 (the practical starter pack - 56 safeguards):
- Asset inventory.
- Software inventory.
- Data management basics.
- Secure configuration.
- Account management + access control.
- Continuous vulnerability management.
- Audit log management.
- Email/web protections.
- Malware defenses.
- Data recovery.
- Network monitoring.
- Security awareness training.
- Service provider management.
- Incident response.
Map exercise: take 5 risks from Day 1, map to NIST CSF function/category and CIS safeguards.
Day 3 - Regulations
Quick reference:
| Reg | Who must comply | What it covers | | ----------- | ------------------------------------------------- | ----------------------- | | HIPAA | US healthcare entities + business associates | PHI | | PCI DSS | Anyone handling cardholder data | Payment data | | SOC 2 | Service orgs (often SaaS) | Trust services criteria | | FERPA | US educational institutions | Student records | | GLBA | US financial institutions | Customer financial info | | GDPR | Anyone processing EU residents' personal data | Personal data, broad | | CCPA / CPRA | Businesses with CA consumer data above thresholds | Personal data, narrower | | FedRAMP | Cloud services for US federal agencies | Government data | | CMMC | DoD contractors | CUI |
Matching exercise: 12 scenarios → identify which regulation(s) apply and one key control each requires.
Day 4 - Policy critique
Provide a deliberately weak password policy (vague, no lockout, no rotation guidance, no enforcement, no exceptions process). Students:
- List 5 weaknesses.
- Rewrite into a 1-page policy.
- Add 1-page accompanying procedure (the actual how).
Differentiation, IEP, and 504 supports
- Math anxiety: Qualitative 5×5 grid is sufficient; quantitative SLE/ARO/ALE can be a worked example they annotate.
- Reading: Regulation table can be used open-note on Day 3.
- Writing: Day 4 policy rewrite can be a marked-up existing policy plus a half-page procedure.
- Adult overlay: Swap "school" for "this organization" in homework and scenarios.
Common misconceptions
- "Compliance = security." - Compliance is a floor. Security is a ceiling. Aim higher than the floor.
- "More controls = lower risk." - Wrong controls ≠ lower risk. Controls have to map to actual threats.
- "GDPR is just for Europe." - If you have any users in the EU, it likely applies to you.
- "GRC is not real cyber." - GRC decides budget, scope, and whether the technical work is allowed. That is the job that hires the rest of the team.
Assessment
Risk register rubric (1–4): threat vs vulnerability distinguished, treatment named, owner assigned, residual risk not identical to inherent without a reason.
- Day 1 risk register (10 rows, scored).
- Day 2 mapping exercise (5 risks → CSF function + CIS safeguard).
- Day 3 matching exercise.
- Day 4 rewritten policy + procedure.
Career connection
GRC is the path most often overlooked by learners who think cyber equals exploitation. It is also the path that sits in the room when leadership decides what gets funded.
Homework
Read the NIST CSF 2.0 introduction. Identify three Govern function categories that did not exist in CSF 1.1 and write 1 paragraph on why they were added. Use the fictional Northlake incident as your example, not a real employer.