<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Self Study or Enroll in ISC2 Course? in CGRC Study Group</title>
    <link>https://community.isc2.org/t5/CGRC-Study-Group/Self-Study-or-Enroll-in-ISC2-Course/m-p/67273#M114</link>
    <description>&lt;P&gt;Thank you very much, appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I searched on internet and the earliest edition for ISC2 CAP, I am finding is from 2012 - apparently that is too old, can you please suggest any site where I can buy the latest edition, thank you very much!&lt;/P&gt;</description>
    <pubDate>Wed, 14 Feb 2024 21:15:24 GMT</pubDate>
    <dc:creator>sharmagds</dc:creator>
    <dc:date>2024-02-14T21:15:24Z</dc:date>
    <item>
      <title>Self Study or Enroll in ISC2 Course?</title>
      <link>https://community.isc2.org/t5/CGRC-Study-Group/Self-Study-or-Enroll-in-ISC2-Course/m-p/65306#M92</link>
      <description>&lt;P&gt;Hi there&lt;BR /&gt;&lt;BR /&gt;I am an ISC2 Instructor, an adjunct Professor in cybersecurity and I received my CGRC certificate last year.&lt;BR /&gt;Many of my students ask me if they should enroll in an ISC2 course or study on their own.&lt;BR /&gt;&lt;BR /&gt;I always answer that it is a trick question and the answer is both! You should enroll in a good ISC2 course and study on your own.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Here are some thumb rules about certification that I got from my mentors, mentees and other students&lt;BR /&gt;&lt;BR /&gt;1. This is a technical certification. Make sure that you have 2-3 years of experience in Governance/Risk/Compliance before you start working on this certification. You will get much more if you have the experience. While there an option to get this certificate with OUT the required work experience, most students got more from preparation for this exam because they could learn at work&lt;BR /&gt;&lt;BR /&gt;2.&amp;nbsp; If you like a structured approach - use the self learning modules by ISC2, it is very interactive and it gives a great overview&lt;BR /&gt;&lt;BR /&gt;3. If you like interacting with your instructor, with your classmates and would like your training to be spread over 8 weeks, I recommend the 8 week instructor led courses. You get access to the course material for 6 months.&lt;BR /&gt;&lt;BR /&gt;4. If you are prepared well, enroll in the 5 day workshop as a great review before you go for the exam.&lt;BR /&gt;&lt;BR /&gt;5. The bottom line is that you have to read the standards and be very familiar with them. Start with this standard.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NIST SP 800-37 Rev 2, Guide for Applying the Risk Management Framework to Federal Information Systems&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;Many of my students and I benefited from the Free flashcards that ISC2 makes available.&lt;BR /&gt;&lt;BR /&gt;Check out the graphics and links below.&lt;BR /&gt;&lt;BR /&gt;Dr K&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;&lt;FONT face="arial, sans-serif"&gt;Sudesh Kannan, CISSP, CGRC PhD&lt;BR /&gt;&lt;SPAN&gt;Cyber Security&amp;nbsp;&amp;nbsp;Professional&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://www.linkedin.com/in/sudeshkannan/" target="_blank" rel="nofollow noopener noreferrer"&gt;&lt;FONT face="arial, sans-serif"&gt;https://www.linkedin.com/in/sudeshkannan/&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Self-Study Resources can be found here:&amp;nbsp;&lt;A href="https://www.isc2.org/Training/Self-Study-Resources" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.isc2.org/Training/Self-Study-Resources&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a link to the Online Instructor Led Course as well:&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;A href="https://enroll.isc2.org/catalog?pagename=cgrc-training" target="_blank" rel="nofollow noopener noreferrer"&gt;https://enroll.isc2.org/catalog?pagename=cgrc-training&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://csrc.nist.gov/projects/risk-management/about-rmf" target="_blank" rel="noopener"&gt;https://csrc.nist.gov/projects/risk-management/about-rmf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DrK_0-1702395585326.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/7985i81B46909442F4810/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DrK_0-1702395585326.png" alt="DrK_0-1702395585326.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NIST SP 800-18 - development of system security plans&amp;nbsp;&lt;/P&gt;&lt;P&gt;NIST SP 800-30 - supports the development of system and organizational risk assessments&amp;nbsp;&lt;/P&gt;&lt;P&gt;NIST SP 800-30 Rev 1, Guide for Conducting Risk Assessments&lt;/P&gt;&lt;P&gt;SP 800-171 Rev. 2&lt;/P&gt;&lt;P&gt;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&lt;/P&gt;&lt;P&gt;800-53 and 800-171 provide actual security controls&lt;/P&gt;&lt;P&gt;NIST SP 800-53A Rev 4 (Rev 5 when released), Assessing Security and Privacy Controls in Federal Information Systems and Organizations*&lt;/P&gt;&lt;P&gt;NIST SP 800-53 Rev 5, Security and Privacy Controls for Federal Systems and Organizations*&lt;/P&gt;&lt;P&gt;NIST SP 800-53B, Control Baselines for Information Systems and Organizations&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NIST SP 800-37 Rev 2, Guide for Applying the Risk Management Framework to Federal Information Systems&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;NIST SP 800-39, Organizational Wide Risk Management&lt;/P&gt;&lt;P&gt;NIST SP 800-160, Volume I, Systems Security Engineering&lt;/P&gt;&lt;P&gt;FIPS 200 addresses the specification of minimum security requirements for federal information and information systems.&lt;/P&gt;&lt;P&gt;FIPS 199 addresses the classification divides systems. It divides the systems into high, moderate, and low impact systems based on their impact on individuals and organizations.&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 13:20:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CGRC-Study-Group/Self-Study-or-Enroll-in-ISC2-Course/m-p/65306#M92</guid>
      <dc:creator>DrK</dc:creator>
      <dc:date>2024-05-16T13:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: Self Study or Enroll in ISC2 Course?</title>
      <link>https://community.isc2.org/t5/CGRC-Study-Group/Self-Study-or-Enroll-in-ISC2-Course/m-p/65950#M94</link>
      <description>&lt;P&gt;Hello, thank you for your response in advance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am already certified CISSP but somehow think like I should go for CGRC certification also, and have been into IT Audit and security field since 2010.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My questions are: I want to self-study, then register for the exam and pass - where do I register for the exam?&amp;nbsp; Given my over 10 years experience, do you think I will have any issues in getting CGRC certified?&amp;nbsp; Any relevant info I will appreciate, thank you very much, regards Ganesh Sharma&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 23:27:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CGRC-Study-Group/Self-Study-or-Enroll-in-ISC2-Course/m-p/65950#M94</guid>
      <dc:creator>sharmagds</dc:creator>
      <dc:date>2024-01-03T23:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Self Study or Enroll in ISC2 Course?</title>
      <link>https://community.isc2.org/t5/CGRC-Study-Group/Self-Study-or-Enroll-in-ISC2-Course/m-p/65980#M95</link>
      <description>&lt;P&gt;Given all of your experience in GRC, you probably won't have any problems passing the test. The original post has a list of the various NIST documents you need to be familiar with. This aligns with the comments I have read on other sites.&lt;BR /&gt;&lt;BR /&gt;You can always look for the most recent edition of a CAP (the old name of the CGRC) book on Amazon if you want something more structured.&amp;nbsp; Also, look on Udemdy or similar site - there might be a related course.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I wish they would release a self study online training course. I personally don't need an instructor led class to be successful.&amp;nbsp; I have been in cybersecurity for 25 years and have many certifications including the CISSP and CCSP.&amp;nbsp; I am just looking to round out my ISC2 certification set.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 17:49:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CGRC-Study-Group/Self-Study-or-Enroll-in-ISC2-Course/m-p/65980#M95</guid>
      <dc:creator>AntiEvil</dc:creator>
      <dc:date>2024-01-04T17:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Self Study or Enroll in ISC2 Course?</title>
      <link>https://community.isc2.org/t5/CGRC-Study-Group/Self-Study-or-Enroll-in-ISC2-Course/m-p/67011#M112</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm also looking for a self-paced training for CGRC. &amp;nbsp;You mentioned this, "&lt;SPAN&gt;2.&amp;nbsp; If you like a structured approach - use the self learning modules by ISC2, it is very interactive and it gives a great overview" in your post. &amp;nbsp;Where are the ISC2 self learning modules? &amp;nbsp;I've seen a list of references and the flash cards and a list of instructor-led training. But I can't find the self learning modules for CGRC. &amp;nbsp;Can you link that, please? &amp;nbsp;Thanks in advance.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 23:18:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CGRC-Study-Group/Self-Study-or-Enroll-in-ISC2-Course/m-p/67011#M112</guid>
      <dc:creator>tkruthoff</dc:creator>
      <dc:date>2024-02-07T23:18:24Z</dc:date>
    </item>
    <item>
      <title>Re: Self Study or Enroll in ISC2 Course?</title>
      <link>https://community.isc2.org/t5/CGRC-Study-Group/Self-Study-or-Enroll-in-ISC2-Course/m-p/67273#M114</link>
      <description>&lt;P&gt;Thank you very much, appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I searched on internet and the earliest edition for ISC2 CAP, I am finding is from 2012 - apparently that is too old, can you please suggest any site where I can buy the latest edition, thank you very much!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 21:15:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CGRC-Study-Group/Self-Study-or-Enroll-in-ISC2-Course/m-p/67273#M114</guid>
      <dc:creator>sharmagds</dc:creator>
      <dc:date>2024-02-14T21:15:24Z</dc:date>
    </item>
  </channel>
</rss>

