<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Introduction &amp;amp; Seeking Guidance on GRC Career Path in CC Study Group</title>
    <link>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78423#M3527</link>
    <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1590936133"&gt;@emb021&lt;/a&gt;&amp;nbsp; &amp;nbsp;I think that ISC2's CGRC is also a good certification and possibly their ISSEP which feel follows it better than the CISSP.&amp;nbsp; I hold both of those as well as a CISM and ISSMP which believe all complement each other other on frameworks and governance..&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Apr 2025 19:17:30 GMT</pubDate>
    <dc:creator>nkeaton</dc:creator>
    <dc:date>2025-04-01T19:17:30Z</dc:date>
    <item>
      <title>Introduction &amp; Seeking Guidance on GRC Career Path</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78394#M3517</link>
      <description>&lt;P class=""&gt;Hello Folks,&lt;/P&gt;&lt;P class=""&gt;I’m thrilled to join this community and eager to learn from professionals in the cybersecurity and GRC space.&lt;/P&gt;&lt;P class=""&gt;I’m currently halfway through the ISC2 Certified in Cybersecurity (CC) Foundation program and preparing to book my exam soon. Since this program is freely offered, I wanted to hear your thoughts on its relevance to a GRC career:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;With the CC certification, would I be well-positioned to start as a GRC analyst, or are there additional certifications, skills, or experience I should focus on?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;What are the best entry paths into GRC, especially for someone looking to break into the field?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Are there any valuable resources, mentorship opportunities, or industry trends I should pay close attention to?&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;I’d appreciate any insights or advice you can share, and I look forward to engaging with and learning from this community.&lt;/P&gt;&lt;P class=""&gt;Best regards,&lt;BR /&gt;Murray Lichoro&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 17:23:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78394#M3517</guid>
      <dc:creator>MurrayLichoro</dc:creator>
      <dc:date>2025-03-31T17:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Introduction &amp; Seeking Guidance on GRC Career Path</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78397#M3518</link>
      <description>I would study up on regulations for a career in GRC.&lt;BR /&gt;&lt;BR /&gt;I would try to narrow down the industry you’d like to work in.&lt;BR /&gt;&lt;BR /&gt;Then, become well-rounded.&lt;BR /&gt;&lt;BR /&gt;Read up on regulations for that industry: for example, Banking has SOX and healthcare has HIPAA.&lt;BR /&gt;&lt;BR /&gt;Read up on GDPR of the EU.&lt;BR /&gt;&lt;BR /&gt;Then, read up on a few state privacy laws to familiarize yourself with that. California is one you’d want to learn about.&lt;BR /&gt;&lt;BR /&gt;The CC is very much only foundational knowledge.&lt;BR /&gt;&lt;BR /&gt;If you have the time, learn the CISSP curriculum. You won’t earn the certification without the work requirements, but you will have a broad exposure to topics.&lt;BR /&gt;&lt;BR /&gt;You really cannot earn the certifications for GRC until you’ve worked in the field: ISACA has certifications, ISC2 has one, and for privacy certifications look into IAPP.&lt;BR /&gt;&lt;BR /&gt;Learn about the cloud too. There is the cloud security alliance with free documents you can download and read.&lt;BR /&gt;&lt;BR /&gt;Learn the content of certifications you are interested in.&lt;BR /&gt;&lt;BR /&gt;Forget about not being able to earn the certifications for the moment.&lt;BR /&gt;&lt;BR /&gt;And post about what you are learning and doing.&lt;BR /&gt;&lt;BR /&gt;That’s my advice.&lt;BR /&gt;</description>
      <pubDate>Mon, 31 Mar 2025 19:11:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78397#M3518</guid>
      <dc:creator>Spirnia</dc:creator>
      <dc:date>2025-03-31T19:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: Introduction &amp; Seeking Guidance on GRC Career Path</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78409#M3520</link>
      <description>Hello Spirnia,&lt;BR /&gt;I hope you're doing well! I wanted to reach out personally to thank you again for the valuable advice you shared in the community. It's been really helpful as I continue my journey into the GRC space.&lt;BR /&gt;I’m based in Kenya, Africa, and I’m looking for ways to connect with professionals in the industry, especially those who can provide guidance and share insights based on their experience. If you’re open to it, I would love to network with you and perhaps receive some additional guidance as I navigate my career path in GRC.&lt;BR /&gt;Would you be open to offering mentorship or providing advice along the way? I’d appreciate any help you could offer as I work towards my goals.&lt;BR /&gt;Thank you!&lt;BR /&gt;</description>
      <pubDate>Tue, 01 Apr 2025 09:44:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78409#M3520</guid>
      <dc:creator>MurrayLichoro</dc:creator>
      <dc:date>2025-04-01T09:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: Introduction &amp; Seeking Guidance on GRC Career Path</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78413#M3523</link>
      <description>&lt;P&gt;I would be happy to answer questions posted to this forum to the best of my knowlege.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not go off platform.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not aware of regulations and laws in Kenya.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISC2 does have a chapter in Kenya. You may want to participate in that:&amp;nbsp;&lt;A href="https://community.isc2.org/t5/Europe-Middle-East-Africa/ct-p/EMEAChapterGroups" target="_blank"&gt;https://community.isc2.org/t5/Europe-Middle-East-Africa/ct-p/EMEAChapterGroups&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your best bet would be to do online research and learn local information in addition to major Europe, Asia, and US regulations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I would recommend starting out in a small organization. Large organizations may not be as suitable for someone switching careers and starting out in GRC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could create a YouTube channel and make short videos about what you are learning and your aspirations. Post links to your videos on LinkedIn, and attract an audience, and build followers. Become a thought leader so that you stand out in your community.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 12:25:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78413#M3523</guid>
      <dc:creator>Spirnia</dc:creator>
      <dc:date>2025-04-01T12:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: Introduction &amp; Seeking Guidance on GRC Career Path</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78421#M3526</link>
      <description>&lt;P&gt;Take a look at what&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/411576483"&gt;@Spirnia&lt;/a&gt;&amp;nbsp;has posted.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Most of the people I know of who are involved in GRC are involved with ISACA which is an international organization with chapters around the world. In fact, ISACA has a GRC Conference.&amp;nbsp; And it has a chapter in Kenya.&lt;BR /&gt;&lt;BR /&gt;People in this space get certs like CISA, CRISC, and CGEIT.&amp;nbsp; If you are involved with infosec, having complementary certs like Sec+, CC, and CISSP is good.&lt;BR /&gt;&lt;BR /&gt;They learn about regulations for security and privacy, which varies from country to country, and learn about international security frameworks like ISO/IEC 27001, NIST CSF, CIS Critical Controls, and the like.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 18:42:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78421#M3526</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2025-04-01T18:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Introduction &amp; Seeking Guidance on GRC Career Path</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78423#M3527</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1590936133"&gt;@emb021&lt;/a&gt;&amp;nbsp; &amp;nbsp;I think that ISC2's CGRC is also a good certification and possibly their ISSEP which feel follows it better than the CISSP.&amp;nbsp; I hold both of those as well as a CISM and ISSMP which believe all complement each other other on frameworks and governance..&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 19:17:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78423#M3527</guid>
      <dc:creator>nkeaton</dc:creator>
      <dc:date>2025-04-01T19:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: Introduction &amp; Seeking Guidance on GRC Career Path</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78435#M3528</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_0037.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9581i44913A606F0B6BA3/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMG_0037.jpeg" alt="IMG_0037.jpeg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_0038.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9579iB418C36494E35D22/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMG_0038.jpeg" alt="IMG_0038.jpeg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_0039.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9580iEC21675007DFCEA8/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMG_0039.jpeg" alt="IMG_0039.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Those interested in GRC may find this webpage of interest to them:&amp;nbsp;&lt;A href="https://sprinto.com/blog/grc-cybersecurity-career-roadmap/" target="_blank" rel="noopener"&gt;https://sprinto.com/blog/grc-cybersecurity-career-roadmap/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The images are from the linked article.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;AI would be good to learn too as it pertains to GRC auditing roles.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 23:24:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78435#M3528</guid>
      <dc:creator>Spirnia</dc:creator>
      <dc:date>2025-04-01T23:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Introduction &amp; Seeking Guidance on GRC Career Path</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78452#M3537</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/253792811"&gt;@nkeaton&lt;/a&gt;&amp;nbsp;I would disagree on CGRC as AFAIK ISC2 has not made any changes to it from the prior NIST RMF-focused CAP certification.&amp;nbsp; Until they rework it to cover more frameworks such as CIS Controls, ISO 27001, NIST CSF etc, I personally wouldn't recommend it.&amp;nbsp; Honestly, I think SANS/GIAC's GCCC would be better as it DOES cover multiple frameworks.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 19:34:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78452#M3537</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2025-04-03T19:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Introduction &amp; Seeking Guidance on GRC Career Path</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78454#M3538</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/411576483"&gt;@Spirnia&lt;/a&gt;&amp;nbsp;Good set of info.&amp;nbsp; HOWEVER, I have some problems with the last picture with the frameworks.&amp;nbsp; "NIST" is NOT a framework, but a government institute.&amp;nbsp; It provides SEVERAL frameworks including the NIST CSF, NIST RMF, NIST SP800-171 which is the basis for CMMC, and the NIST Privacy Framework.&amp;nbsp; So I have no idea which framework this chart is talking about.&amp;nbsp; Its either the NIST CSF or the RMF.&amp;nbsp; Am guessing probably the CSF as too many people refer to the NIST CSF as just NIST.&lt;BR /&gt;&lt;BR /&gt;AND GDPR and HIPAA are NOT frameworks but regulations.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 20:14:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78454#M3538</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2025-04-02T20:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Introduction &amp; Seeking Guidance on GRC Career Path</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78455#M3539</link>
      <description>&lt;P&gt;Well-stated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I completely agree!&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 20:18:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78455#M3539</guid>
      <dc:creator>Spirnia</dc:creator>
      <dc:date>2025-04-02T20:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Introduction &amp; Seeking Guidance on GRC Career Path</title>
      <link>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78466#M3542</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1590936133"&gt;@emb021&lt;/a&gt;&amp;nbsp; I had to look that up.&amp;nbsp; I thought was a technical acronym that didn't know.&amp;nbsp; Way to bring me back to reality.&amp;nbsp; ISC2 has been including more frameworks and started before the name change.&amp;nbsp; I can agree that it was pretty NIST focused and maybe still is.&amp;nbsp; I do feel like the CISM covers frameworks and GRC better.&amp;nbsp; I definitely do not want to see another certification done away with.&amp;nbsp; I am sure that you understand with a HCISPP.&amp;nbsp; I was thinking about working towards earning it when the obituary came out.&amp;nbsp; The CAP has a funny history though.&amp;nbsp; I took the exam in 2012 right after a major exam objectives change.&amp;nbsp; It was more focused on DIACAP before that and was Certification and Accreditation Professional.&amp;nbsp; When I took the exam, it was focused on RMF and NIST and changed to Certified Authorization Professional.&amp;nbsp; Of course now it is CGRC.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 14:40:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CC-Study-Group/Introduction-amp-Seeking-Guidance-on-GRC-Career-Path/m-p/78466#M3542</guid>
      <dc:creator>nkeaton</dc:creator>
      <dc:date>2025-04-03T14:40:26Z</dc:date>
    </item>
  </channel>
</rss>

