Courses titled as the job.
Every course ends in an artefact you keep, and teaches the same obligation in two realities: early-stage and SME, and enterprise. Frameworks are the source of the obligation, never the subject of the course.
63 courses across 11 domains. Jump to one:
Concepts you hear but never learned
Sixteen ten-minute lessons, free to every member. 0.25 ALC each, 4 ALCs toward the Foundations Certificate.
Open the series to read every term in full.
Bridge letter
A bridge letter, sometimes called a gap letter, is a short statement from a service organization covering the period between the end of its most recent SOC report and the…
CUEC
Complementary user entity controls are the controls a SOC report assumes you, the customer, operate. Every service organization's control objectives depend on some things…
Subservice organisation and carve-out
A subservice organization is a vendor of your vendor whose controls matter to the service you receive: the cloud provider the software runs on, the data centre, the…
Global Privacy Control (GPC)
Global Privacy Control is a browser signal. When it is switched on, the browser sends a header and exposes a flag on every request saying that the user opts out of the…
TCF and consent strings
The Transparency and Consent Framework is an industry standard, maintained by the IAB in Europe, for passing a user's consent choices through the advertising supply…
SBOM and VEX
A software bill of materials is a parts list for software: every component, library and dependency in a build, with versions, expressed in a machine-readable format such…
Statement of Applicability
The Statement of Applicability is the ISO 27001 document that lists every control in the standard's Annex A, states whether each applies to your organization, gives the…
ITGC
IT general controls are the controls over the technology environment that financial and other application controls depend on. Auditors group them into four areas…
Legitimate interest and the balancing test
Legitimate interests is one of the six lawful bases for processing personal data under GDPR. It allows processing that is necessary for a genuine interest of the…
Article 28 processor terms
Article 28 of GDPR sets the mandatory terms of any contract between a controller and a processor. The contract has to bind the processor to act only on the controller's…
Business associate agreement
A business associate agreement is the contract that HIPAA requires between a covered entity, such as a healthcare provider or health plan, and any organization that…
Risk acceptance and expiry
Risk acceptance is a decision by someone with the authority to make it that a known risk will not be treated further for now. It is a legitimate outcome of risk…
Type I versus Type II
A SOC 2 Type I report describes a service organization's controls and gives an auditor's opinion on whether they are suitably designed at a single point in time. A Type…
Data processing agreement versus data protection addendum
Both are abbreviated DPA, and both deal with how a vendor handles personal data, which is why they are confused. A data processing agreement is a standalone contract, or…
Suppression list
A suppression list is the set of contacts an organization must not market to: people who unsubscribed, objected, opted out of sale, asked by phone not to be called, or…
Population and sample
When an auditor tests a control, they start by defining the population: the complete set of instances in which the control should have operated during the period. Every…
Digital Trust Foundations
What Digital Trust Means in Your Job
A personal responsibility map: every trust obligation your role touches, who owns it, and what evidence proves it.
Ethics and Judgement Calls for Practitioners
A decision log template and worked calls on six real dilemmas (pressure to sign an attestation, discovered over-collection, a vendor hiding an incident).
Reading a Regulation Without a Lawyer
An obligation register built from one regulation: article to obligation to owner to evidence.
Privacy & Data Protection
GDPR in Practice: From Articles to an Operating Program
A 12-month privacy program plan with lawful-basis decisions, DPO determination, Article 30 approach and processor terms.
US State Privacy Laws in Practice: CCPA/CPRA and the Rest
An applicability matrix by state and a single opt-out handling standard covering Do Not Sell/Share, GPC signals and sensitive data limits.
HIPAA in Practice for HealthTech and Business Associates
A BA obligations checklist, a BAA review guide and a minimum-necessary standard for product teams.
Data Subject Rights Operations: GDPR, CCPA and HIPAA Access
A DSAR runbook: intake, identity verification, datastore search, vendor sub-requests, exemptions, SLA clock, response pack and evidence file.
Building a Record of Processing and Data Inventory That Survives Audit
A completed RoPA and datastore catalog, with the method for keeping it current after the project ends.
Consent and Cookie Management Platforms in Practice
A configured CMP design: tag categorisation, TCF and GPC handling, banner logic by jurisdiction, scan cadence and a cookie policy that matches the site.
Privacy in Marketing: Consent, Lists and Campaign Compliance
A marketing consent standard and a list-scrub procedure: opt-in cleansing, suppression against opt-outs and Do Not Sell, consent expiry, purchased and event lists, B2B versus B2C rules across GDPR, PECR, CAN-SPAM and TCPA.
DPIA and PIA: Running One That Changes a Decision
A completed DPIA on a realistic case with mitigations that were actually adopted, plus a screening trigger list.
Breach Notification Decisions Under Pressure
A breach decision tree across GDPR 72-hour, HIPAA and US state timelines, risk-of-harm tests, and notification templates for regulators, individuals and customers.
Retention and Deletion That Actually Deletes
A retention schedule, legal-hold procedure and a deletion evidence standard covering backups and SaaS.
International Transfers: SCCs, Transfer Assessments and the DPF
A transfer register with mechanism per flow and a completed transfer impact assessment.
Data Governance
Data Classification and Handling Rules People Follow
A three-level classification scheme, handling matrix and labelling approach that maps to your DLP and sharing settings.
Data Mapping and Discovery: Connectors, Owners and Drift
A discovery plan and ownership model for keeping the inventory accurate as systems change.
Secure Data Sharing: Data Rooms, Remanence and What People Miss
A data sharing decision record: what is shared, with whom, by which channel, for how long, how it ends, and what remains afterwards.
Governance, Risk & Compliance
SOC 2 From the Inside: Scoping, Ownership, Evidence and the Auditor
A scoped engagement plan: TSC selection, control ownership across control, evidence and task, an evidence calendar, and a walkthrough guide.
ISO 27001 Implementation, Not Interpretation
A Statement of Applicability, risk treatment plan and internal audit plan ready for Stage 1.
Control Mapping and Evidence Reuse Across SOC 2, ISO, NIST CSF and HITRUST
A crosswalk for your control set, with deliberate empty cells documented, and an evidence-reuse register.
Policies People Read: Writing, Versioning, Acknowledgement and Training Binding
A policy set with version control, acknowledgement records bound to versions, and the training that satisfies each policy.
Evidence Management and Audit Readiness
An audit packet: populations, sample selection, walkthrough notes, evidence index and a gap list with remediation tasks.
Internal Controls and SOX for Practitioners
A quarterly attestation cycle: ITGC scope, control owner certification, deficiency register with severity, and the quarter-close report.
PCI DSS in Practice: Scoping, SAQs and Compensating Controls
A cardholder data environment scope diagram, SAQ selection rationale and a compensating control worksheet.
HITRUST for HealthTech: Self-Assessment to Validated
A HITRUST readiness plan with control inheritance from cloud providers and a self-assessment approach.
Running a Security Awareness Program Auditors Accept
A training plan mapped to framework controls, completion evidence design and role-specific modules.
Risk Management
Risk Assessment as a Craft: Scoping, Scenarios and Judgement
A scenario-based assessment for one business process: threat, asset, consequence and the assumptions you made, written to be challenged.
Quantifying Risk: From Heat Maps to Money
A quantified estimate for one scenario: frequency and magnitude ranges, the calibration behind them, and the decision the number supports.
Treatment, Acceptance and Exceptions That Expire
A treatment plan and an exception register where every acceptance names an accountable executive, a compensating control and an expiry date.
Risk Appetite, KRIs and the Board Conversation
Appetite statements tied to measurable indicators, thresholds that trigger action, and a one-page risk view for the board.
Audit & Assurance Operations
Owning a Control: Accountability, Delegation and Follow-Through
A control ownership pack: one accountable owner per control, named performers for each task, a status roll-up your leadership can read, and the escalation path when a task slips.
Populations, Completeness and Sampling
A population definition per control with the completeness argument written down, a sample selection method, and the sampling worksheet you hand the auditor.
Evidence That Holds: Collection, Freshness and Reuse
An evidence calendar with owners and cadence, a naming and retention convention, and an evidence index mapped to controls across two frameworks.
Automated Audit Tests and Continuous Control Monitoring
A test catalogue: what each automated test asserts, its data source, failure handling, and the manual procedure it replaces or supplements.
Working With Auditors: Walkthroughs, Questions and Findings
A walkthrough script per control, an auditor question log with agreed answers and owners, and a findings response template with remediation dates.
Framework Scope as a Guardrail, Not a Burden
A scope decision record: what is in, what is deliberately out, the justification for each exclusion, and the trigger that would bring it back in.
Control Maturity and Status Reporting
A maturity model your organization can defend, control-level status definitions, and the quarterly report that shows movement rather than colour.
Cybersecurity & Threat
Software Supply Chain: SBOMs, VEX and Component Monitoring in Practice
An SBOM programme: generation, ingestion, CVE matching, VEX handling, staleness rules and vendor SBOM requests.
Threat Intelligence for Risk Decisions
A procedure for turning breach and vulnerability intelligence into risk register changes and vendor actions.
Vulnerability Management Governance: SLAs, Exceptions and Evidence
Remediation SLAs by severity, an exception process with expiry and the evidence auditors ask for.
Incident and Breach Readiness: Tabletop to Regulator
An incident runbook, a decision log template, communication templates and a tabletop exercise kit.
Access Reviews That Pass Audit
A user access review procedure with populations, reviewer evidence and revocation proof.
Cyber Insurance Applications and Attestations
An evidence-backed answer set to a standard cyber insurance application and a control gap list.
Third-Party & Supply Chain Risk
Building a Third-Party Risk Program: From Zero and At Scale
A TPRM operating model: tiering criteria, inherent risk questionnaire, assessment depth by tier, and an annual cycle.
Reading a SOC 2 Report: Opinion, Scope, Exceptions, CUECs and Subservice Organisations
A SOC report review memo template and a completed review of a real report: what the opinion covers, what it carves out, which exceptions matter to you.
Handling CUECs: Turning Complementary User Entity Controls Into Your Own Obligations
A CUEC register: every complementary control from your critical vendors, mapped to an internal control, an owner and evidence.
Vendor Due Diligence Questionnaires: SIG, CAIQ, Custom and Scoring
A tiered questionnaire set with partial-credit scoring, evidence requests and a review procedure.
Contracting for Risk: DPAs, BAAs, Security Schedules and Right to Audit
A contract clause playbook and a negotiation position sheet by vendor tier.
Continuous Vendor Monitoring: Breach Intelligence, Attestation Expiry and Recertification
A monitoring standard: what triggers a reassessment, expiry ladders for SOC reports and DPAs, and an offboarding checklist.
Fourth-Party and Concentration Risk
A subprocessor map and a concentration analysis for your critical services.
Answering Customer Security Questionnaires: The Other Side of the Table
A questionnaire answer library, a trust center content plan and an evidence-reuse approach for buyer diligence.
Regulated Outsourcing: DORA, OCC and FCA Registers in Practice
A material outsourcing register, exit plan template and regulator-ready reporting for ICT third parties.
AI Governance
AI Inventory and Use-Case Intake in Practice
An AI use-case inventory with owners, data classes, risk tiers and an intake form product teams will complete.
AI Risk and Impact Assessment: NIST AI RMF and EU AI Act Tiers Applied
A completed AI impact assessment and a tiering decision under the EU AI Act.
Third-Party AI and Model Vendor Governance
AI vendor due diligence questions, DPA and training-data clauses, and an approval workflow.
AI Acceptable Use and Policy That Engineers Follow
An AI acceptable-use policy, approval tiers and monitoring approach.
Trust & Assurance
Building and Running a Trust Center
A trust center content architecture: public claims, gated evidence, subprocessor list, and an update cadence tied to your control evidence.
Program Attestations and Certificates of Diligence for Buyers, Insurers and Regulators
A program attestation pack: what you can claim, what evidence backs it, and how it stays current.
M&A Cyber Diligence: Buy Side and Sell Side
A diligence request list, a scoring approach and an inherited-risk register for post-close.
Practitioner Methods
A Risk Register Executives Use
A risk register with inherent and residual scoring, risk appetite statements, acceptance expiry, and KRIs that trigger action.
Findings That Get Fixed: Task, Remediation and Evidence Management
A remediation workflow where every finding has an owner, a deadline and completion evidence.
Digital Trust Metrics and Board Reporting
A one-page board report and the metric definitions behind it.
Capstone: Build a 90-Day Trust Program for a Real Organisation
A complete 90-day program plan, obligation register, control set, vendor tiering, privacy operations design and board report for a chosen SME or enterprise case.