22-Day GRC Mastery Program
“Five hiring-critical frameworks. One focused hour a day. Taught from the CISO chair.”
A practitioner-led live bootcamp covering GRC, ISO 27001, PCI DSS, ITGC and DPDPA. You leave with working templates, hands-on practice and the judgment to build, audit or break into compliance, plus free access to the Srida IT practice-lab portal.
Program Highlights
The 22-Day Curriculum
Five modules, mapped across 22 focused sessions, from foundations to the frameworks the industry hires for.
GRC Foundations
Focus: Governance, Risk and Compliance
- The GRC landscape, ecosystem and key roles
- Risk management: threats, likelihood, impact and treatment
- Frameworks map: NIST CSF, ISO, SOC 2, COBIT, COSO
- Controls, the audit lifecycle and building evidence
ISO/IEC 27001
Focus: Information Security Management System
- ISMS fundamentals and the ISO 27000 family
- Clauses 4-10: context, leadership, planning, operation
- All 93 Annex A controls across the four themes
- Internal audit, management review and improvement
PCI DSS
Focus: Payment Card Industry Data Security Standard
- Card ecosystem, cardholder data and scoping
- The 12 requirements in depth
- Segmentation strategy and SAQ selection
- v4.0 changes, validation, RoC, SAQ and AoC
ITGC
Focus: IT General Controls and Audit Readiness
- ITGC in SOX, SOC 1 and SOC 2 audits
- Access management and segregation of duties
- Change management and IT operations controls
- Design vs operating-effectiveness testing and evidence
DPDPA
Focus: Digital Personal Data Protection Act, 2023
- Key definitions, scope and applicability
- Consent, notice and the rights of Data Principals
- Obligations, safeguards and Significant Data Fiduciaries
- Building a compliance program and capstone project
How the Program Works for You
Same 22 days, three destinations, whether you are building a compliance program, auditing one, or breaking into the field.
Stand up real programs, with a toolkit in hand
- A ready-to-use toolkit ships with every module
- Build an ISMS, scope a PCI assessment or run a DPDPA readiness
- Learn control design, evidence and the sequencing that gets programs live
Test controls with confidence across frameworks
- Design vs operating-effectiveness testing, sampling and evidence
- Write clean findings and evaluate deficiencies
- Map one control set across ISO, PCI, ITGC and DPDPA
Get hired and interview-ready in GRC
- Master the exact frameworks that job descriptions ask for
- A capstone readiness project for your portfolio and resume
- Guidance on GRC roles, resume framing and mock interviews
A Toolkit With Every Module
Leave with the working documents, not just notes.
Risk register and assessment template, control catalogue
ISMS policy pack, Statement of Applicability, internal-audit checklist
Scoping and segmentation worksheet, SAQ selector, evidence tracker
Access / change / ops control matrix, test scripts, sampling sheet
Data inventory (RoPA), notice and consent templates, gap-assessment tool
Srida IT Portal Self-Learning Access
Enrolled learners unlock the full library of hands-on practice modules, with real-world scenarios, quizzes and certificates.
Risk Assessment
9 chapters, ISO 27005, NIST 800-30
GRC Enterprise Simulation
8 real-world orgs, 5 phases each
Compliance Audit Essentials
ISO 27001, SOC 2, audit planning
Incident Response & Handling
NIST CSF, SANS IR, playbooks
Mock Interview
AI-powered, 8 GRC roles
DPDPA Certificate Course
DPDP Act 2023 and Rules
The Practicals
How every session stays hands-on.
Program Format
Frameworks Covered
Reserve Your Seat for the 3 August Cohort
Seats are limited to keep the cohort interactive. Register to confirm your batch and receive joining details, or hop into the WhatsApp group first.