22-Day GRC Mastery Program
“Five hiring-critical frameworks. One focused hour a day. Taught from the CISO chair.”
A practitioner-led live bootcamp covering GRC, ISO 27001, PCI DSS, ITGC, DPDPA and, new for this cohort, AI Governance. You leave with working templates, hands-on practice and the judgment to build, audit or break into compliance, plus free access to all 14 practice modules on the Srida IT portal.
Attend the free 2-Day Demo before you enrol
Two live sessions with Rajendra Bodda, at the same 8 AM IST slot as the main cohort — so you know exactly what to expect.
- Day 1:
- Friday, 5 September 2026 · 8:00 AM IST
- Day 2:
- Saturday, 6 September 2026 · 8:00 AM IST
- Meeting ID:
- 857 9698 3291
- Passcode:
- 531116
Program Highlights
The 22-Day Curriculum
Five core modules mapped across 22 focused sessions, plus an AI Governance thread that runs through all of them, from foundations to the frameworks the industry hires for.
GRC Foundations
Focus: Governance, Risk and Compliance
- The GRC landscape, ecosystem and key roles
- Risk management: threats, likelihood, impact and treatment
- Frameworks map: NIST CSF, ISO, SOC 2, COBIT, COSO
- Controls, the audit lifecycle and building evidence
ISO/IEC 27001
Focus: Information Security Management System
- ISMS fundamentals and the ISO 27000 family
- Clauses 4-10: context, leadership, planning, operation
- All 93 Annex A controls across the four themes
- Internal audit, management review and improvement
PCI DSS
Focus: Payment Card Industry Data Security Standard
- Card ecosystem, cardholder data and scoping
- The 12 requirements in depth
- Segmentation strategy and SAQ selection
- v4.0 changes, validation, RoC, SAQ and AoC
ITGC
Focus: IT General Controls and Audit Readiness
- ITGC in SOX, SOC 1 and SOC 2 audits
- Access management and segregation of duties
- Change management and IT operations controls
- Design vs operating-effectiveness testing and evidence
DPDPA
Focus: Digital Personal Data Protection Act, 2023
- Key definitions, scope and applicability
- Consent, notice and the rights of Data Principals
- Obligations, safeguards and Significant Data Fiduciaries
- Building a compliance program and capstone project
AI Governance
Focus: ISO/IEC 42001 and the NIST AI Risk Management Framework
- ISO/IEC 42001 AI management system and how it sits beside your ISMS
- AI risk assessment: model inventory, bias, drift and explainability
- DPDPA and AI: lawful basis, notice and automated decision-making
- Governing AI use in controls, vendor reviews and audit evidence
How the Program Works for You
Same 22 days, three destinations, whether you are building a compliance program, auditing one, or breaking into the field.
Stand up real programs, with a toolkit in hand
- A ready-to-use toolkit ships with every module
- Build an ISMS, scope a PCI assessment or run a DPDPA readiness
- Learn control design, evidence and the sequencing that gets programs live
Test controls with confidence across frameworks
- Design vs operating-effectiveness testing, sampling and evidence
- Write clean findings and evaluate deficiencies
- Map one control set across ISO, PCI, ITGC and DPDPA
Get hired and interview-ready in GRC
- Master the exact frameworks that job descriptions ask for
- A capstone readiness project for your portfolio and resume
- Guidance on GRC roles, resume framing and mock interviews
A Toolkit With Every Module
Leave with the working documents, not just notes.
Risk register and assessment template, control catalogue
ISMS policy pack, Statement of Applicability, internal-audit checklist
Scoping and segmentation worksheet, SAQ selector, evidence tracker
Access / change / ops control matrix, test scripts, sampling sheet
Data inventory (RoPA), notice and consent templates, gap-assessment tool
AI model inventory, AI risk assessment sheet, ISO 42001 readiness checklist
Srida IT Portal Self-Learning Access
Enrolled learners unlock all 14 hands-on practice modules, with real-world scenarios, quizzes and certificates, including the three-level DPDPA certification path.
22-Day GRC Practical Simulation
22 days, 22 deliverables, AI-reviewed, one Board-level capstone
ISO 27001:2022 Practitioner Track
Clauses 4-10, all 93 Annex A controls, internal audit
PCI DSS v4.0 Practitioner Track
CDE scoping, the 12 requirements, segmentation, SAQ selection
ITGC + SOC 2 Type II Track
All 4 ITGC domains, testing methodology, SOC 2 readiness
Cybersecurity Audit Fundamentals
Free 5-chapter foundation, NIST / ISO / COBIT
Risk Assessment
9 chapters, ISO 27005, NIST 800-30, risk register
GRC Enterprise Simulation
8 real-world orgs, 5 phases each
Compliance Audit Essentials
ISO 27001, SOC 2, audit planning
Incident Response & Handling
NIST CSF, SANS IR, playbooks
Mock Interview
AI-powered evaluation across 8 GRC roles
DPDPA Certificate Course
DPDP Act 2023 and DPDP Rules, 6 modules
CDFP — DPDPA Foundation (L1)
8 modules, certificate at 70%
CDIP — DPDPA Implementation (L2)
12 modules, 8 hands-on labs, certificate at 75%
CDPO-India — DPO (L3)
14 modules plus capstone: GDPR, ISO 27701, AI governance
The Practicals
How every session stays hands-on.
Program Format
Frameworks Covered
Enrolment Is Open — ₹9,500
Cohort starts 7 September 2026 at 8 AM IST. Free 2-Day GRC Demo on 5 & 6 September (same time) — attend live before deciding. Seats are limited to keep the cohort interactive. Enrol and pay securely by UPI, or join the WhatsApp group for any questions first.