BRISTLEBACK INFORMATION SECURITY GOVERNANCE BBISG · ADVANCED PROGRAM

Learn to govern security.
Manage risk. Prove compliance.

Build practical governance, risk and compliance capability through risk management, ISMS implementation, control testing, audit, business resilience and GRC operations.

18Modules
4Levels
GRCPractical work
CapstoneFinal project

THE RIGHT FOUNDATION

Build the capability behind governance.

BBISG takes you from GRC fundamentals to practical information-security governance through risk assessment, ISMS implementation, controls, audit, resilience and operational reporting.

01

What you'll learn

Governance, risk management, ISO 27001 and ISMS, control frameworks, policy development, audit, compliance assessment, business continuity, third-party risk and GRC reporting.

02

Who is this for?

Aspiring GRC professionals, cybersecurity learners, IT and security administrators, auditors, compliance professionals and technically inclined learners moving into information-security governance.

03

Prerequisites

A basic understanding of information technology and cybersecurity is recommended. The program is designed to build GRC capability progressively from foundations.

THE BBISG PATH

From GRC foundations to a complete governance and assurance function.

A four-level progression covering governance, risk, ISMS, controls, audit, resilience, third-party risk and GRC operations.

LEVEL 1

GRC & Information Security Foundations

01Governance, Risk & Compliance Fundamentals12 topics+
  • What is GRC?
  • Governance vs risk vs compliance
  • Information security governance
  • IT governance
  • Cybersecurity governance
  • Business objectives and security objectives
  • Roles and responsibilities
  • Board, management and security functions
  • Three Lines Model
  • Policies, standards, procedures and guidelines
  • Security culture
  • Accountability and ownership
02Information Security Fundamentals15 topics+
  • CIA triad
  • Information assets
  • Asset ownership
  • Threats
  • Vulnerabilities
  • Risks
  • Security controls
  • Administrative controls
  • Technical controls
  • Physical controls
  • Preventive controls
  • Detective controls
  • Corrective controls
  • Defense in depth
  • Security control lifecycle
03GRC Frameworks & Standards13 topics+
  • ISO/IEC 27001
  • ISO/IEC 27002
  • ISO/IEC 27005
  • NIST Cybersecurity Framework
  • NIST Risk Management Framework
  • COBIT
  • CIS Controls
  • SOC 2
  • PCI DSS
  • GDPR
  • HIPAA
  • IT General Controls
  • Framework selection: when and why organizations use each
04Legal, Regulatory & Compliance Fundamentals11 topics+
  • Laws vs regulations vs standards
  • Regulatory requirements
  • Contractual requirements
  • Industry requirements
  • Data protection
  • Privacy fundamentals
  • Regulatory obligations
  • Compliance obligations
  • Evidence of compliance
  • Non-compliance
  • Penalties and business impact
LEVEL 2

Risk Management & ISMS

05Enterprise & Cybersecurity Risk Management15 topics+
  • Risk terminology
  • Risk appetite
  • Risk tolerance
  • Risk capacity
  • Risk criteria
  • Inherent risk
  • Residual risk
  • Risk owner
  • Risk scenario
  • Threat vs vulnerability vs risk
  • Risk identification
  • Risk analysis
  • Risk evaluation
  • Risk treatment
  • Risk acceptance
06Risk Assessment12 topics+
  • Qualitative risk assessment
  • Quantitative risk assessment
  • Likelihood
  • Impact
  • Risk scoring
  • Risk matrix
  • Risk register
  • Risk scenarios
  • Business impact
  • Risk prioritization
  • Risk assessment methodology
  • Practical risk register creation
07ISO/IEC 27001 & ISMS14 topics+
  • What is an ISMS?
  • ISO 27001 structure
  • Context of the organization
  • Interested parties
  • ISMS scope
  • Leadership
  • Information security policy
  • Roles and responsibilities
  • Risk assessment
  • Risk treatment
  • Objectives
  • Documentation
  • Performance evaluation
  • Improvement
08ISO/IEC 27001 Implementation12 topics+
  • Define context
  • Define scope
  • Identify assets
  • Perform risk assessment
  • Select controls
  • Create Statement of Applicability
  • Implement controls
  • Monitor
  • Internal audit
  • Management review
  • Corrective action
  • Certification readiness
LEVEL 3

Controls, Audit & Compliance

09ISO 27002 Security Controls11 topics+
  • Purpose of ISO 27002
  • Control selection
  • Control applicability
  • Organizational controls
  • People controls
  • Physical controls
  • Technological controls
  • Control ownership
  • Control implementation
  • Control effectiveness
  • Risk → Control → Evidence → Testing → Finding → Remediation
10Security Policies & Documentation13 topics+
  • Information Security Policy
  • Acceptable Use Policy
  • Password Policy
  • Access Control Policy
  • Asset Management Policy
  • Incident Response Policy
  • Backup Policy
  • Change Management Policy
  • Business Continuity Policy
  • Data Classification Policy
  • Vendor Security Policy
  • Remote Access Policy
  • Policy lifecycle and approval
11IT Audit Fundamentals15 topics+
  • What is an IT audit?
  • Audit objectives
  • Audit scope
  • Audit criteria
  • Risk-based audit
  • Audit planning
  • Audit program
  • Audit procedures
  • Audit evidence
  • Sampling
  • Interviews
  • Observation
  • Documentation review
  • Technical testing
  • Audit working papers
12Control Testing & Compliance Assessment13 topics+
  • Control objectives
  • Control design
  • Control implementation
  • Control effectiveness
  • Test procedures
  • Evidence collection
  • Evidence validation
  • Exceptions
  • Findings
  • Root cause
  • Risk rating
  • Corrective action
  • Mini ISO 27001 compliance assessment
LEVEL 4

Business Resilience, Third Parties & GRC Operations

13Audit Findings & Reporting12 topics+
  • Observation
  • Nonconformity
  • Finding
  • Risk
  • Root cause
  • Impact
  • Recommendation
  • Corrective action
  • Management response
  • Evidence
  • Closure
  • Professional GRC audit report
14Business Continuity & Disaster Recovery13 topics+
  • Business continuity
  • Disaster recovery
  • Business Impact Analysis
  • Critical business processes
  • RTO
  • RPO
  • Recovery strategies
  • Backup
  • Restoration
  • DR planning
  • Testing
  • Crisis management
  • Lessons learned
15Third-Party & Vendor Risk Management11 topics+
  • Vendor risk
  • Third-party risk
  • Supply-chain risk
  • Vendor assessment
  • Security questionnaires
  • Due diligence
  • Contractual security requirements
  • SLA
  • Security clauses
  • Vendor monitoring
  • Vendor offboarding
16Risk Monitoring & GRC Reporting11 topics+
  • Risk register maintenance
  • KRIs
  • KPIs
  • KCIs
  • Risk dashboards
  • Risk heatmaps
  • Compliance dashboards
  • Control status
  • Exception management
  • Risk acceptance
  • Management reporting
17GRC Tools & Practical Workflows13 topics+
  • Excel/Google Sheets
  • Document repository
  • Risk register
  • Control library
  • Compliance tracker
  • Audit tracker
  • Evidence repository
  • Corrective action tracker
  • GRC workflow concepts
  • ServiceNow GRC concepts
  • RSA Archer concepts
  • MetricStream concepts
  • OneTrust concepts
18Full GRC Capstone13 topics+
  • GRC environment setup
  • Organizational context
  • ISMS scope
  • Asset and risk register
  • Control mapping
  • Policy package
  • Evidence repository
  • Control testing
  • Audit findings
  • Corrective action plan
  • Risk and compliance dashboard
  • Management report
  • Final GRC capstone review

PRACTICAL LEARNING

Don't just learn the framework. Learn how to operate it.

Work through realistic GRC activities where you turn business context into risks, risks into controls, controls into evidence and evidence into findings, remediation and management reporting.

>_

Risk Assessment

Build a practical risk register and prioritize organizational risk.

>_

ISMS Implementation

Translate organizational context into scope, risk treatment and an actionable ISMS.

>_

Control Management

Map risks to controls and assess control design and effectiveness.

>_

Policy Development

Create practical security policies and supporting documentation.

>_

Audit & Evidence

Plan tests, collect evidence, document findings and track corrective action.

>_

GRC Reporting

Turn risk, compliance and control status into clear management reporting.

05 · PRICING

BBISG course fee.

The standard BBISG course fee is ₹33,000. Learning-mode offers are calculated automatically from the standard fee. The course fee is collected in two equal instalments.

FULL COURSE FEE

₹33,000

Standard fee for the complete BBISG programme.

Full price
ONLINE · 40% OFF

₹19,800

Save ₹13,200 · 2 equal instalments of ₹9,900

Online offer
OFFLINE · 10% OFF

₹29,700

Save ₹3,300 · 2 equal instalments of ₹14,850

Offline offer
Two equal instalments.Coming Soon · Batch allocation is confirmed before payment and course commencement.₹33,000 standard

REFUND & CANCELLATION

Four Learning Satisfaction Checkpoints. You stay in control.

The course fee for the selected learning mode is collected in two equal instalments. At 25%, 50%, 75% and 100% of syllabus coverage, you can assess whether the learning delivered so far is satisfactory. If you are not satisfied, the applicable Learning Satisfaction Checkpoint refund is available and you may exit. No certificate is issued for an unsatisfied exit.

25% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 100% of 1st instalment

Exit the programme. No certificate is issued.

50% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 50% of 1st instalment

Exit the programme. If satisfied, pay the 2nd instalment and continue.

75% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 100% of 2nd instalment

Exit the programme. No certificate is issued.

100% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 50% of 2nd instalment

Exit the programme. If satisfied, the programme is completed and a Certificate of Completion is issued.

Two instalments · four Learning Satisfaction Checkpoints.The checkpoint refund is calculated against the relevant equal instalment of the selected learning mode. See the full Refund & Cancellation Policy for complete terms and examples.

CHOOSE HOW YOU LEARN

Learn online. Learn in the classroom.

Choose the mode that fits you. Batch availability depends on learner demand and confirmed scheduling.

Teaching languages: English and Tamil.

01

Online

Live online learning with instructor-led sessions, guided GRC exercises and practical documentation work.

02

Offline

Classroom learning in Puducherry when an offline batch is confirmed.

03

Flexible

Prefer either mode? Tell us your preference during registration and we will consider you for the next suitable batch.

BATCH AVAILABILITY

Find a learning slot that works for you.

Programs will be allocated to the slot with sufficient demand. Once a batch is confirmed, its dedicated batch page will publish the confirmed schedule.

SLOT 01Awaiting allocationNo batch assigned yet
SLOT 02Awaiting allocationNo batch assigned yet
SLOT 03Awaiting allocationNo batch assigned yet
SLOT 04Awaiting allocationNo batch assigned yet

CERTIFICATION & REGISTRATION

Ready to start BBISG?

Register your interest, tell us your preferred learning mode and schedule, and we'll consider you for the next suitable batch. Payment is collected only after your batch is confirmed.

BBISG Certification

Complete the defined learning and practical requirements of the programme to receive the Bristleback Information Security Governance Certificate of Completion.

Coming Soon