GUIDED BY THE NIST CYBERSECURITY FRAMEWORK (CSF) 2.0
Governance, Risk, and Compliance (GRC) Portfolio Studio
Build an Organization's Information Security Management System
A mentoring program from The Tech Academy
Build a security program for a fictional company and leave with twelve GRC portfolio pieces you can show and defend in interviews or advisory work.
Founding member price until October 7: $497, or 2 payments of $275 (total $550). Step 0 is free.
What we heard
I surveyed 53 people who registered for my GRC masterclass in August 2026. Seven in ten were career changers, and about half had not started yet. Many told me the same thing: they needed practical work they could show and explain.
"I want to be able to defend what I have learnt and actually do the job."
"Something real which can make employers interview me."
Why I built the Studio
A few years ago, I referred a well-qualified career changer for an interview. Afterward, the hiring manager told me she clearly had the education, but she struggled to show that she could actually do the work and explain her decisions. That call led me to design learning around realistic cases, the portfolio pieces professionals produce, and reasoning you can defend.
You can build evidence of your skills through realistic work you can explain and defend.
The work
What you build
One portfolio for TechFlow Solutions, a fictional company that serves healthcare and financial services clients and has no formal security program yet.
The Studio has twelve steps: a free Step 0, then Steps 1 to 11. Every step produces one portfolio piece, so the full portfolio has twelve pieces. The steps fall into four areas, and here are some of the pieces you build in each:
- Set up the security program: a program charter and a current-state gap assessment.
- Assess and treat risk: a risk register and a vendor risk assessment.
- Put safeguards into practice: a tailored policy set and a control implementation plan.
- Check the work and report to leadership: an audit-readiness package built on simulated evidence, and a leadership review brief.
An information security management system (ISMS) is the people, rules, safeguards, and checks an organization uses to protect its information.
The method
How it works
Every step follows the same three parts.
- Learn It. Short videos explain the ideas and show them on TechFlow.
- Build and Defend It. You complete that step's portfolio piece and write a short defense of one key decision.
- Use It Professionally. You practice explaining your work, as you would to an employer or a client.
Each step also has an optional short podcast on how that work is being carried out in organizations now, so you have something to say about it in interviews and with clients.
The foundations
What guides the work
- The NIST Cybersecurity Framework (CSF) 2.0. You use its six functions, Govern, Identify, Protect, Detect, Respond, and Recover, to organize TechFlow's security work, from leadership and risk to controls, evidence, and review.
- ISO/IEC 27001 and SOC 2. You get a plain description of how ISMS certification and SOC 2 reports work, so you can speak about them accurately with employers, clients, and auditors.
- The organization's own requirements. Every decision also answers to TechFlow's goals, client commitments, contracts, and policies.
- The limits of your role. You assess and recommend. Leadership decides, and legal and technical questions go to specialists.
Two ways to use it
- A job inside a company. Use your portfolio pieces in interviews to show how you assess risk, choose controls, and prepare for audits.
- Advisory work. Use the same method to help organizations build or improve their ISMS, once you have the experience to offer it as a service.
Completion & recognition
What you finish with
Complete all the work in every step, and you finish with:
- A Certificate of Achievement from The Tech Academy, when your complete portfolio passes the Completion Check.
- A reference letter from Dr. Shumba, your mentor, on request once you have completed all the work, describing your completed training project and the skills you demonstrated.
- Twelve portfolio pieces you can show, one for each step, to use in interviews or in advisory work.
- The Studio builds practical skills in GRC. These skills provide a foundation for further study toward an ISO/IEC 27001 Foundation qualification. You can then pursue Foundation training and an exam through a separate provider, subject to that provider’s requirements. External training and exam fees are not included in the Studio.
Is it for you?
Who it is for
- Entering GRC: recent graduates and career changers who want a non-coding role and practical work to show.
- Handling GRC tasks at work: people in IT, security, audit, or compliance who are taking on risk registers, audits, or security questionnaires.
- Preparing for advisory work: people who want to start their own services, helping organizations build their ISMS.
Inside the program
What you get
- The TechFlow case file and video lessons for every step
- An optional short podcast for every step on how the work is used in organizations now
- One portfolio template, in Word, with a section for each of the twelve steps
- Practice questions with explanations, two plain-English reference guides (NIST CSF 2.0, and certification and SOC 2), and a word list
- Written feedback on each portfolio piece within 5 business days, during your first 90 days
- Live group office hours with Dr. Shumba on the 2nd and 4th Saturday of each month during your first 90 days, for members only
- 6 months of access to all lessons and materials
Pace and enrollment
Self-paced. Plan on about 24 hours in all: around 6 to 8 weeks at 3 to 4 hours a week.
Founding member price: $497, or 2 monthly payments of $275 (total $550), plus applicable sales tax. Paying in full opens every step at once. On a payment plan, Steps 1 to 5 open with your first payment, and Steps 6 to 11 open after your second payment. Your second payment is charged one month after the first. Step 0 is also available free.
Join by Wednesday, October 7 to receive the founding member price and attend the live kickoff on Saturday, October 10 at 9:00 a.m. Eastern. You can begin the self-paced lessons as soon as you enroll.
Enrollment stays open after October 7, so you can also join whenever you are ready.
What learners say
Experiences from Dr. Shumba's previous training and mentoring programs.
"I finished an MS in Cybersecurity and still had nothing to show for it. I took Dr. Shumba's GRC portfolio program, then her resume and LinkedIn workshop. We built real pieces of work. I did not see how much that mattered until the calls started coming. I have had six interviews in the last two weeks, and I feel ready for anything now."
Maccus, M
"I was a plumber, and the Security+ material overwhelmed me. Dr. Shumba mentored me all the way to the exam, and I passed. I got a job as a SOC analyst, then was laid off when AI changed the team. I went back to her, and now I am a GRC analyst. I love what I do."
Gloria, C
Start here
Try Step 0 free
Try the real work before you pay. In Step 0, you watch a short welcome and three videos, read the TechFlow case file, and produce your first portfolio piece: a short page recommending a framework for TechFlow.
Start Step 0 free and find out if this work is for you.
Your mentor
Dr. Rose Shumba is a PECB Certified ISO/IEC 27001 Senior Lead Implementer who helps organizations build the systems that protect their information. She has over 20 years in cybersecurity education, is a former director of an NSA/DHS Center of Academic Excellence in Cyber Defense, and has helped hundreds of professionals move into technology and cybersecurity careers. Read Dr. Shumba's full bio.
Details and questions
After you buy:
You have access right away and can get started. If you join by October 7, we send you the link to the live virtual kickoff on Saturday, October 10 at 9:00 a.m. Eastern. Everyone receives a Calendly link to book Dr. Shumba's office hours.
Pace:
Self-paced, so your speed decides. Plan on about two hours for each step, including the videos, your portfolio piece, and revisions, so about 24 hours in all. At 3 to 4 hours a week, that is about 6 to 8 weeks.
Access and support:
6 months of access. Mentor support and portfolio feedback run for 90 days from your enrollment date, whatever pace you study at.
Feedback:
Submit each portfolio piece when you finish it. You receive one round of written feedback on each piece within 5 business days: what worked, what needs attention, and one question to take further.
Office hours:
Live online group sessions with Dr. Shumba on the 2nd and 4th Saturday of each month during your first 90 days. Book your place through the Calendly link sent after you buy.
Enrollment:
Join by Wednesday, October 7 to receive the founding member price and attend the live kickoff on Saturday, October 10 at 9:00 a.m. Eastern. You can begin the self-paced lessons as soon as you enroll. Enrollment stays open after October 7, so you can also join whenever you are ready.
Payment plans:
Steps 1 to 5 open with your first payment. Steps 6 to 11 open after your second payment. Paying in full opens every step at once. The plan is 2 monthly payments of $275 (total $550), plus applicable sales tax. Your second payment is charged one month after the first. Step 0 is also available free.
Refunds:
This is a digital product, and access opens as soon as you buy. All sales are final, so please try the free Step 0 first to see whether the work suits you.
What is GRC?
GRC stands for governance, risk, and compliance: deciding how an organization protects its information, working out what could go wrong, and showing that the organization keeps the promises it has made.
Do I need a technical background?
No coding is required for this program. Step 0 explains the terms in plain English.
What do I need?
A computer, Microsoft Word or a program that opens Word files, a Google account for your working folder, and 3 to 4 hours a week.
Is TechFlow a real company?
TechFlow is fictional. Describe your portfolio as a case-based project.
Does the Studio certify me in NIST CSF or ISO/IEC 27001?
The Studio awards The Tech Academy's Certificate of Achievement. NIST does not certify individuals, and this certificate is not issued or endorsed by NIST, ISO, or IEC.
What about ISO/IEC 27001 Foundation?
The Studio builds a practical foundation in the ideas ISO/IEC 27001 is built on. Foundation training and its exam are offered by training providers, and their fees are separate from the Studio. When you pass the exam, you receive the provider's certificate and digital badge. We encourage every learner to take this next step.
How is this different from your AI governance programs?
The GRC Portfolio Studio designs an organization's program for protecting its information. The AI governance programs focus on how an organization decides, assesses, and oversees its use of AI. You can take either one first.
Where do I get help?
Office hours and portfolio feedback during your first 90 days, and email at [email protected]. Office hours are for members only.
Your next step
Build it. Defend it. Use it.
Build practical GRC work you can show, and learn to explain every decision.
Join by Wednesday, October 7 for the founding member price, $497 or 2 payments of $275, and the live kickoff on Saturday, October 10 at 9:00 a.m. Eastern. Step 0 is free.
Start Step 0 freeStart Step 0 free and find out if this work is for you.
Iron sharpens iron, Dr. Rose Shumba