The Tech Academy

GUIDED BY THE NIST CYBERSECURITY FRAMEWORK (CSF) 2.0

Governance, Risk, and Compliance (GRC) Portfolio Studio

Build an Organization's Information Security Management System

A mentoring program from The Tech Academy

GRC is the work of deciding how an organization protects its information, managing its risks, and showing it meets its commitments.

Build practical GRC work you can show, and learn to explain every decision.

You design a proposed security program for a fictional company, step by step. You leave with one portfolio, including a program charter, a risk register, a vendor risk assessment, a tailored policy, and audit evidence, that you can use to demonstrate your skills in interviews.

For people entering GRC, people handling GRC tasks at work, and people preparing for advisory work.

Suggested pace: 5–6 weeks, 2 to 3 hours a week, or go at your own pace and finish early. Founding price: $497, or 2 payments of $249 (total $498). Step 0 is free.

What we heard

I surveyed the people who joined my live GRC masterclass. Seven in ten were career changers, and about half had not started yet. Many told me the same thing: they needed practical work they could show and explain.

"I want to be able to defend what I have learnt and actually do the job."
"Something real which can make employers interview me."

Why I built the Studio

A few years ago, I referred a well-qualified career changer for an interview. Afterward, the hiring manager told me she clearly had the education, but she struggled to show that she could actually do the work and explain her decisions. That call led me to design learning around realistic cases, the portfolio pieces professionals produce, and reasoning you can defend.

You can build evidence of your skills through realistic work you can explain and defend.

The Studio

What you build

One portfolio for TechFlow Solutions, a fictional company that serves healthcare and financial services clients and has no formal security program yet. Each step adds one portfolio piece, and the work moves through four stages:

  • Set up the security program: who leads security, what the program covers, and where the company falls short today.
  • Assess and treat risk: build a risk register, assess a vendor, and choose the safeguards that address the top risks.
  • Put safeguards into practice: write clear policies and plan how the company puts its safeguards in place.
  • Check the work and report to leadership: gather evidence, answer customer security questions, and brief leadership.

An information security management system (ISMS) is the set of people, rules, safeguards, and checks an organization uses to protect its information: who decides, what could go wrong, which safeguards are used, how they are checked, and how leaders stay informed.

Your portfolio is a proposed design for a fictional company. Present it as a case-based project.

How it works

Every step follows the same three parts.

  • Learn It. Short videos explain the ideas and show them on TechFlow.
  • Build and Defend It. You complete that step's portfolio piece and write a short defense of one key decision.
  • Use It for Your Career. You practise explaining your work, as you would to an employer or a client.

Each step also has an optional short podcast on how that work is being carried out in organizations now, so you have something to say about it in interviews and with clients.

What guides the work

  • The NIST Cybersecurity Framework (CSF) 2.0. You use its six functions, Govern, Identify, Protect, Detect, Respond, and Recover, to organize TechFlow's security work, from leadership and risk to controls, evidence, and review.
  • ISO/IEC 27001 and SOC 2. You get a plain description of how ISMS certification and SOC 2 reports work, so you can speak about them accurately with employers, clients, and auditors.
  • The organization's own requirements. Every decision also answers to TechFlow's goals, client commitments, contracts, and policies.
  • The limits of your role. You assess and recommend. Leadership decides, and legal and technical questions go to specialists.

Two ways to use your portfolio

  • A job inside a company. Use your portfolio pieces in interviews to show how you assess risk, choose controls, and prepare for audits.
  • Advisory work. Use the same method to help organizations build or improve their ISMS, once you have the experience to offer it as a service.

What makes it different

Complete all the work in every step, and you earn more than a portfolio:

  • A Certificate of Achievement from The Tech Academy, when your complete portfolio passes the Completion Check by Dr. Shumba
  • A reference letter from Dr. Shumba, your mentor, on request once you have completed all the work, describing what you built
  • A foundation for ISO/IEC 27001 Foundation. The Studio covers the ideas the standard is built on, and we encourage every learner to take ISO/IEC 27001 Foundation training and sit the exam through a training provider. When you pass the exam, you receive the provider's ISO/IEC 27001 Foundation certificate and digital badge.

Who it is for

  • Entering GRC: recent graduates and career changers who want a non-coding role and practical work to show.
  • Handling GRC tasks at work: people in IT, security, audit, or compliance who are taking on risk registers, audits, or security questionnaires.
  • Preparing for advisory work: people who want to start their own services, helping organizations build their ISMS.

What you get

  • The TechFlow case file and video lessons for every step
  • An optional short podcast for every step on how the work is used in organizations now
  • One portfolio template, in Word, with a part for every step
  • Practice interview questions with explanations, two plain-English reference guides (NIST CSF 2.0, and certification and SOC 2), and a word list
  • Individual feedback on your portfolio during your first 90 days
  • Office hours with Dr. Shumba on the 2nd and 4th Saturday of each month during your first 90 days, for members only
  • 12 months of access to all lessons and materials

Founding price: $497, or 2 payments of $249 (total $498). On a payment plan, Steps 1 to 5 open with your first payment, and Steps 6 to 11 open after your second payment.

Try Step 0 free

Try the real work before you pay. In Step 0, you watch a short welcome and three videos, read the TechFlow case file, and produce your first portfolio piece: a short page recommending a framework for TechFlow.

Start Step 0 free and find out if this work is for you.

Your mentor

Dr. Rose Shumba has over 20 years in cybersecurity education. She is a former director of an NSA/DHS Center of Academic Excellence in Cyber Defense. Her PECB credentials as an ISO/IEC 42001 Lead Implementer and an ISO/IEC 27001 Senior Lead Implementer are for the work she does with organizations: setting up the policies, roles, risk checks, and oversight they need to use AI responsibly, and building the systems that protect their information. She has helped hundreds of professionals move into technology and cybersecurity careers. Read Dr. Shumba's full bio.

Building and defending realistic portfolio pieces is a practical way to turn GRC and AI governance knowledge into evidence you can explain to employers and clients.

Details and questions

After you buy:

You have access right away and can get started. We also send you a Calendly link to book Dr. Shumba's office hours.

Pace:

Self-paced. Suggested pace: 5–6 weeks at 2 to 3 hours a week, or go at your own pace and finish early.

Access and support:

12 months of access. Mentor support and portfolio feedback run for 90 days from your enrollment date, whatever pace you study at.

Feedback:

Submit each portfolio piece when you finish it and receive written feedback: what worked, what needs attention, and one question to take further.

Enrollment:

Open year-round.

Payment plans:

Steps 1 to 5 open with your first payment. Steps 6 to 11 open after your second payment.

Refunds:

This is a digital product, and access opens as soon as you buy. All sales are final, so please try the free Step 0 first to see whether the work suits you.

Do I need a technical background?

Coding is not required. Step 0 explains the terms in plain English.

What do I need?

A computer, Microsoft Word or a program that opens Word files, a Google account for your working folder, and 2 to 3 hours a week.

Is TechFlow a real company?

TechFlow is fictional. Describe your portfolio as a case-based project.

Does the Studio certify me in NIST CSF or ISO/IEC 27001?

The Studio awards The Tech Academy's Certificate of Achievement. NIST does not certify individuals, and this certificate is not issued or endorsed by NIST, ISO, or IEC. Individual ISO/IEC 27001 credentials come from training providers, and the Studio prepares you for ISO/IEC 27001 Foundation training and its exam.

How is this different from your AI governance programs?

The GRC Portfolio Studio designs an organization's program for protecting its information. The AI governance programs focus on how an organization decides, assesses, and oversees its use of AI. You can take either one first.

Where do I get help?

Office hours on the 2nd and 4th Saturday of each month and individual portfolio feedback during your first 90 days, and email at [email protected]. Office hours are for members only; you book them through the Calendly link sent after you buy.

Build it. Defend it. Use it.

Build practical GRC work you can show, and learn to explain every decision.

Suggested pace: 5–6 weeks, or go at your own pace and finish early. Founding price: $497, or 2 payments. Step 0 is free.

Start Step 0 free and find out if this work is for you.

Iron sharpens iron, Dr. Rose Shumba

© 2026 The Tech Academy. All rights reserved. Terms of Service | Privacy Policy