100% Free Forever
AI-Powered Learning
Industry Expert Content
Certificates & Badges
Learn At Your Own Pace
Governance, Compliance & Career Readiness
20 minintermediate

Project brief — design a security program for a 200-person startup

This capstone asks you to design a complete security program for a fictional two-hundred-person SaaS startup that has grown quickly without ever formalizing governance, and now needs to satisfy enterprise customers' security questionnaires and prepare for its first SOC 2 audit within the next twelve months of active, fast-paced operation. Unlike the standalone practice exercises in earlier modules, this capstone asks you to carry one company's context across four connected deliverables, so decisions in one lesson must remain consistent with decisions made in the next.

Analogy🏏Cricket
💼 Think of it like business: GRC frameworks are the shared accounting standards of security. A company that reports earnings under a recognized standard lets investors, lenders, and regulators all read the same numbers the same way, instead of trusting a founder's hand-drawn chart. Adopting ISO 27001, SOC 2, or NIST CSF does the same for security posture, giving auditors, customers, and regulators one common language to judge maturity rather than each party inventing its own yardstick. This reveals that frameworks really sell trust: their product is a claim outsiders can verify without taking your word for it.
Lesson 31 of 35
0% complete