Agile and State-of-the-Art Compliance Training Transforming the Future of Compliance
SecuRetain’s compliance courses drive a culture of governance and compliance throughout the organization and demonstrate conformity for all required Compliances & Frameworks.Meet regulatory compliance requirements and prove security control enforcement
Affordable compliance courses will educate employees to implement regulatory compliance requirements
Track progress and course completion for yourself or an entire enterprise with the SecuRetain Platform
Customize compliance courses to reflect your strategies, frameworks, guidelines, policies, and procedures
Use this platform to distribute your training content along with SecuRetain courses in your own private space
Corporations can save more than 15% by developing in-house skills to implement SOC, ISO, NIST, CSF, & more. The series of courses aim to enhance end to end knowledge.
Preview e-Learning Courses
Comprehensive Compliance Based e-Learning Courses
Beneficial for all organizations, irrespective of their size, industry, and geography. SecuRetain will help employees grow personally and professionally.
Learning Outcomes from Compliance Based e-Learning Courses
Transform your Cybersecurity talent pool with fundamental learning and with in-depth knowledge in PCI, FCPA, GDPR, HIPPA, HITRUST, ISO 27001, SSAE18 SOC, FFIEC, FedRAMP, NIST, and more.- Anti Money Laundering, PCI - Basics, Consequences, Penalties, Applicable Laws, Insider Trading
- GDPR – Global set of Rules and Regulations pertaining to Individual Privacy
- HIPAA & HITRUST - Introduction, Frameworks, Governance, Controls, Regulations, Penalties pertaining to Healthcare industry
- ISO 27001 - ISO 27000 compliance family, benefits of compliance, standard and certification, implementing ISMS and ISO 27001, ISMS mandatory processes, ISO 27001 Annex A controls Checklist
- FFIEC - FFIEC risk and maturity, maturity levels, how to interpret and analyze assessment results, application of principles, create rating summary, cybersecurity maturity level calculation, and maturity results based on the maturity input
- Fraud and Audit Management Series
- SOC - Learn to implement SOC by training on series of 7 courses - SOC 2 vs. SOC 1, compliance frameworks, the difference between a Type I and Type II audit, decide the type of SOC report the organization's needs, driving the audit scope, foundation of SOC 1®, SOC 2®, and SOC 3® Reports, SOC 1, SOC 2, SOC 3, SOC 2 +, SOC for Cybersecurity. and SOC for Supply Chain Reports
- SOC, NIST, ITGC – Introduction, Frameworks, Governance, Controls, Criteria, Regulations, Consequences, Penalties, Ratings
- FCPA – Key concepts, Compliances, Implications, Enforcements, Penalties
- FedRAMP – Strategy and plan, certification process, program steps to become FedRAMP compliant, Independent Verification and Validation, certification authorities, governance, and stakeholders
SecuRetain’s Compliance e-Learning Courses
Browse all Compliance category courses available for you on our SecuRetain platformAnti Money Laundering Awareness - CO00103
What you will learn:
- What it is and how does it work?
- Why people and organizations launder money?
- How money laundering works: basic process
- Legal consequences for money laundering, including state and federal (U.S.) penalties
- Applicable laws and regulation
- Insider trading
Information Security Management System (ISMS) Part I - CO00304
What you will learn:
- Understand what information and information security is
- Understand how to secure information
- Know about ISO 27000 compliance family
- Learn about ISO 27001and ISO 27002 and benefits of compliance
- Learn about ISO 27001standard and certification
- Introduction to implementing ISMS and ISO 27001
- Learn about ISMS mandatory processes and documentation
- Introduction to ISO 27001 Annex A controls Checklist
Information Security and Privacy Awareness - CS00101
What you will learn:
- Learn How to Protect Information
- Understand the Key Security Terms
- Learn about Insider Risk
- Learn about Privately Identifiable Information and Privately Healthcare Information
- Learn about Physical Security, Facility Security and Clean Desk Policies
- Learn about Social Engineering and Phishing
- Learn about Acceptable Personal Use of Corporate Property and Email
- Learn about Malicious Software and Incident Reporting
- Learn about User Id and Password Protection
- Understand Your Responsibility as a User
FedRAMP Fundamentals Part I - CO00801
What you will learn:
- Overview of FedRAMP process
- Study about FedRAMP certification process
- Understand the FedRAMP from an agency’s perspective
- Understand the FedRAMP Standard Operating Procedures
- Learn about the initial review SOP/checklists
- Learn about the detailed review checklists
- Understand the review and approve procedure
- Understand the authorization process
FedRAMP Fundamentals Part II - CO00802
What you will learn:
- Understand the FedRAMP
- Study the FedRAMP Security Assessment Framework
- Categorize
- Select
- Implement
- Assess
- Authorize
- Monitor
FedRAMP Fundamentals Part III - CO00803
What you will learn:
- Understand the FedRAMP
- Study the FedRAMP Security Assessment Framework
- Categorize
- Select
- Implement
- Assess
- Authorize
- Monitor
- Learn about NIST Special Publications history
- Understand NIST 800-53, 800-18, 800-30, 800-37, 800-70, 800-60
- Learn about implementing NIST 800-53 Special Publications
Foreign Corrupt Practices Act Awareness Part I All Employee - CO00301
What you will learn:
- Overview of the FCPA
- Study the implications of the FCPA
- Learn about the enforcement and penalties
- Study the U.S. Sentencing guidelines
- Understand the SEC and DOJ FCPA guidance
- Study the DOJ and SEC hallmarks of an effective compliance program
- Learn about the DOJ’s evaluation of compliance programs
- Learn about UK Bribery Act 2010
- Study the UK Bribery Act 2010 provisions
- Study the consequences of non-compliance with the Bribery Act 2020 – Case Study
Foreign Corrupt Practices Act Awareness Part II - CO00302
What you will learn:
- Overview of the FCPA
- Study the implications of the FCPA
- Learn about the enforcement and penalties
- Study the U.S. Sentencing guidelines
- Understand the SEC and DOJ FCPA guidance
- Study the DOJ and SEC hallmarks of an effective compliance program
- Learn about the DOJ’s evaluation of compliance programs
- Learn about UK Bribery Act 2010
- Study the UK Bribery Act 2010 provisions
- Study the consequences of non-compliance with the Bribery Act 2020 – Case Study
Foreign Corrupt Practices Act (FCPA) Part III - CO00303
What you will learn:
- Understand Fraud and Examples of Fraud
- Understand the Different Types of Fraud
- The Scale of the Problem
- Learn about Fraud Triangle Components
- Understand the Fraud Tree
- Learn about Factors Contributing to Fraudulent Behavior or Why People Commit Fraud
- Learn about Who Commits Fraud
- Knowledge of Common Fraud Schemes
- Understand Fraud Response
- Management Preventive Steps
General Data Protection Regulation (GDPR) Part I - CO00701
What you will learn:
- Understand the GDPR driving factors
- Learn about different type of PII data
- Learn about identifiable personal information
- Understand GDPR basics
- Learn about the controllers and processor
- Study GDPR principles
- Understand the six lawful bases for processing
General Data Protection Regulation (GDPR) Part II - CO00702
What you will learn:
- Learn about data Subject Rights
- Learn about Accountability and Governance principle
- Understand Privacy by Design
- Learn about the Data Protection Officer Role
- Study the privacy Codes of Conduct principle
- Understand Data Protection Impact Assessments (DPIA)
General Data Protection Regulation (GDPR) Part III - CO00703
What you will learn:
- Learn about the Data Protection Officer’s (DPO) – Appointing DPO, DPO responsibilities, etc.
- Learn how to implement GDPR security principal requirements
- Understand rules related to international transfers
- Learn about exemptions rules
- Learn about GDPR data breach communication requirements
- Understand the penalties for violation of GDPR requirements
- Study the principles applicable to use of data for law enforcement purposes
- Learn how to protect children’s data and GDPR requirements
- Study the GDPR 10 step compliance checklist
General Data Protection Regulation (GDPR) Part IV - CO00704
What you will learn:
- Understand the GDPR articles
- Learn the 10 steps compliance checklist
- Study the GDPR implementation approach
- Learn how to prepare for the project and key concepts
- Learn about data mapping
- Study the readiness assessment, gap assessment, and privacy assessment process
- Learn about data protection by design and by default a key concept
- Learn to implement data subject rights
- Understand the Data Protection Impact Assessment (DPIA) Process
- Learn to amend third-party contracts and review third party procedures
- Study the different steps to ensure the security of personal and sensitive data
- Understand how to handle data breaches
- Study the GDPR compliance audit and training requirement
Health Insurance Portability And Accountability Act (HIPAA) Awareness - CO00102
What you will learn:
- Learn about HIPAA and HITECH
- The Security Rule, The Privacy Rule, The Breach Notification Rule, Omnibus
- Chapter 181, Texas Medical Records Privacy Act
- Understand How Health Care Privacy Laws affect your organization
- Understand HIPAA IT Security Risk Assessment
- Learn about Administrative, Technical and Physical Safeguards
- Learn about Covered Entities
- Learn about Use and Disclosure of PHI
- Understand How HIPAA and HITECH are Related
- Learn about HITECH and Breach Notification
HITRUST Foundation Part I - CO00601
What you will learn:
- Understand what is HITRUST
- Learn about the HITRUST CSF components
- Learn how to calculate HITRUST scores
- Understand the steps in certification plan and plan considerations
- Understand HITRUST Implementation Planning use case and learn to implement
- Learn to calculate risk rating as per HITRUST
- Understand the corrective action plan (CAP) and documentation
- Learn how to calculate the CAP risk rating and prioritization
HITRUST Implementation Part II - CO00602
What you will learn:
- Understand what is HITRUST
- Learn about the HITRUST CSF components
- Learn how to calculate HITRUST scores
- Understand the steps in certification plan and plan considerations
- Understand HITRUST Implementation Planning use case and learn to implement
- Learn to calculate risk rating as per HITRUST
- Understand the corrective action plan (CAP) and documentation
- Learn how to calculate the CAP risk rating and prioritization
Information Security Management System (ISMS) Part II - CO00305
What you will learn:
- Understand the need for ISMS
- Learn about ISO 27001certification and ISMS Mandatory Process
- Introduction to implementing ISMS
- Learn how to implement ISO 27001 ISMS 11 Step Program
- Step by Step Guide on implementing ISMS program
- Learn the practical examples and study the documentation samples
- Learn about ISO 27001 Annex A Controls Checklist 14 Domains and 35 Control Objectives
- ISMS Part III includes implementation details for each control objective along guidance
Information Security Management System (ISMS) Part III - CO00306
What you will learn:
- Understand the need for ISMS
- Learn about ISO 27001certification and ISMS Mandatory Process
- Introduction to implementing ISMS
- Learn how to implement ISO 27001 ISMS 11 Step Program
- Step by Step Guide on implementing ISMS program
- Learn the practical examples and study the documentation samples
- Learn about ISO 27001 Annex A Controls Checklist 14 Domains and 35 Control Objectives
- ISMS Part III includes implementation details for each control objective along guidance
Incident Management Awareness Part I - CS00401
What you will learn:
- Brief about Incident and Incident Management (IM)
- Incident Management Objectives
- What is a Security Incident Management?
- Incident, Problem, and Service Request
- Incident Management Key Concepts
- Incident Management Process and ITIL
- Incident Management Process Workflow Examples
- Incident Management Process
- Incident Management Process Steps Discussed in Detail
Information Technology General Controls (ITGC) Awareness Part I - CS00701
What you will learn:
- Learn How to Protect Information
- Understand the Key Security Terms
- Learn about Insider Risk
- Learn about Privately Identifiable Information and Privately Healthcare Information
- Learn about Physical Security, Facility Security and Clean Desk Policies
- Learn about Social Engineering and Phishing
- Learn about Acceptable Personal Use of Corporate Property and Email
- Learn about Malicious Software and Incident Reporting
- Learn about User Id and Password Protection
- Understand Your Responsibility as a User
Information Technology General Controls (ITGC) COSO Framework Part II - CS00702
What you will learn:
- Understand IT Governance considerations in SOX compliance
- Understand Activity/Process Level Considerations in General Control Issues
- Learn about evaluating security administration controls
- Understand the SOX requirement for:
- Application change controls
- Data Backup and Recovery
- Systems Development Life Cycle (SDLC)
- Outsourcing Financial Applications
- Learn about the Role of Application and Data-Owner Processes
- Understand the application-level control considerations
- Understand the process level control considerations
ISO/IEC 27701 Part I - CO00901
What you will learn:
- Learn about ISO 27701 Privacy Information Management System
- Understand the fundamental concepts of ISO/IEC 27701
- Understand the ISO 27701 driving factors
- Identify the relationship between ISO/IEC 27701, ISO/IEC 27001, ISO/IEC 27002
- Learn about the ISO 27701 driving factors and need for ISO 27701
- Learn the ISO 27701 terms and definitions
- Learn about the identifiable personal information
- Learn about a different type of PII data
- Learn about controllers and processors in context of ISO 27701 and comparison with GDPR
ISO/IEC 27701 Part II - CO00902
What you will learn:
- Learn about ISO 27701 Privacy Information Management System
- Understand the fundamental concepts of ISO/IEC 27701
- Understand the ISO 27701 driving factors
- Identify the relationship between ISO/IEC 27701, ISO/IEC 27001, ISO/IEC 27002
- Learn about the ISO 27701 driving factors and need for ISO 27701
- Learn the ISO 27701 terms and definitions
- Learn about the identifiable personal information
- Learn about a different type of PII data
- Learn about controllers and processors in context of ISO 27701 and comparison with GDPR
National Institute Of Standard And Technology (NIST) Cyber Security Framework (CSF) Fundamentals Part I - CS00501
What you will learn:
- Learn about CSF fundamentals
- Learn how to establish or improve your cybersecurity program
- Understand the NIST CSF concept and how to implement with the help of case study
- Understand the practical application of CSF framework’s core, design, functions,
- categories, and subcategories
- Detailed knowledge of functions, categories, and subcategories along with
- informative references from COBIT, ISA, NIST SP 800-53, CIS CSC, ISO 27001, etc.
National Institute Of Standard And Technology (NIST) Cyber Security Framework (CSF) Fundamentals Part II - CS00502
What you will learn:
- Learn about CSF fundamentals
- Learn how to establish or improve your cybersecurity program
- Understand the NIST CSF concept and how to implement with the help of case study
- Understand the practical application of CSF framework’s core, design, functions,
- categories, and subcategories
- Detailed knowledge of functions, categories, and subcategories along with
- informative references from COBIT, ISA, NIST SP 800-53, CIS CSC, ISO 27001, etc.
Payment Card Industry Awareness - CO00201
What you will learn:
- Need for PCI DSS training
- PCI data security
- Relationship between PCI DSS and PA DSS
- PCI DSS scope
- PCI DSS requirement explained with examples
- Control costs and gain tangible, real-world insights on best practices
- Understand PCI compliance before going through an assessment
- Apply PCI DSS security principles across business
Privileged Access Management (PAM) Part I - CS00203
What you will learn:
- Privileged Access Management Overview
- Learn about privileges and how are they created, granted, etc.
- Learn about privileged accounts
- Understand the types of privileged accounts
- Study the privileged service accounts
- Learn about privilege related risks and challenges
- Learn about privileged threat vectors – external and internal
- Understand the benefits of privileged access management
- Learn how hackers compromise the privileged accounts.
- Study the privilege access management best practices
Privileged Access Management (PAM) Part II - CS00204
What you will learn:
- Learn about privileges and how are they created, granted, etc.
- Learn about the capabilities of PAM software
- Study the PAM security controls
- Learn about the PAM solution partner considerations
- Study about the PAM baseline and ongoing Improvements
- Study the considerations for selection of PAM
- Learn how to protect privileged accounts
Privileged Access Management (PAM) Part III - CS00205
What you will learn:
- Study the FCPA recent cases and takeaways
- Learn about the effective FCPA compliance program
- Study the FCPA program best practices Third Parties Review Transactions Gifts, Meals, Travel and Entertainment
- Training Due Diligence Reporting Risk Areas
- Learn about the FCPA enforcement actions and monitory resolutions
Risk Assessment Awareness Part I - RM00103
What you will learn:
- Risk Identification – Learn to identify risk
- Risk Assessment - How to assess risk?
- Risk Analysis – How to analyze risk?
- Controls – Learn to develop controls
- Risk Treatment – How to treat risk?
- Risk Management Elements – What are the risk management elements?
- Risk Monitoring – How to monitor risk?
- Risk Management Approach – Learn the process?
- Issue Management Remediation
Sarbanes Oxley Compliance (SOX) Part I - CO01101
What you will learn:
- Sarbanes-Oxley Act (SOX) basics
- SOX Sections 302, 404, and 906
- SOX Requirements, Risk and Controls, Controls Testing
- SOX and Corporate Governance
- Internal Controls
- COSO Framework and Relationship with SOX
- Components of COSO Internal Control-Integrated Framework
- COSO Framework three Dimensions
- Objectives
- Entity and activity level focus
- Internal control
- The types of Internal Controls and Technology Controls
- SOX Requirements for IT controls
Sarbanes Oxley Compliance (SOX) Part II - CO01102
What you will learn:
- Sarbanes Oxley brief from Part I
- How to approach SOX 404 audit requirements and study the end-to-end process
- The business process basics and business process lifecycle
- The importance of developing a well-defined process
- The elements of the control framework
- The control environment
- The relationship between SOX and IT controls
Security Framework Awareness - CS00108
What you will learn:
- Understand What is a Framework
- Understand What is an Information Security Framework
- Learn about Types of Security Frameworks
- Learn about Compliance Regulations and Frameworks
- Understand Factors Driving Security Frameworks
- Learn about Various Security Frameworks - ISO, COBIT, NIST, ITIL, COSO, NERC, TY, CYBER, HITRUST, CSF
- Understand the Business Benefits of Security Frameworks?
The Federal Financial Institutions Examination Council (FFIEC) Awareness Part I - CO00406
What you will learn:
- What is FFIEC?
- Learn about FFIEC Cybersecurity Priorities
- Understand FFFIEC CAT Inherent Risk Profile Assessment Categories
- Understand FFIEC Risk Levels
- Learn about Inherent Risk Categories and Ratings
- Understand in detail the FFIEC CAT Maturity Assessment Categories
- Domain 1: Cyber Risk Management and Oversight
- Domain 2: Threat Intelligence and Collaboration
- Domain 3: Cybersecurity Controls
- Domain 4: External Dependency Management
- Domain 5: Cyber Incident Management and Resilience Domains, Assessment
- Factors, Components, and Declaration
The Federal Financial Institutions Examination Council (FFIEC) Part II - CO00407
What you will learn:
- Role of internal audit in FFIEC risk and maturity
- Understand FFIEC maturity levels
- Learn on how to interpret and analyze assessment results
- Complete case study to provide in-depth understanding and application of principles
- How to calculate risk for technology and connection type
- How to create rating summary
- Learn how to create an inherent risk profile
- Understand cybersecurity maturity level calculation
- Learn to document maturity results based on the maturity input
- Learn to prepare target maturity and maturity result charts
- Learn to prepare a chart of components
- Learn to develop roles and responsibilities of the internal audit function
- Learn to evaluate the cybersecurity maturity assessment
Cybersecurity Best Practices For Startups And Small Businesses Part I - CS00901
What you will learn:
- Part I of the series “Cybersecurity Best Practices for Startups and Small Business” you will:
- Know the factors driving cybersecurity and compliance for startups and small businesses
- Study the weaknesses leading to cyberattacks
- Know what cybersecurity and compliance means to your organization
- Understand the concept of capability maturity and scale yours over a period
- Learn what cybersecurity controls mean
- Study Information Security Management System (ISMS), ISMS governance, and risk management
- Understand the cybersecurity best practices for Startups and Small Businesses and Case Studies
Cybersecurity Best Practices For Startups And Small Businesses Part II - CS00902
What you will learn:
- In Part II of the series, you will:
- Understand how insider threat knowledge is an essential component of a comprehensive security program
- Know the insider threat risk and impact and learn how to mitigate those risks
- Study the concept of physical security and how it relates to information security
- Learn how to secure offices, rooms, workplaces, and office equipment
- Understand the importance of cybersecurity training
- Know the sources of security threats and vulnerabilities and many more
Cybersecurity Best Practices For Startups And Small Businesses Part III - CS00903
What you will learn:
- In Part III of the series, you will:
- Learn about the essential considerations when computers leave the corporate security perimeter and people work remotely
- Learn that new risks arise for the company due to remote work
- Learn about the security risks are associated with Bring Your Own Devices (BYOD)
- Learn how to secure the BYOD environment
- Learn about the IT Asset Managment and Backup and Recovery industry best practices Each topic contains case studies. The case studies explain how the suggested security considerations will help protect from cyberattacks.
Cybersecurity Best Practices For Startups And Small Businesses Part IV - CS00904
What you will learn:
- Part IV will assist executives to:
- Understand the relevant contextual factors
- Decide the type of insurance policy
- Understand factors driving third-party risk management
- Understand disaster recovery plans, factors driving Disaster Recovery (DR), and DR programs implementation steps
- Learn about Advanced Persistent Threat (APT)
Code Of Conduct Part I - CC00101
What you will learn:
- Learn about the ethical principles, employees and executives should follow to reinforce professional behavior in the workplace
- Study the best practices for code of conduct
- Understand the difference between Code of Conduct vs. Code of Ethics
- Learn to create a positive working environment of equal opportunity and no retaliation
- Understand how corporations can enforce ethical behavior by using penalties for breaches of the Code of Conduct
- Learn to recognize the actions that may harm the company, such as sharing confidential company, client, and customer information
- Learn about the corporate best practices and employee responsibilities
Code Of Conduct Part II - CC00102
What you will learn:
- Learn to recognize conflict of interest and handle the conflicts
- Learn how bribes, kickbacks, payments, gifts/entertainment, and money laundering harm employers
- Learn the Foreign Corrupt Practices Act (FCPA) Accounting and Anti Bribery provisions
- Understand the ethical and legal issues involving the use of company assets by employees
- Learn about the facility and physical security perimeter and how badge and visitor’s security works
- Study the best practices for acceptable use of company information resources and social media
Occupational Safety - OS00102
What you will learn:
- Learn about CSF fundamentals
- Learn how to establish or improve your cybersecurity program
- Understand the NIST CSF concept and how to implement with the help of case study
- Understand the practical application of CSF framework’s core, design, functions,
- categories, and subcategories
- Detailed knowledge of functions, categories, and subcategories along with
- informative references from COBIT, ISA, NIST SP 800-53, CIS CSC, ISO 27001, etc.
Artificial Intelligence (AI) Machine Learning (ML) Part I
What you will learn:
- What is ML?
- What do you want the ML systems to do?
- How businesses are using ML
- Examples of ML Use Cases
- Putting ML to work
- What is The Business Value of MLOps?
- What Makes MLOps Different From DataOpsand DevOps?
- Why do we need MLOps?
- What are the key challenges that MLOps addresses
Robotic Process Automation (RPA) Part I
What you will learn:
- Learn about the RPA basics, Types of RPA tools, Types of RPA
- Understand the Pros and Cons of RPA
- Learn about RPA & Business Process Management
- Learn where to start and how to start with RPA
- WHY behind RPA
- Learn about the applications of RPA and RPA tools
- Learn to select the right RPA tool
- Understand the process for identifying RPA Opportunities and considerations for RPA
- Learn about the Challenges of RPA Implementation
- Continue to enhance knowledge about the use case
Business Process Reengineering Part I
What you will learn:
- Understand the principles of BPR
- Plan, implement and evaluate BPR in your organization
- Use BPR tools effectively
- Manage the BPR process
- Deal with typical BPR challenges
Project Management Part II
What you will learn:
- Define key project management concepts
- List the reasons why project management needed
- Explain difference between projects and operations
- Identify trends in project management environment
- List project succes and failure factors
- Identify potential benfits of project management
Project Management Part III
What you will learn:
- Define key project management concepts
- List the reasons why project management needed
- Explain difference between projects and operations
- Identify trends in project management environment
- List project succes and failure factors
- Identify potential benfits of project management
Project Management Part IV
What you will learn:
- Project Management Tools
- Agile Project Management
- Project Manager Roles
- Project Manager Responsibilities
- How to become project manager
- Project Management methodologies
Project Management Part V
What you will learn:
- Project Life Cycle Models
- Initiating Projects
- Planning Projects
- Executing Projects
- Controlling Projects
- Closing Projects
- Organizational Impacts
- Overview of Knowledge Areas
- Role of the Project Manager