Module 16: GRC, assess your own system
This module is under construction.
Governance, risk, and compliance is where most GRC training goes wrong: students write assessments of imaginary systems and learn the paperwork without the substance. You have something better. The lab you've built is a real, interconnected set of information resources under one management (yours), which is exactly what the compliance world calls a General Support System. This module designates it GSS-1 and takes it through an authorization lifecycle for real: define the system boundary, categorize it, select a scoped set of controls, assess your own implementation with evidence from your own journal, record the gaps honestly in a POA&M, and write the system security plan and authorization memo yourself.
The artifacts you leave with (an SSP and a POA&M describing a system that exists) are the portfolio pieces GRC interviews ask about, and almost nobody applying for those roles has ever produced one about infrastructure they built themselves.