Certified Authorisation Professional (CAP) Certification and Training

Nivå: Foundation
Snittbetyg: 4,4/5 4,38/5 Based on 80 Reviews

This official (ISC)² Certified Authorisation Professional (CAP) course prepares you for the CAP exam and provides in-depth coverage of the Risk Management Framework. It is the only security certification under the DoD8570 Mandate that aligns to each of the RMF steps. You will learn the skills and concepts in the 7 domains including RMF, Security Categorization, Security Controls implementation, assessment, monitoring and authorisation.

The Risk Management Framework (RMF) is used by security professionals who are responsible for assessing risk and establishing documentation for their IT systems. Achieve this CAP certification and demonstrate your expertise in lifecycle cyber security risk management.


  • Official (ISC)² curriculum
  • After-course instructor coaching benefit

Du kommer lära dig att:

  • Prepare for and pass the CAP Exam
  • Define and implement a Risk Management Framework (RMF)
  • Select, tailor and document security controls
  • Prepare for security control assessment
  • Perform ongoing security control assessments

Välj den utbildningsform som passar dig bäst


I klass & Live, Online-utbildning

  • 5-day instructor-led training course
  • One-on-one after course instructor coaching
  • Pay later by invoice -OR- at the time of checkout by credit card
  • Exam Voucher Included 



  • Använd denna eller någon annan utbildning i ditt företag
  • Fullskalig programutveckling
  • Levereras när, var och hur du vill
  • Blandade utbildningsmodeller
  • Skräddarsytt innehåll
  • Coaching av ett expertteam

Anpassa kurs och innehåll efter teamets behov

Kontakta oss

Utveckla dig och ditt team med anpassade eller öppna kurser alternativt e-learning

Learning Tree erbjuder kundanpassad utbildning hos er, öppna kurser i Stockholm, London eller Washington, möjlighet att delta via våra Anywhere centers (Malmö, Göteborg, Linköping, Stockholm eller Borlänge) eller olika former av e-learning med lärarstöd. Läs mer på www.learningtree.se/priser .

I klass & Live, Online-utbildning

Note: This course runs for 5 dagar *

*Events with the Partial Day Event clock icon run longer than normal but provide the convenience of half-day sessions.

  • 4 - 8 jan 9:00 - 4:30 EST Online (AnyWare) Online (AnyWare) Boka Din Kursplats

  • 8 - 12 feb 9:00 - 4:30 EST Herndon, VA / Online (AnyWare) Herndon, VA / Online (AnyWare) Boka Din Kursplats

  • 21 - 25 jun 9:00 - 4:30 EDT Alexandria, VA / Online (AnyWare) Alexandria, VA / Online (AnyWare) Boka Din Kursplats

  • 9 - 13 aug 9:00 - 4:30 EDT Herndon, VA / Online (AnyWare) Herndon, VA / Online (AnyWare) Boka Din Kursplats

Kurs med startgaranti

När du ser symbolen för “Guaranteed to Run” vid ett kurstillfälle vet du att kursen blir av. Garanterat.

Partial Day Event

Learning Tree offers a flexible schedule program. If you cannot attend full day sessions, this option consists of four-hour sessions per day instead of the full-day session.

Important CAP Certification Course Information

  • Who Should Attend

    The CAP is ideal for IT, information security and information assurance practitioners and contractors who use the RMF in:

    • The U.S. federal government, such as the U.S. Department of State or the Department of Defence (DoD)
    • The military
    • Civilian roles, such as federal contractors
    • Local governments
    • Private sector organisations
  • Certification Information

    To qualify for the CAP certification, you must have:

    • A minimum of two years cumulative, paid, full-time work experience
    • In one or more of the seven domains of the CAP Common Body of Knowledge (CBK)

    To maintain certification, you must:

    • Earn and post a minimum of 20 (ISC)2 CPE credits per year
    • Comply with (ISC)2's Code of Professional Ethics
  • Earn (ISC)2 CPEs

    As one of only 12 (ISC)2 CPE Submitters worldwide, Learning Tree can submit courses on your behalf to (ISC)2 for CPE credit. (ISC)2 members can earn Group A credits for attending any of our cybersecurity courses, and Group B General Education credits for any other Learning Tree course they attend.

    Or (ISC)2 members can submit CPE credits directly to the CPE portal in the Members section of the (ISC)2 website.

CAP Certification Course Outline

  • Risk Management Framework (RMF)

    • Describe the RMF
    • Describe and distinguish between the RMF steps
    • Identify roles and define responsibilities
    • Understand and describe how the RMF process relates to the organisational structure
    • Understand the relationship between the RMF and System Development Life Cycle (SDLC)
    • Understand legal, regulatory and other security requirements
  • Categorization of Information Systems

    • Categorise the system
    • Describe the information system (including the security authorisation boundaries)
    • Register the system
  • Selection of Security Controls

    • Identify and document (inheritable) controls
    • Select, tailor and document security controls
    • Develop security control monitoring strategy
    • Review and approve security plan
  • Security Control Implementation

    • Implement selected security controls
    • Document security control implementation
  • Security Control Assessment

    • Prepare for security control assessment
    • Develop security control assessment plan
    • Assess security control effectiveness
    • Develop initial security assessment report (SAR)
    • Review interim SAR and perform initial remediation actions
    • Develop final SAR and optional addendum
  • Information System Authorisation

    • Develop plan of action and milestones (POAM) (e.g., resources, schedule, requirements)
    • Assemble security authorisation package
    • Determine risk
    • Determine the acceptability of risk
    • Obtain security authorisation decision
  • Monitoring of Security Controls

    • Determine security impact of changes to system and environment
    • Perform ongoing security control assessments (e.g., continuous monitoring, internal and external assessments)
    • Conduct ongoing remediation actions (resulting from incidents, vulnerability scans, audits, vendor updates, etc.)
    • Update key documentation (e.g., SP, SAR, POAM)
    • Perform periodic security status reporting
    • Perform ongoing risk determination and acceptance
    • Decommission and remove system


CAP Certification Training FAQs

  • What is the Certified Authorisation Professional (CAP) Certification?

    The Certified Authorisation Professional certification covers the RMF in great detail and is the only security certification under the DoD8570 Mandate that aligns to each of the RMF steps. /p>

  • How do I take the CAP Certification exam?

    A minimum of two years cumulative, paid, full-time work experience and in one or more of the seven domains of the CAP Common Body of Knowledge (CBK)

  • Can I become an (ISC)² Certified Authorisation Professional online?

    Yes! We know your busy work schedule may prevent you from getting to one of our classrooms which is why we offer convenient online training to meet your needs wherever you want. This course is available in class, online, and on demand.

Questions about which training is right for you?

call 08-506 668 00

100% Satisfaction Guaranteed

Your Training Comes with a 100% Satisfaction Guarantee!*

*Partner-delivered courses may have different terms that apply. Ask for details.

Online (AnyWare)
Herndon, VA / Online (AnyWare)
Alexandria, VA / Online (AnyWare)
Herndon, VA / Online (AnyWare)
Hur föredrar du att bli kontaktad:

Please Choose a Language

Canada - English

Canada - Français