Skip to content
Information Technology

Certified Authorization Professional (CAP)

Through real-world applications and comprehensive training, this course prepares candidates to manage security risks, design authorization processes, and assess information system controls. Participants will develop the ability to:

Category
Information Technology
01

Overview

Practical Skills and Application

Through real-world applications and comprehensive training, this course prepares candidates to manage security risks, design authorization processes, and assess information system controls. Participants will develop the ability to:

  • Apply RMF Across System Lifecycles – Use the Risk Management Framework (RMF) throughout the information system lifecycle.
  • Identify Security and Privacy Controls – Identify, assess, and document relevant security and privacy controls.
  • Conduct Ongoing Assessments – Perform continuous assessment, auditing, and monitoring of information systems.
  • Prepare for Authority to Operate – Develop the knowledge needed to support the Authority to Operate (ATO) process.

Industry Framework Alignment

Furthermore, the training aligns with recognized industry frameworks and standards, including the National Institute of Standards and Technology (NIST) Risk Management Framework, ISO/IEC 27001, and the Federal Information Security Modernization Act (FISMA).

As a result, participants gain practical knowledge that supports effective security authorization, risk management, and compliance. The program also addresses the requirements associated with ISO/IEC 17024 compliance.

Risk Management and Compliance Foundations

Participants will develop a strong understanding of risk management principles, security frameworks, and regulatory requirements.

  • Understand Risk Management Frameworks – Explore industry frameworks including NIST, COBIT, ISO/IEC 27001, and ISO 31000.
  • Define Security Requirements – Establish Software Development Life Cycle (SDLC) requirements and align them with organizational security policies.
  • Identify Compliance Requirements – Recognize applicable regulatory requirements, including FISMA, FedRAMP, GDPR, and HIPAA.

Furthermore, participants will learn how these frameworks and requirements support effective risk management, security governance, and regulatory compliance.

Information System Categorization

Participants will learn how to categorize information systems and determine the appropriate security requirements based on system characteristics and potential impact.

  • Define System Boundaries – Identify and document information system boundaries, components, and architecture.
  • Determine Impact Levels – Assess potential impacts and classify information types according to their security requirements.
  • Align Security Categorization – Apply relevant privacy and security standards, including FIPS and ISO/IEC 27002.

Furthermore, participants will learn how accurate categorization supports effective risk management, security controls, and compliance.

Security Control Implementation and Monitoring

Participants will develop the skills needed to implement, tailor, and monitor security controls throughout the information system lifecycle.

  • Document Security Controls – Identify and document baseline and inherited security controls.
  • Apply Security Enhancements – Tailor security controls and apply appropriate enhancements based on system requirements and risks.
  • Develop Monitoring Strategies – Create continuous control monitoring strategies to identify and address security issues.
  • Review Security Plans – Evaluate and support the approval of security plans and Information Security Management System (ISMS) plans.

Furthermore, participants will learn how effective control implementation and continuous monitoring support stronger security, compliance, and risk management.

Security Control Implementation and Alignment

Participants will learn how to implement security controls effectively while aligning system configurations with recognized security standards and organizational requirements.

  • Apply Security Settings – Configure security settings in accordance with ITSG-33, NIST, and Security Technical Implementation Guides (STIGs).
  • Coordinate Inherited Controls – Work across departments to identify, manage, and document inherited security controls.
  • Implement Alternative Controls – Apply compensating or alternative controls when standard controls cannot be implemented directly.
  • Document Control Implementation – Record implementation details and ensure security designs remain aligned with identified risks.

Furthermore, participants will learn how consistent control implementation strengthens security, supports compliance, and maintains a risk-based approach to system protection.

Security Assessment and Audit

Participants will develop the skills needed to plan, conduct, and document effective security assessments and audits.

  • Prepare Audit Activities – Define the audit scope and collect relevant documentation and evidence.
  • Conduct Security Assessments – Perform assessments using approved tools, procedures, and methodologies.
  • Manage Remediation – Recommend corrective actions, conduct reassessments, and document progress.
  • Finalize Audit Reports – Prepare final audit reports and develop appropriate remediation plans.

Furthermore, participants will learn how structured assessments and timely remediation can strengthen security controls and support ongoing compliance.

System Authorization and Risk Acceptance

Participants will learn how to prepare systems for formal authorization while evaluating risks and supporting informed authorization decisions.

  • Prepare Authorization Documentation – Compile the required documentation and evidence for system authorization.
  • Evaluate System Risk – Assess system risks and evaluate available residual risk options.
  • Support Authorization Decisions – Approve systems within defined risk tolerances and Authority to Operate (ATO) requirements.

Furthermore, participants will learn how risk-based authorization decisions support secure and compliant information system operations.

Continuous Monitoring and System Lifecycle Management

Participants will learn how to maintain security throughout the system lifecycle by monitoring changes, vulnerabilities, threats, and emerging risks.

  • Monitor System Changes and Threats – Identify changes and emerging threats that may affect system security.
  • Conduct Ongoing Assessments – Perform continuous assessments and vulnerability scanning to identify security weaknesses.
  • Monitor Emerging Risks – Track supply chain risks, legal and regulatory updates, and relevant threat intelligence.
  • Support Response Planning – Participate in response planning and maintain an accurate system security posture.
  • Manage Secure Decommissioning – Apply appropriate security practices when systems reach the end of their lifecycle.
  • Master Risk Management – Build a comprehensive understanding of RMF and security authorization processes.
  • Career Advancement – Qualify for roles in cybersecurity governance, compliance, and system auditing.
  • Improved Earning Potential – CAP-certified professionals are in demand in defense, government, and private sectors.
  • Boost Organizational Security – Learn to implement and monitor robust cybersecurity controls.
  • Demonstrate Compliance – Ensure your organization aligns with frameworks like NIST, ISO/IEC 27001, and FISMA.

Upcoming Schedules: Please contact us to know more about our next available CAP training sessions and pricing.

Elevate your career in risk management and information system security with CAP certification.

Related certifications

Continue your certification journey.

Certification programmeCertified Cloud Security Professional (CCSP)

The Certified Cloud Security Professional (CCSP) certification, offered by (ISC)², is a globally recognized credential that validates your expertise in securing cloud environments. Whether you’re designing secure cloud applications, managing cloud-based infrastructure, or protecting critical cloud data, CCSP certification is your pathway to advanced career opportunities in cloud security.CCSPs apply in-depth information security knowledge to cloud computing environments. This certification measu

View Programme

Certification programmeCertified in Risk and Information Systems Control (CRISC)

The Certified in Risk and Information Systems Control (CRISC) certification is a globally recognized credential designed to validate IT professionals’ expertise in enterprise risk management, information security controls, and risk mitigation strategies. Offered by ISACA, CRISC certification equips professionals with the necessary skills to identify, evaluate, and manage IT risks while implementing effective information systems controls.

View Programme

Next step

Build the capability your organisation needs.

Discuss a corporate certification pathway with the SPS team.