We've noticed this is not your region.
Redirect me to my region
What do you want to learn today?

Details

CRISC—Certified in Risk and Information Systems Control

ISACA’s Certified in Risk and Information Systems Control™ (CRISC®) certification indicates expertise in identifying and managing enterprise IT risk and implementing and maintaining information systems controls. Gain instant recognition and credibility with CRISC and boost your career! If you are a mid-career IT professional with a focus on IT and cyber risk and control, CRISC can get you the leverage you need to grow in your career.

Outline

This update to the CRISC exam content outline is based on changes in the work practices of IT risk professionals as well as market dynamics and trends that have placed an increased focus on organizational governance, continuous risk monitoring and reporting, information security and data privacy considerations for effective ITRM. These statements and domains are the results of extensive research, feedback, and validation from IT risk and control subject matter experts and prominent industry leaders from around the globe.

Below are the key domains, subtopics and tasks candidates will be tested on:

DOMAIN 1—Governance 26% Organizational Governance A
  • Organizational Strategy, Goals, and Objectives
  • Organizational Structure, Roles, and Responsibilities
  • Organizational Culture
  • Policies and Standards
  • Business Processes
  • Organizational Assets
Risk Governance B
  • Enterprise Risk Management and Risk Management Framework
  • Three Lines of Defense
  • Risk Profile
  • Risk Appetite and Risk Tolerance
  • Legal, Regulatory, and Contractual Requirements
  • Professional Ethics of Risk Management
DOMAIN 2—IT Risk Assessment 20% IT Risk Identification A
  • Risk Events (e.g., contributing conditions, loss result)
  • Threat Modelling and Threat Landscape
  • Vulnerability and Control Deficiency Analysis (e.g., root cause analysis)
  • Risk Scenario Development
IT Risk Analysis and Evaluation B
  • Risk Assessment Concepts, Standards, and Frameworks
  • Risk Register
  • Risk Analysis Methodologies
  • Business Impact Analysis
  • Inherent and Residual Risk
DOMAIN 3—Risk Response and Reporting 32% Risk Response A
  • Risk Treatment / Risk Response Options
  • Risk and Control Ownership
  • Third-Party Risk Management
  • Issue, Finding, and Exception Management
  • Management of Emerging Risk
Control Design and Implementation B
  • Control Types, Standards, and Frameworks
  • Control Design, Selection, and Analysis
  • Control Implementation
  • Control Testing and Effectiveness Evaluation
Risk Monitoring and Reporting C
  • Risk Treatment Plans
  • Data Collection, Aggregation, Analysis, and Validation
  • Risk and Control Monitoring Techniques
  • Risk and Control Reporting Techniques (heatmap, scorecards, dashboards)
  • Key Performance Indicators
  • Key Risk Indicators (KRIs)
  • Key Control Indicators (KCIs)
DOMAIN 4—Information Technology and Security 22% Information Technology Principles A
  • Enterprise Architecture
  • IT Operations Management (e.g., change management, IT assets, problems, incidents)
  • Project Management
  • Disaster Recovery Management (DRM)
  • Data Lifecycle Management
  • System Development Life Cycle (SDLC)
  • Emerging Technologies
Information Security Principles B
  • Information Security Concepts, Frameworks, and Standards
  • Information Security Awareness Training
  • Business Continuity Management
  • Data Privacy and Data Protection Principles
Reviews
Be the first to write a review about this course.
Write a Review

Over the past years, SGL Technologies has continued to maintain and focus on the products and technologies from a customer's perspective, developing and delivering ICT cutting edge solutions and training for vendors and partners as Consultants and Training Specialists for different organizations irrespective of the industry sector.

SGL Technologies has the experience and team that can create a system for you and your business. Working hand-in-hand with our team gives our clients the tools to create an easily manageable workflow in an organization.

Our services include the provisions of top notch Business Support Information Technology Solutions:

IT Training, Licensing of Computer Softwares, Networking, Data Protection and Storage Management Solutions, Video Conferencing,   ICT Professional Certification Testing and Facilitate Internationally Recognized Professional Certificates in IT.

We offer world class Information Technology training to prepare you adequately for a global IT career.

  • Over Twenty ( 25) Highly Experienced and Certified  Consultants / Trainers
  • Optimized Training Budget
  • Customized Training Solutions
  • Standard and Vendors’ Approved Course wares
  • Both Classroom and On-Site Training Options ...
SGL Technologies
22, Akinremi street,, Anifowoshe, Ikeja, Lagos, Nigeria 234
8127323861
Sending Message
Please wait...
× × Speedycourse.com uses cookies to deliver our services. By continuing to use the site, you are agreeing to our use of cookies, Privacy Policy, and our Terms & Conditions.