Certified in Risk and Information Systems Control (CRISC)
Exam Details
Pre-requisites:
Minimum of 3 years of cumulative work experience performing the tasks of a CRISC professional across at least 2 of the 4 CRISC domains.
Price
Duration
The CRISC - Certified in Risk and Information Systems Control certification is the most current and rigorous assessment available to evaluate the risk management proficiency of IT professionals and other employees within an enterprise or
financial institution. Achieving CRISC certification validates that you have the knowledge and expertise to help companies understand business risk. It also confirms that you have the technical knowledge to implement appropriate information system (IS) controls.
KEY OUTCOMES
Be able to:
- Prepare for and pass the Certified Risk and Information System Controls (CRISC) exam
- Identify the universe of IT risk to contribute to the execution of the IT risk management strategy
- Analyze and evaluate IT risk to determine the likelihood and impact on business objectives
- Determine risk response options and evaluate their efficiency and effectiveness to manage risk
- Continuously monitor and report on IT risk and controls
Objectives
- Risk Identification
o Collect and review information.
o Identify potential threats and vulnerabilities to the organization’s people, processes and technology to enable IT risk analysis.
o etc - Risk Assessment
o Analyze risk scenarios based on organizational criteria
o Identify the current state of existing controls and evaluate their effectiveness for IT risk mitigation
o etc - Risk Response and Mitigation
o Consult with risk owners to select and align recommended risk responses with business objectives and enable informed risk decisions
o Consult with, or assist, risk owners on the development of risk action plans
o etc - Risk and Control Monitoring and Reporting
o Define and establish key risk indicators (KRIs) and thresholds based on available data
o Monitor and analyze key risk indicators (KRIs)
o etc