CLS
Cybersecurity

CRISC Certified in Risk and Information Systems Control

Certified in Risk and Information Systems Control (CRISC) develop students enhance their understanding of the impact of IT risk and identify how it relates to their organization.

Total Duration
32 Hours
Level
Intermediate
Category
Cybersecurity
Partner
ISACA
About this course

About this course

CRISC training will provide students with a comprehensive review of the unique challenges surrounding IT and enterprise risk management.

This course provides a deep dive into IT risk management, governance, and control implementation, empowering professionals to protect organizations from evolving cybersecurity threats and regulatory challenges.


Target Audience

Risk Managers who seek to improve their ability to identify, analyze, treat, and monitor organizational risks.
IT Risk who wants to strengthen their skills in enterprise risk management and risk assessment.
GRC Professionals who want to improve their expertise in governance, risk, and control management.
Information Security Professionals who want to develop their understanding of technology and security risk management
Professionals Preparing for the CRISC certification.

Prerequisites

An understanding of IT risk management and information systems control
Familiarity with governance, compliance, and audit practices
Experience with risk analysis, mitigation and business impact analysis

Course Outline

  • Strategy, Goals, and Objectives
  • Organizational Structure, Roles, and Responsibilities
  • Organizational Culture and Ethics
  • Policies and Standards
  • Business Processes and Resilience (e.g., DRP, BCP)
  • Organizational Asset Management
  • Enterprise Risk Management (ERM)
  • Lines of Defense
  • Risk Profile
  • Risk Appetite and Risk Tolerance
  • Risk Frameworks, Legal, Regulatory, and Contractual Requirements
  • Risk Events
  • Threat Modeling and Threat Landscape
  • Vulnerability and Control Deficiency Analysis
  • Risk Scenario Development
  • Risk Assessment Concepts and Standards
  • Business Impact Analysis (BIA)
  • Risk Register
  • Risk Analysis Methodologies
  • Inherent and Residual Risk
  • Risk and Control Ownership
  • Risk Treatment/Risk Response Options
  • Risk Management
  • Issue, Finding and Expectation Management
  • Control Types, Standards and Frameworks
  • Control Design, Selection and Analysis
  • Control Testing Methodologies
  • Risk Action Plans
  • Data Collection, Aggregation, Analysis, and Validation
  • Risk and Control Metrics (e.g., KRIs, KCIs, KPIs)
  • Risk and Control Monitoring Techniques
  • Risk and Control Reporting Techniques (e.g., heatmap, scorecards, dashboards)
  • Monitoring and Reporting of Emerging Risks
  • Technology Principles
  • Technology Roadmaps and Enterprise Architecture (EA)
  • Operations Management (e.g., change management, assets, DevOps, problems, incidents)
  • System Development Life Cycle (SDLC)
  • Data Lifecycle Management
  • Portfolio and Project Management (e.g. Agile)
  • Technology Resilience and Disaster Response/Recovery
  • Emerging Technologies
  • Security Concepts, Frameworks, and Standards
  • Security/Risk Awareness and Training
  • Data Privacy and Data Protection Principles
Learning outcomes

What you'll learn

Learn how to identify, analyze, and evaluate IT risks and their potential impact on business operations.
Explain governance, enterprise risk and IT risk principles
Delegates identify, analyze, and assess IT risks
Develop skills in risk scenarios, registers, and business impact analysis
Explain control design, implementation, testing and evaluation
Plan, execute, scrutinize, and retain information systems controls.
Cover IT operations, resilience, information security, data protection and privacy

Skills you'll learn

12 skills
Risk Governance
Enterprise Risk Management
Risk Analysis
Risk Identification
Risk Register
Risk Response
Control Testing
Risk Monitoring
Risk Reporting
Change Management

Certificate

  • Attendance Certificate from CLS Learning Solutions
  • This course enables you to pass CRISC Certified in Risk and Information Systems Control Exam  
CRISC Certified in Risk and Information Systems Control

Potential Career Paths

IT Risk Professionals
Risk analysts
IT auditors
Cybersecurity Experts
Risk Consultants
IT and Security Managers