Certified in Risk and
Information Systems
Control (CRISC)
Contents
Contents 2
Certified in Risk and Information Systems Control (CRISC) 3
Syllabus 4
Domain 1: Governance 5
Domain 2: IT Risk Assessment 6
Domain 3: Risk Response and Reporting 7
Domain 4: Information Technology and Security 9
Our Delivery Methods 10
Our Packages 11
Contact us 12
Certified in Risk and
Information Systems
Control (CRISC)
The Certified Risk Information Systems Control training course provides
delegates with valuable technical skills, which ensure success and prosperity in
the realm of IT security.
The CRISC certification is a powerful manifestation of proficiency and expertise
regarding various areas of risk. As well as this, CRISC demonstrates a
commitment to IT security operations and enterprises and a willingness to
deliver quality within their profession.
The demand for CRISC qualified individuals is ever-growing, and CRISC has been
established as one of the most desirable and preferable IT security certifications
worldwide.
Also, delegates will discover how to address challenges that they may encounter
in the field of IT and will be able to adapt CRISC principles to their own
organisation.
Syllabus
The course is split into 4 easy-to-understand domains –
which will improve your skills and make you an expert in
IT security.
Domain 1: Governance
Domain 2: IT Risk Assessment
Domain 3: Risk Response and Reporting
Domain 4: Information Technology and Security
Domain 1
Governance
Organisational Governance
● Organisational Strategy, Goals and Objectives
● Organisational Structure, Roles and Responsibilities
● Organisational Culture
● Policies and Standards
● Business Process Review
● Organisational Assets
Risk Governance
● Enterprise Risk Management and Risk Management Frameworks
● Three Lines of Defence
● Risk Profile
● Risk Appetite, Tolerance and Capacity
● Legal, Regulatory and Contractual Requirements
● Professional Ethics of Risk Management
Domain 2
IT Risk Assessment
IT Risk Identification
● Risk Events
● Threat Modelling and Threat Landscape
● Vulnerability and Control Deficiency Analysis
● Risk Scenario Development
IT Risk Analysis, Evaluation and Assessment
● Risk Assessment Concepts, Standards and Frameworks
● Risk Register
● Risk Analysis Methodologies
● Business Impact Analysis
● Inherent, Residual and Current Risk
Domain 3
Risk Response and Reporting
Risk Response
● Risk and Control Ownership
● Risk Treatment/Risk Response Options
● Third Party Risk Management
● Issue, Finding and Expectation Management
● Management of Emerging Risk
Control, Design and Implementation
● Control Types, Standards and Frameworks
● Control Design, Selection and Analysis
● Control Implementation
● Control Testing and Effectiveness Evaluation
Domain 3
Risk Response and Reporting
Risk Monitoring and Reporting
● Risk Treatment Plans
● Data Collection, Aggregation, Analysis and Validation
● Risk and Control Monitoring Techniques
● Risk and Control Reporting Techniques
● Key Performance Indicators
● Key Risk Indicators
● Key Control Indicators
Domain 4
Information Technology and Security
Information Technology Principles
● Enterprise Architecture
● IT Operations Management
● Project Management
● Enterprise Resiliency
● Data Life Cycle Management
● System Development Life Cycle
● Emerging Trends in Technology
Information Security Principles
● Information Security Concepts, Frameworks and Standards
● Information Security Awareness Training
● Data Privacy and Principles of Data Protection
Our Delivery Methods
POPULAR POPULAR
Online Instructor-led Online Self-paced In-house Classroom
Join a scheduled class with a live Learn at your own pace. Our Our courses can be adapted to Some of our courses are
instructor and other delegates. expert trainers are on hand to meet your individual project or available in our classrooms. All of
Ask questions, share documents, help you with anything. business requirements. In-house our trainers are highly qualified,
interact with whiteboards, ask All of our courses come with a training gives your team a great having 10+ years of experience.
live questions and communicate standard 90 days access which opportunity to come together, We use the highest quality
with your trainer and peers. can be upgraded if need be.. bond and discuss, which may be learning facilities to make sure
Access the best pool of trainers, Our e-learning platform is limited in a standard classroom your experience is as
wherever you are. available on all devices. setting. comfortable as possible.
Our Packages
Below is the package containing multiple courses delivered as Online Instructor-led and Online self-paced.
Complete Risk Management
Certification
3 courses
Included courses
Management of Risk (MoR®)
Foundation and Practitioner
Certified in Risk and Information
Systems Control (CRISC)
ISO 22301 Lead Implementer
Contact Us
Europe North America Asia
+1 646 687 6780 +91 181 5047001
+44 1344 203 999
M a s t e r c l a s s
+1 613 800 4703 +971 800 0444 3286
+49 8005 895337
+44 1344 203 999 +966 8008110368
Oceania
+31 80000 227317 +65 800 1206314
+61 1 800 150644 +852 800 908601
+41 800 312616
+64 800 446148
+32 80077519
E x c e l
18