Course Details
Course Duration: 4 day; / 28 hours; Instructor-led/ remote online training
Audience
Individuals who are looking to build a greater understanding of the impact of IT Risk and how it relates to their organization.
Prerequisites
There are no prerequisite requirements for taking the CRISC Exam Preparation Course or the CRISC exam; however, in order to apply for CRISC certification, the candidate must meet the necessary experience requirements determined by ISACA There are no pre-course reading materials needed for this course although candidates are encouraged to have the ISACA CRISC Review Manual available
Methodology
This program will be conducted with interactive lectures, PowerPoint presentation, discussion and practical exercise.
Course Objectives
The CRISC Exam Preparation course is an intensive, three-day review program to prepare individuals who are planning to sit for the Certified in Risk and Information System Controls™(CRISC) exam. The course focuses on the key points covered in the CRISC Review Manual 6th Edition and includes class lectures, group discussions, exam practice and answer debrief. The course is intended for individuals with familiarity with and experience in IT and enterprise risk management. This course is provided in partnership with Sapience Consulting Pte. Ltd.
Outlines
Module 1: Domain 1 — Governance
Lesson
- Key Risk Concepts
- Organisational Strategy, Goals and Objectives
- Organisational Structure, Roles and Responsibilities
- Organisational Culture and Assets
- Policies, Standards and Business Process Review
- Risk Governance Overview
- Enterprise Risk Management, Risk Management
- Frameworks and Three Lines of Defense
- Risk Profile, Risk Appetite and Risk Tolerance
- Professional Ethics, Laws, Regulations and Contracts
Module 2: Domain 2 – IT Risk Assessment
Lesson
- Risk Events
- Threat Modelling and Threat Landscape
- Vulnerability and Control Deficiency Analysis
- Risk Scenario Development
- Risk Assessment Concepts, Standards and Frameworks
- Risk Register
- Risk Analysis Methodologies
- Business Impact Analysis
- Inherent, Residual and Current Risk
Module 3: Domain 3 – Risk Response and Reporting
Lesson
- Risk and Control Ownership
- Risk Treatment/Risk Response Options
- Managing Risk from Processes, Third Parties and Emergent Sources
- Control Types, Standards and Frameworks
- Control Design, Selection and Analysis
- Control Implementation, Testing and Effectiveness Evaluation Risk Treatment Plans
- Data Collection, Aggregation, Analysis and Validation
- Risk and Control Monitoring and Reporting Techniques Metrics
Module 4: Domain 4 – Information Technology and Security
Lesson
- Enterprise Architecture
- IT Operations Management
- Project Management
- Enterprise Resiliency
- Data Life Cycle Management
- System Development Life Cycle
- Emerging Technologies