CRISC Cert Prep: 1 Governance
2h 6mIntermediate2022-01-14
Authors

Jerod Brennen
Security Architect, Advisor, Speaker, Teacher
Course details
The Certified in Risk and Information Control (CRISC) certification is an established, well-recognized credential from ISACA, the organization that has issued over 200,000 certifications to cybersecurity professionals in 188 countries. A CRISC certification shows employers that you understand how to identify and manage IT risk in an enterprise and that you’re capable of implementing and maintaining the controls necessary to address risks. This series of courses provides you with insights and content around the four IT risk management domains. In this first course of the series, instructor Jerod Brennen focuses on the first CRISC domain: IT Risk Identification. Jerod goes over some basic definitions and information for IT risks, then covers several threats and vulnerabilities and how you can protect your organization’s people, processes, and technology. He addresses enterprise risk context and shows you techniques to engage your stakeholders and improve your risk posture.
Skills covered
Incident ResponseCert PrepCybersecurity
Concepts
Introduction
- Governance
- What you need to know
IT Risk Basics
- Define IT risk
- Collect relevant information
- Measure IT risk
Threats and Vulnerabilities
- Understand threats
- Understand vulnerabilities
- Protect people
- Protect processes
- Protect technology
Enterprise Risk Context
- Prioritize IT risk
- Establish an IT risk register
- Understand the enterprise risk profile
- Three lines of defense
Engage Your Stakeholders
- Identify key stakeholders
- Determine risk appetite and tolerance
- Align with business objectives
- Align with external requirements
- Develop control documentation
- Enable informed decisions
Improve Your Risk Posture
- Collaborate with stakeholders
- Develop a risk-awareness program
- Train your stakeholders
- Promote a risk-aware culture
Conclusion
- Next steps