CRISC Cert Prep: 3 Risk Response and Reporting
1h 50mIntermediate2022-01-21
Authors

Jerod Brennen
Security Architect, Advisor, Speaker, Teacher
Course details
The Certified in Risk and Information Control (CRISC) certification is an established, well-recognized credential from ISACA, the organization that has issued over 200,000 certifications to cybersecurity professionals in 188 countries. A CRISC certification shows employers that you understand how to identify and manage IT risk in an enterprise and that you’re capable of implementing and maintaining the controls necessary to address risks. This series of courses provides you with insights and content around the four IT risk management domains. In this third course of the series, instructor Jerod Brennen focuses on the third CRISC domain: Risk Response and Mitigation. Jerod covers the tasks you’ll be tested on when you sit for the exam, including consulting with risk owners, creating a risk action plan, selecting risk management controls, assigning control ownership to establish clear lines of accountability, and registering risk profile changes.
Skills covered
Governance, Risk, and ComplianceCybersecurityCert Prep
Concepts
Introduction
- Risk response and reporting
Consult with Risk Owners
- Determine risk responses
- Align with business objectives
- Establish accountability
Risk Action Plans
- What is a risk action plan
- Determine response
- Determine cost
- Determine target date
- Third-party risk management
Support Control Owners
- Control frameworks
- Control design
- Control testing
- Control implementation
- Efficient and effective execution
Risk Register Updates
- Identify risk profile changes
- Determine management response
- Validate execution
- Risk and control monitoring and reporting
- Key risk indicators
- Key performance indicators
- Key control indicators
Conclusion
- Next steps