Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
CRISC Certified in Risk and Information Systems Control
Highest Rated
Rating: 4.8 out of 5(1,235 ratings)
5,976 students

CRISC Certified in Risk and Information Systems Control

Certified in Risk and Information Systems Control certification
Last updated 9/2023
English
Arabic [Auto],Danish [Auto],

What you'll learn

  • Learn how ISACA looks at IT Risk Management and what that means for you as a Risk Practitioner.
  • Understand established frameworks and standards (e.g., COBIT, ISO) that guide IT governance and risk management practices.
  • Identify and document potential risks that could affect the organization's IT environment.
  • Categorize identified risks based on their nature, impact, and relevance to the organization.
  • Prioritize risks based on their severity, potential impact on business objectives, and the organization's risk appetite.
  • Evaluate the acceptability of risks by comparing the identified risks with the organization's risk tolerance and criteria.
  • Develop risk response strategies for each risk, including risk mitigation plans, contingency plans, and risk transfer strategies.
  • Continuously monitor the organization's IT environment to identify new risks or changes in existing risks.
  • Regularly review risk assessments and update them based on changes in the organization's environment and risk landscape.
  • Document the entire risk assessment process, including identified risks, analysis, control measures, and response plans.
  • Understand the set of fundamental concepts and practices that guide the design, implementation, management, and protection of information technology systems,
  • Learn the basics of data privacy requirements and how that integrates with risk management.

Course content

4 sections67 lectures16h 27m total length
  • Course Overview4:12

    Discover how this CRISC course covers governance, IT risk assessment, risk response and reporting, and information technology and security to prepare you for CRISC.

  • IT Risk Management Context21:34

    Explore governance and IT risk management in CRISC, highlighting four governance questions, board accountability, risk practitioner advisory role, RACI concepts, and the risk cycle from identify to monitor with controls.

  • Key Concepts of Risk19:59

    Explore key risk concepts for CRISC, including taxonomy, likelihood, consequence, threats, opportunities, vulnerabilities, and risk scenarios. Learn to communicate risk to senior management using quantitative impacts and cost benefit reasoning.

  • The Importance and Value of IT Risk Management and Business Strategy15:55

    Understand the value of IT risk management and its alignment with business goals. See how identifying threats, prioritizing responses, and senior management support drive project success and compliance.

  • The RACI Chart11:33

    This lecture explains the RACI chart and its four roles—responsible, accountable, consulted, informed—how it defines team roles and accountability in risk, with exam-style examples.

  • Key Roles Regarding Risk10:53

    Explore CRISC risk management roles including the risk manager, risk analyst, risk owner, control owner, control steward, and SMEs, with clear accountability, responsibility, and consulted or informed duties.

  • Organizational Structure and Culture13:58

    Align organizational structure with a risk-aware culture and establish enterprise mandates that enable cross-department communication, collaboration, and proactive ownership of risk management.

  • The Impact on Risk Management of Culture and Behavior14:40

    Learn how culture drives risk behavior from senior leadership to the boots on the ground. See how risk awareness fosters risk culture, governance, and information security controls.

  • Risk Culture8:51

    Learn how risk culture arises from behavior toward risk, policy compliance, and negative outcomes, and how misalignment with risk appetite, along with the blame culture, undermines risk management.

  • The Value of Risk Communication14:46

    Learn how risk communication turns data into actionable information, guiding senior management and external stakeholders through balanced reporting and informed decision making.

  • What are Policies, Standards, and Procedures?14:33

    Explore how policies, standards, and procedures shape governance, compliance, and risk management in CRISC, with ISO 27001 guidance, risk appetite, exceptions, and compensating controls.

  • Reviewing the Business Process7:01

    Align risk management with business goals by reviewing and documenting current processes, engaging knowledgeable people from all departments, and applying gap analysis to drive continuous improvement.

  • Risk Management Principles, Processes and Controls13:45

    Explore risk management principles, processes, and controls, and learn to align IT risk with business objectives through cost-benefit analysis, open communication, and continuous improvement.

  • IT Risk and its Relation to Other Business Functions17:47

    Explore how IT risk relates to other business functions, balancing risk appetite, risk capacity, and tolerances while integrating BCM, audits, and controls to protect the enterprise.

  • Project Risk and Change Risk7:59

    Explore how project risk anchors information technology risk management to protect value and enterprise goals, highlighting scoping, scope creep, change management, and the change advisory board in the risk lifecycle.

  • People and Technology11:11

    Explore how people and technology interact to create risk in IT environments, covering culture, cross-training, retention, incentives, and data lifecycle from hardware refresh and disposal to data retention and accountability.

  • Data and Intellectual Property8:41

    Identify data and intellectual property as core assets, classify data by business value and security needs, and protect trademarks, copyrights, patents, and trade secrets with NDAs and access controls.

  • IT Risk Management and Good Practices8:19

    Apply IT risk management best practices through coordinated activities to direct and control risk and support business goals. Maintain comprehensive, auditable, compliant, and continuously monitored risk management with clear scoping.

  • Three Lines of Defense15:40

    Explore the three lines of defense model for risk and information systems control, detailing operational management, risk and compliance functions, and audit to clarify roles and enhance communication.

  • What is a Risk Profile?11:51

    Explore how a risk profile delivers a dynamic view of risk posture, appetite, tolerance, capacity, and controls for proactive identification and response.

  • Risk Appetite, Tolerance and Capacity14:44

    Explore ISACA CRISC concepts of risk appetite, tolerance, and capacity, defining residual risk and the roles of the board and senior management in setting policies and risk response.

  • Legal, Contractual, and Regulatory Requirements18:29

    Explore how legal, contractual, and regulatory requirements shape risk management in CRISC, including HIPAA, GDPR, PCI DSS, and Sarbanes-Oxley, with guidance on compliance decisions and ethics.

Requirements

  • While there are no strict prerequisites for attending a CRISC preparation course, it's recommended that participants have some background in IT risk management, information security, and related areas. The CRISC certification is typically intended for professionals who have at least three years of cumulative work experience in at least three of the four domains covered by the CRISC exam.

Description

The ISACA Certified in Risk and Information Systems Control certification is one of the top risk management certifications in the world. This course will help prepare you to be acknowledged as a Risk Management expert. Taking a proactive approach based on Agile methodology, you’ll learn how to enhance your company’s business resilience, deliver stakeholder value and optimize Risk Management across the enterprise. This course covers areas of risk governance, policies and controls. You will also learn and understand the risk management lifecycle with a focus on IT systems security and control.

The CRISC certification course is designed to provide professionals with the knowledge and skills required to effectively manage IT risks and implement information systems controls within organizations. The course covers essential concepts related to risk identification, assessment, evaluation, response, and control, as well as the integration of risk management practices with overall business objectives.

CRISC is intended for professionals who work in the fields of IT risk management, control assurance, and governance.

While there are no strict prerequisites for attending a CRISC preparation course, it's recommended that participants have some background in IT risk management, information security, and related areas. The CRISC certification is typically intended for professionals who have at least three years of cumulative work experience in at least three of the four domains covered by the CRISC exam.

Who this course is for:

  • IT Risk Professionals
  • Information Security Professionals
  • IT Auditors and Governance Professionals
  • Compliance Officers
  • Risk Assurance Professionals: