IT and business professionals who identify and manage risk through appropriate controls in information systems: risk and compliance managers, IT risk managers, information security and internal control professionals, business analysts and project managers.
Practical experience in IT risk management or with controls in information systems, as well as basic knowledge of IT operations and information security, is required. For certification, ISACA requires at least three years of professional experience in at least two of the four CRISC domains after passing the exam.
After the course you will be able to:
- embed IT risk management in the organisation’s governance and define risk appetite and risk tolerance
- identify and analyse risks based on threats, vulnerabilities and scenarios, and document them in the risk register
- select appropriate risk responses and design, implement and test controls
- monitor risks and controls using key indicators and report on them to the relevant audience
- classify risks arising from technology, supply chains, emerging technologies and data privacy
- prepare specifically for the CRISC exam