CRISC job practice areas
I have combined the job practice areas to ease the flow of reading and the logical structure of the book. The following list summarizes the practice areas and their corresponding chapters in this book:
Domain 1 – Governance
- Organizational governance:
- Chapter 3, Organizational Governance, Policies, and Risk Management:
- Organizational strategy, goals, and objectives
- Organizational structure, roles, and responsibilities
- Organizational culture
- Policies and standards
- Business processes
- Organizational assets
- Chapter 3, Organizational Governance, Policies, and Risk Management:
- Risk governance:
- Chapter 4, The Three Lines of Defense and Cybersecurity:
- Enterprise risk management and the risk management framework
- Three lines of defense
- Risk profile
- Risk appetite, tolerance, and capacity
- Chapter 5, Legal Requirements and the Ethics of Risk Management:
- Legal, regulatory, and contractual requirements
- Professional ethics of risk management
- Chapter 4, The Three Lines of Defense and Cybersecurity:
Domain 2 – IT risk assessment
- IT risk identification:
- Chapter 6, Risk Management...