Summary
At the beginning of this chapter, we learned about the major laws and regulations over a variety of industries and geographies that may pose a legal requirement for the organization to adhere to those regulations. Then, we learned about the relationship between ethics, culture, and IT risk management that is critical to determine an organization’s response to risks. In the next section, we learned about the importance of professional ethics and ISACA’s Code of Professional Ethics, which all the CRISC candidates and certification holders are expected to comply with.
In the next chapter, we will be diving into domain 2, IT Risk Assessment, and learn about the risk management life cycle.