Risk Management Life Cycle
This chapter marks the beginning of Domain 2, IT Risk Assessment, for CRISC. This domain represents 20 percent (approximately 30 questions) of the CRISC exam. As a reminder, Domain 1 of the CRISC exam and the material we learned up to Chapter 5, Legal Requirements and the Ethics of Risk Management, was entirely based on Governance, which relates to the direction from the stakeholders and leadership team. This chapter, and the following chapters, are about the hands-on approach to implementing those directions across the organization.
The aim of this chapter is to introduce the concept of risk, learn how it is different from IT risk, take a deeper dive into the risk management life cycle, understand the requirements of risk assessments, learn the difference between issues, events, incidents, and breaches, and ultimately, learn about how the correlation of events and incidents works. Additionally, we will learn about how to choose different sets of controls...