CRISC Practice Areas and the ISACA Mindset
If the previous chapter was all about learning about governance, risk, and compliance, and why they are required, this chapter will focus on preparing you for the main goal of this book – to pass the ISACA Certified in Risk and Information Systems Control (CRISC) exam.
The CRISC certification aims to advance your career by helping you understand the impact of IT risk and how it relates to your organization. The CRISC certification demonstrates the holder’s ability to identify and evaluate IT risk, propose strategies to mitigate risk optimally, and help the enterprise accomplish its business objectives.
The ISACA website (https://www.isaca.org/credentialing/crisc) provides an apt description of the certification: The CRISC certification validates your experience in building a well-defined, agile risk-management program, based on best practices to identify, analyze, evaluate, assess, prioritize, and respond to risks. This...