ISACA Code of Professional Ethics
ISACA has defined and set forth a code of professional conduct for members of the association, including CRISC holders and certified risk practitioners. ISACA certification holders shall do the following:
- Support the implementation of, and encourage compliance with, appropriate standards and procedures for the effective governance and management of enterprise information systems and technology, including audit, control, security, and risk management.
- Perform their duties with objectivity, due diligence, and professional care, in accordance with professional standards.
- Serve in the interest of stakeholders in a lawful manner, while maintaining high standards of conduct and character, and not discrediting their profession or the association.
- Maintain the privacy and confidentiality of information obtained in the course of their activities unless disclosure is required by a legal authority. Such information shall not be used for personal...