|
via Udemy |
Go to Course: https://www.udemy.com/course/is-risk-and-control-exams-in-2025/
IS Risk and Control IS Risk and Control certification will make you a Risk Management expert. Studying a proactive approach based on Agile methodology, you'll learn how to enhance your company's business resilience, deliver stakeholder value and optimize Risk Management across the enterprise.26% DOMAIN 1 - GOVERNANCEThe governance domain interrogates your knowledge of information about an organization's business and IT environments, organizational strategy, goals and objectives, and examines potential or realized impacts of IT risk to the organization's business objectives and operations, including Enterprise Risk Management and Risk Management Framework.A-ORGANIZATIONAL GOVERNANCEOrganizational Strategy, Goals, and ObjectivesOrganizational Structure, Roles and ResponsibilitiesOrganizational CulturePolicies and StandardsBusiness ProcessesOrganizational AssetsB-RISK GOVERNANCEEnterprise Risk Management and Risk Management FrameworkThree Lines of DefenseRisk ProfileRisk Appetite and Risk ToleranceLegal, Regulatory and Contractual RequirementsProfessional Ethics of Risk Management20% DOMAIN 2 - IT RISK ASSESSMENTThis domain will certify your knowledge of threats and vulnerabilities to the organization's people, processes and technology as well as the likelihood and impact of threats, vulnerabilities and risk scenarios.A-IT RISK IDENTIFICATIONRisk Events (e.g., contributing conditions, loss result)Threat Modelling and Threat LandscapeVulnerability and Control Deficiency Analysis (e.g., root cause analysis)Risk Scenario DevelopmentB-IT RISK ANALYSIS AND EVALUATIONRisk Assessment Concepts, Standards and FrameworksRisk RegisterRisk Analysis MethodologiesBusiness Impact AnalysisInherent and Residual Risk32% DOMAIN 3 - RISK RESPONSE AND REPORTINGThis domain deals with the development and management of risk treatment plans among key stakeholders, the evaluation of existing controls and improving effectiveness for IT risk mitigation, and the assessment of relevant risk and control information to applicable stakeholders.A-RISK RESPONSERisk Treatment / Risk Response OptionsRisk and Control OwnershipThird-Party Risk ManagementIssue, Finding and Exception ManagementManagement of Emerging RiskB-CONTROL DESIGN AND IMPLEMENTATIONControl Types, Standards and FrameworksControl Design, Selection and AnalysisControl ImplementationControl Testing and Effectiveness EvaluationC-RISK MONITORING AND REPORTINGRisk Treatment PlansData Collection, Aggregation, Analysis and ValidationRisk and Control Monitoring TechniquesRisk and Control Reporting Techniques (heatmap, scorecards, dashboards)Key Performance IndicatorsKey Risk Indicators (KRIs)Key Control Indicators (KCIs)22% DOMAIN 4 - INFORMATION TECHNOLOGY AND SECURITYIn this domain we interrogate the alignment of business practices with Risk Management and Information Security frameworks and standards, as well as the development of a risk-aware culture and implementation of security awareness training.A-INFORMATION TECHNOLOGY PRINCIPLESEnterprise ArchitectureIT Operations Management (e.g., change management, IT assets, problems, incidents)Project ManagementDisaster Recovery Management (DRM)Data Lifecycle ManagementSystem Development Life Cycle (SDLC)Emerging TechnologiesB-INFORMATION SECURITY PRINCIPLESInformation Security Concepts, Frameworks and StandardsInformation Security Awareness TrainingBusiness Continuity ManagementData Privacy and Data Protection Principles