CRISC · Domain 1
Governance
About 26% of the exam
Governance versus management
- Governance
- direction, oversight, accountability
- Management
- plan, build, run, monitor
- Board
- sets appetite, oversees risk
- Executives
- own strategy, accept enterprise risk
- Risk practitioner
- advises, facilitates, never owns
- Alignment
- IT risk serves business objectives
Risk management exists to help the enterprise meet its objectives, not to eliminate risk
Three lines of defense
- First line owns and manages
- Second line oversees and challenges
- Third line assures independently
- First line
- business and IT operations, control owners
- Second line
- risk, compliance, security functions
- Third line
- internal audit, reports to the board
- External
- regulators and external auditors
- Governing body
- sets tone, appetite, oversight
- Independence
- audit cannot own what it audits
Operations own the risk, risk functions oversee it, audit checks both and answers to the board
Risk culture
- Tone at the top shapes behavior
- Risk-aware decisions at every level
- Safe to report issues and near misses
- Incentives aligned with appetite
- Communication in business language
- Culture gaps are themselves a risk
- Awareness programs change habits slowly
Appetite, tolerance, capacity, profile
- Appetite
- amount the board will pursue
- Tolerance
- acceptable variation from appetite
- Capacity
- most the enterprise can absorb
- Profile
- current aggregate exposure
- Threshold
- KRI value that triggers action
- Order
- capacity above appetite above tolerance bands
Appetite is a board statement in writing; the practitioner measures against it and reports deviations
Roles, RACI and ownership
- Risk owner
- business manager accountable for the risk
- Control owner
- operates and maintains the control
- Process owner
- runs the business process
- Data owner
- classifies and sets access rules
- Custodian
- implements what the owner decides
- Accountable
- one per activity, cannot delegate
- Responsible
- does the work, can be many
Policies, standards, procedures
- Policy
- Standard
- Procedure
- Guideline
- Policy states management intent, mandatory
- Standards make policy specific and measurable
- Procedures give step by step instructions
- Guidelines recommend, never bind
- Approved by management, reviewed on cycle
- Exceptions formal, time-bound, owner accepts
Frameworks
- COBIT
- governance and management of enterprise IT
- ISO 31000
- risk management principles and process
- ISO 27001
- certifiable ISMS
- ISO 27005
- information security risk management
- NIST CSF
- six functions, govern added
- NIST RMF
- categorize through monitor, federal
- COSO ERM
- enterprise risk and internal control
- Risk IT
- ISACA IT risk framework
Enterprise risk management
- Set context
- Identify
- Assess
- Respond
- Monitor
- Report
What governance provides
- Appetite and tolerance statements
- Risk policy and methodology
- Roles, RACI, committees
- Common taxonomy and rating scales
- Reporting lines to the board
What IT risk feeds back
- IT risk profile aggregated to enterprise
- Scenarios in business impact terms
- KRI breaches and trends
- Residual risk against appetite
- Emerging risks needing a decision
IT risk is a subset of enterprise risk; it must roll up in the same language and scales
Legal, regulatory, contractual
- Inventory obligations before designing controls
- Map many requirements to one control set
- Strictest requirement satisfies the rest
- Contracts push requirements to suppliers
- Compliance is a risk, not the goal
- Legal counsel decides applicability
- Regulatory change is an emerging risk source
Ethics and professional conduct
- Objectivity and independence in assessments
- Report through established channels first
- Never underreport to please a sponsor
- Disclose and manage conflicts of interest
- Competence: do not assess beyond skill
- Confidentiality of what you learn
- Escalate to audit committee when blocked
Emerging risk
Why it is hard
- Little history, traditional models struggle
- Evolves fast, needs continuous monitoring
- Cuts across silos and jurisdictions
- Impact unclear until it lands
- Held in a watch list, not fully rated
How to find it
- Horizon scanning and trend analysis
- Weak signal analysis, expert consultation
- Cross-industry intelligence sharing
- Red team and scenario workshops
- Technology risk assessment before adoption
Sources to name
- AI, generative models, adversarial inputs
- Quantum threat to current cryptography
- IoT, OT convergence, edge devices
- Cloud sovereignty, shared responsibility
- Geopolitics, regulation, supply chain, climate
First step for a new technology risk: inventory what depends on it, then assess before adopting
Processes, assets, architecture
- Business processes define what matters
- Asset inventory before risk identification
- Owner and classification for every asset
- Enterprise architecture shows dependencies
- Third parties are assets you rent
- Organizational structure fixes accountability
- Data flows reveal hidden exposure
Rapid recall: the FIRST move
- Understand business objectives before assessing
- Confirm appetite before rating anything
- Identify the owner before proposing treatment
- Check policy and law before technology
- Escalate above appetite, never absorb it
- Emerging technology: assess first, adopt second
- Report to the board in business terms
Reference strip: lines, roles, frameworks, emerging
Three lines
- First: owns and manages risk
- Second: oversees, challenges, sets methods
- Third: independent audit assurance
- Board: appetite and oversight
- External audit and regulators outside
Roles
- Risk owner: business, accountable
- Control owner: operates the control
- Data owner classifies, custodian implements
- Practitioner advises and facilitates
- One Accountable per activity
Frameworks
- COBIT: enterprise IT governance
- ISO 31000: risk management principles
- ISO 27001 and 27005
- NIST CSF and NIST RMF
- COSO ERM, ISACA Risk IT
Appetite words
- Appetite: what we pursue
- Tolerance: allowed variation
- Capacity: what we can absorb
- Profile: current exposure
- Threshold: KRI trigger
Emerging risk toolkit
- Horizon scanning, trend analysis
- Weak signals, expert panels
- Watch list in the register
- Technology assessment before adoption
- Continuous monitoring, not annual
Quick exam traps
- Trap: The risk practitioner owns the IT risks they identify
- Trap: Internal audit is part of the second line of defense
- Trap: Risk appetite is set by the risk management function
- Trap: Compliance with every regulation means risk is under control
- Trap: Emerging risks should wait until enough data exists to rate them
- Trap: Guidelines are mandatory once management publishes them
- Trap: The goal of risk management is zero risk
- Trap: IT risk can be reported in technical terms as long as it is accurate
cybercertprep.com · original revision sheet written from the public body of knowledge