CRISC · Domain 4
Information Technology and Security
About 20% of the exam
Architecture and IT operations
- Enterprise architecture maps business to technology
- Dependencies reveal where failure spreads
- Single points of failure are risk entries
- Asset and configuration inventory first
- Cloud shifts controls, not accountability
- Operations metrics feed risk monitoring
- Technical debt is an unrecorded risk
Projects and the SDLC
- Requirements
- Design
- Build
- Test
- Deploy
- Operate
- Retire
Risk in each phase
- Requirements: security and compliance stated early
- Design: threat model, architecture review
- Build: secure coding, dependency checks
- Test: security testing, UAT, sign-off
- Deploy: change approval, rollback ready
Practitioner's role
- Risk assessment at project initiation
- Gate reviews before each phase exit
- Segregate development, test, production
- Agile and DevOps: automate the gates
- Post-implementation review closes the loop
Fixing a flaw in requirements costs least; fixing it in production costs most and adds risk
Change and configuration
- Change management
- request, assess, approve, test, implement, review
- Emergency change
- act first, document and approve after
- CAB
- reviews risk and impact of changes
- Configuration baseline
- known good state to compare
- CMDB
- inventory of items and relationships
- Drift
- unauthorized deviation from baseline
- Patch management
- test, prioritize by risk, verify
Unauthorized change is the leading cause of outages; verify patches landed, do not trust the SLA
Data lifecycle
- Create
- Store
- Use
- Share
- Archive
- Destroy
- Classify at creation, owner assigned
- Protect in storage, transit, use
- Share by need, log the access
- Retain per law and business need
- Destroy verifiably when retention ends
- Data flows cross borders, mind sovereignty
Classification and privacy
- Owner classifies by impact if exposed
- Few levels, clearly defined handling rules
- Personal data brings legal obligations
- Privacy by design and by default
- Data minimization and purpose limitation
- Impact assessment for high-risk processing
- Breach notification clocks start at awareness
Security concepts
- Confidentiality
- only authorized parties see it
- Integrity
- accurate, complete, unaltered
- Availability
- there when the business needs it
- Least privilege
- minimum access to do the job
- Segregation of duties
- no one person controls a whole transaction
- Defense in depth
- layers, no single control trusted
- Identity and access
- provision, review, revoke on leaving
Emerging technology risk
- Assess before adoption, not after
- Cloud: shared responsibility, data location
- AI: bias, data leakage, opaque decisions
- IoT and OT: expanded attack surface
- Quantum: inventory cryptography now
- Low-code: bypasses security review
- Open-source dependencies: one flaw, many systems
Business impact analysis and recovery targets
BIA
- Identify critical processes and their dependencies
- Quantify impact as outage lengthens
- Business owners set the numbers
- Objective criteria settle priority disputes
- Output drives RTO, RPO, recovery order
Targets
- MTD
- longest outage before unacceptable harm
- RTO
- time to restore, shorter than MTD
- RPO
- data loss tolerated, drives backup frequency
- WRT
- catch-up work after systems return
- SDO
- minimum service level while degraded
- Zero and zero
- synchronous replication, active-active sites
RTO plus WRT inside MTD; daily midnight backup with failure at 11 PM loses 23 hours
BCP versus DRP versus IRP
- BCP
- keep critical business functions running
- DRP
- restore IT systems and infrastructure
- IRP
- manage a security incident
- Crisis communication
- timely, accurate stakeholder messaging
- Succession
- key roles covered if people unavailable
- Resilience
- anticipate, absorb, adapt, recover
DRP is the IT subset of BCP; the BIA feeds both
Recovery sites
- Hot
- fully equipped, fastest, most costly
- Warm
- hardware in place, needs configuration and data
- Cold
- space and utilities, slowest, cheapest
- Mobile
- transportable facility
- Reciprocal
- mutual agreement, hard to test
- Cloud, multi-region
- active-active, automated failover
Site choice follows the RTO the business set, and the budget that accepts it
Testing continuity plans
- Checklist
- Tabletop
- Walkthrough
- Simulation
- Parallel
- Full interruption
- Test regularly and after significant change
- Tabletop finds gaps at lowest cost
- Full interruption risks a real outage
- Recovery slower than RTO is a finding
- Every test ends with plan updates
Backups and resilience
- Full
- everything, fastest restore, most storage
- Incremental
- since last backup, restore full plus each
- Differential
- since last full, restore full plus latest
- Offsite, offline
- survives site loss and ransomware
- Replication
- synchronous for RPO near zero
- Redundancy
- remove single points of failure
- Chaos testing
- inject failure to prove resilience
Know the numbers
- RTO 4h, RPO 1h
- restore in four, lose at most one
- RTO must be
- less than MTD
- RPO sets
- backup or replication frequency
- 99.99%
- about 52 minutes downtime per year
- Weekly full plus daily incremental
- restore full, then each incremental in order
- Fastest site
- hot, then warm, then cold
Rapid recall: the FIRST move
- BIA before choosing any recovery solution
- Business owners set RTO and RPO
- Assess new technology before adoption
- Change goes through approval, then production
- Classify data before deciding controls
- Map dependencies before sequencing recovery
- Test the plan, then fix the plan
Reference strip: lifecycle, change, continuity, security
SDLC and projects
- Requirements, design, build, test, deploy
- Security gates at each phase exit
- Segregate dev, test, production
- Post-implementation review closes it
- Retire securely at end of life
Change and configuration
- Request, assess, approve, test, implement
- Emergency change documented after
- Baseline, CMDB, drift detection
- Patch by risk, verify installation
- Rollback plan for every change
Continuity metrics
- MTD: outer limit of outage
- RTO: restore time target
- RPO: data loss tolerated
- WRT: work recovery after restore
- SDO: degraded service level
Plans and sites
- BCP business, DRP technology, IRP incidents
- Hot, warm, cold, mobile, reciprocal
- Tabletop through full interruption
- Full, incremental, differential backups
- Crisis communication and succession
Security and data
- Confidentiality, integrity, availability
- Least privilege, segregation of duties
- Create, store, use, share, archive, destroy
- Classify by impact, owner decides
- Privacy by design, minimization, DPIA
Quick exam traps
- Trap: RTO can safely equal or exceed MTD
- Trap: RPO describes how quickly systems come back
- Trap: A full interruption test is the best place to start
- Trap: The DRP covers the whole business, the BCP covers IT
- Trap: IT sets recovery objectives because IT runs the systems
- Trap: An emergency change needs no documentation or later approval
- Trap: Meeting the patch SLA means the systems are patched
- Trap: Moving to the cloud transfers accountability for the data
cybercertprep.com · original revision sheet written from the public body of knowledge