National data — wages and growth are not published by state for this view.
Certification
Certified in Risk and Information Systems Control (CRISC)
ISACA
Median earnings
—
Cost
$50
Duration
—
Completion
—
A Certified in Risk and Information Systems Control® (CRISC®) certification demonstrates your IT risk management expertise. By taking a proactive approach, you will learn how to enhance your organization’s business resilience, deliver stakeholder value and optimize risk management across the enterprise. As a CRISC, you will be ready to address emerging technology, including AI risk assessment and general best practices for risk management and mitigation related to AI data governance and ethics.
Collect, review, and evaluate existing information regarding the organization’s business and information system environmentsIdentify potential or realized impacts of information system risk to the organization’s business objectives and operationsIdentify threats and vulnerabilities to the organization’s people, processes, and technologiesEvaluate threats, vulnerabilities, and risk to create information system risk scenariosEstablish accountability by assigning and validating appropriate levels of risk and control ownershipMaintain or establish the information system risk register and incorporate it into the enterprisewide risk profileAssist key stakeholders in the selection of risk appetite and tolerance thresholds and the impact on business objectivesPromote a risk-aware culture by contributing to the development and implementation of security/risk awareness and trainingConduct a risk assessment by analyzing information system risk scenarios and events to generate a risk score/ratingIdentify the current state of existing controls and evaluate their effectiveness for information system risk treatmentDetermine if risk exceeds appetite and tolerance thresholds to recommend treatment options and rectify concernsReview the results of risk and/or control analysis to assess any gaps between current and desired states of the risk environmentCollaborate with risk owners on the development of risk treatment plansCollaborate with control owners on the selection, design, implementation, and maintenance of controlsValidate that risk responses have been executed according to risk action plansDefine, implement, and refine key risk indicators (KRIs)Collaborate with control owners on the identification and refinement of key performance indicators (KPIs) and key control indicators (KCIs)Monitor and analyze key risk indicators (KRIs), key performance indicators (KPIs), and key control indicators (KCIs)Review the results of control assessments to determine the adequacy, effectiveness, and maturity of the control environmentConduct aggregation, analysis, and validation of risk and control dataReport relevant risk and control information to applicable stakeholders to facilitate risk-based decision-makingEvaluate emerging technologies and changes to the environment for threats, vulnerabilities, and opportunitiesEvaluate alignment of business practices with risk management frameworks, standards, and regulationsFacilitate tabletop exercises to verify and identify gaps in risk scenarios, capabilities, and responses