Free knowledge base

CRISC Certified in Risk and Information Systems Control — key terms, tricks & tips

Everything from the course in one searchable place: 205 entries. Use it to review before a practice test or look up a word you forgot.

205 results

Key term

CRISC

Certified in Risk and Information Systems Control, an ISACA certification.

Getting Started: CRISC Exam Essentials

Key term

ISACA

Information Systems Audit and Control Association, global professional organization.

Getting Started: CRISC Exam Essentials

Key term

IT Risk

Potential for an IT-related event to negatively impact business objectives.

Getting Started: CRISC Exam Essentials

Key term

IS Controls

Policies, procedures, and mechanisms to manage IT risks.

Getting Started: CRISC Exam Essentials

Key term

CPE

Continuing Professional Education, hours required to maintain certification.

Getting Started: CRISC Exam Essentials

Key term

Governance

Framework ensuring IT aligns with business strategy and objectives.

Getting Started: CRISC Exam Essentials

Key term

Risk Appetite

The amount of risk an organization is willing to accept.

Getting Started: CRISC Exam Essentials

Memory trick

Understanding the CRISC Certification

To remember the CRISC domains, think 'GRIT': Governance, Risk Assessment, Information Technology & Security, and (Risk) Response & Reporting. GRIT helps you manage risk!

Getting Started: CRISC Exam Essentials

Exam tip

Understanding the CRISC Certification

The CRISC certification requires a minimum of three years of cumulative work experience in at least two of the four CRISC domains. This experience must be within the 10-year period preceding the application date or within five years of passing the exam. Memorize these specific timeframes and domain count.

Getting Started: CRISC Exam Essentials

Common mistake

Understanding the CRISC Certification

Underestimating the required work experience: Many candidates pass the exam but fail to meet the experience requirements for certification.

Getting Started: CRISC Exam Essentials

Common mistake

Understanding the CRISC Certification

Focusing only on technical controls: CRISC emphasizes a holistic view of risk, including business impact, not just technical solutions.

Getting Started: CRISC Exam Essentials

Common mistake

Understanding the CRISC Certification

Neglecting CPE requirements: Failing to earn and report sufficient CPEs can lead to certification revocation.

Getting Started: CRISC Exam Essentials

Key term

Domain

A major section or area of knowledge covered by the CRISC exam.

Getting Started: CRISC Exam Essentials

Key term

Weighting

The percentage of the exam dedicated to a specific domain, indicating its importance.

Getting Started: CRISC Exam Essentials

Key term

Multiple-Choice Question

An exam question with a stem and four possible answer options.

Getting Started: CRISC Exam Essentials

Key term

Scaled Score

A standardized score that adjusts for variations in exam difficulty.

Getting Started: CRISC Exam Essentials

Key term

Passing Score

The minimum scaled score required to pass the CRISC exam (450).

Getting Started: CRISC Exam Essentials

Key term

Time Management

Strategically allocating time during the exam to answer all questions.

Getting Started: CRISC Exam Essentials

Memory trick

Navigating the CRISC Exam Structure and Format

Go RIch, Risk Response, Monitor: G-R-R-M helps remember the domain order and emphasis.

Getting Started: CRISC Exam Essentials

Exam tip

Navigating the CRISC Exam Structure and Format

Memorize the exact percentage weightings for each of the four CRISC domains. The exam frequently tests your understanding of the relative importance of these areas.

Getting Started: CRISC Exam Essentials

Common mistake

Navigating the CRISC Exam Structure and Format

Underestimating the importance of higher-weighted domains like Governance and Risk Response.

Getting Started: CRISC Exam Essentials

Common mistake

Navigating the CRISC Exam Structure and Format

Spending too much time on a single difficult question, jeopardizing completion of the entire exam.

Getting Started: CRISC Exam Essentials

Common mistake

Navigating the CRISC Exam Structure and Format

Failing to read questions carefully, especially those asking for the 'BEST' or 'MOST appropriate' answer.

Getting Started: CRISC Exam Essentials

Key term

Organizational Governance

System directing and controlling an organization.

Module 1: Governance Fundamentals

Key term

Enterprise Risk Management (ERM)

Holistic framework for managing all organizational risks.

Module 1: Governance Fundamentals

Key term

GRC

Governance, Risk, and Compliance integrated approach.

Module 1: Governance Fundamentals

Key term

Stakeholder

Any party with an interest in the organization.

Module 1: Governance Fundamentals

Key term

Risk Tolerance

Acceptable deviation from risk appetite.

Module 1: Governance Fundamentals

Key term

Strategic Objective

High-level goal aligned with the organization's mission.

Module 1: Governance Fundamentals

Memory trick

Organizational Governance & ERM Principles

To remember the ERM process, think: 'I Eat Risk Regularly, So Control It, Monitor Always!' (Internal Environment, Event Identification, Risk Assessment, Risk Response, Control Activities, Information/Communication, Monitoring Activities, Always Objective Setting)

Module 1: Governance Fundamentals

Exam tip

Organizational Governance & ERM Principles

The exam often tests the relationship between governance and ERM. Look for questions asking how governance provides direction for risk management, or how ERM supports strategic objectives set by governance. Keywords like 'board oversight,' 'strategic alignment,' and 'risk appetite definition' are strong indicators.

Module 1: Governance Fundamentals

Common mistake

Organizational Governance & ERM Principles

Confusing governance with management: Governance provides direction; management executes.

Module 1: Governance Fundamentals

Common mistake

Organizational Governance & ERM Principles

Treating ERM as a separate, siloed function rather than integrated across the enterprise.

Module 1: Governance Fundamentals

Common mistake

Organizational Governance & ERM Principles

Failing to align risk management activities with the organization's strategic objectives and risk appetite.

Module 1: Governance Fundamentals

Key term

Risk Culture

Shared attitudes, values, and behaviors regarding risk.

Module 1: Governance Fundamentals

Key term

First Line of Defense

Operational management owning and managing risks.

Module 1: Governance Fundamentals

Key term

Second Line of Defense

Risk management and compliance functions overseeing risks.

Module 1: Governance Fundamentals

Key term

Third Line of Defense

Internal Audit providing independent assurance.

Module 1: Governance Fundamentals

Key term

Tone at the Top

Leadership's commitment to ethical and risk-aware behavior.

Module 1: Governance Fundamentals

Memory trick

Roles, Responsibilities & Risk Culture

Remember the '3 Lines of Defense' like a castle: The guards (line management) are on the walls, the general (risk management) plans defenses, and the king's advisor (internal audit) checks everything.

Module 1: Governance Fundamentals

Exam tip

Roles, Responsibilities & Risk Culture

The exam frequently distinguishes between the Board's oversight role (setting appetite) and executive management's implementation role (executing the framework). Pay attention to keywords like 'establish,' 'approve,' 'oversee' for the Board, and 'implement,' 'manage,' 'execute' for executive management.

Module 1: Governance Fundamentals

Common mistake

Roles, Responsibilities & Risk Culture

Confusing the Board's strategic oversight with executive management's operational implementation.

Module 1: Governance Fundamentals

Common mistake

Roles, Responsibilities & Risk Culture

Underestimating the importance of line management as the 'first line' of risk defense.

Module 1: Governance Fundamentals

Common mistake

Roles, Responsibilities & Risk Culture

Believing risk culture is just about policies, rather than shared behaviors and values.

Module 1: Governance Fundamentals

Key term

Law

A system of rules enforced by government.

Module 1: Governance Fundamentals

Key term

Regulation

A rule or directive made and maintained by an authority.

Module 1: Governance Fundamentals

Key term

Policy

A high-level internal statement of intent.

Module 1: Governance Fundamentals

Key term

Standard

A mandatory requirement for implementing policies.

Module 1: Governance Fundamentals

Key term

Procedure

Detailed step-by-step instructions for tasks.

Module 1: Governance Fundamentals

Key term

Ethics

Moral principles guiding behavior and decision-making.

Module 1: Governance Fundamentals

Key term

Compliance

Adherence to rules, regulations, and laws.

Module 1: Governance Fundamentals

Key term

GDPR

General Data Protection Regulation (EU data privacy law).

Module 1: Governance Fundamentals

Memory trick

Legal, Regulatory, Ethics & Policies

L-R-P-S: Laws Rule People's Systems! (Laws, Regulations, Policies, Standards)

Module 1: Governance Fundamentals

Exam tip

Legal, Regulatory, Ethics & Policies

The exam frequently tests your understanding of the hierarchy of governance documents. Be prepared to distinguish between laws, regulations, policies, and procedures. Keywords like 'mandatory external,' 'internal high-level,' and 'step-by-step' are key.

Module 1: Governance Fundamentals

Common mistake

Legal, Regulatory, Ethics & Policies

Confusing a policy (what to do) with a procedure (how to do it).

Module 1: Governance Fundamentals

Common mistake

Legal, Regulatory, Ethics & Policies

Assuming legal compliance automatically means ethical behavior.

Module 1: Governance Fundamentals

Common mistake

Legal, Regulatory, Ethics & Policies

Failing to regularly review and update policies and controls as laws and regulations change.

Module 1: Governance Fundamentals

Key term

Business Acumen

Understanding business operations, goals, and strategic context.

Module 1: Governance Fundamentals

Key term

Strategic Alignment

Ensuring risk management supports organizational objectives.

Module 1: Governance Fundamentals

Key term

Business Case

Document justifying an investment with costs and benefits.

Module 1: Governance Fundamentals

Key term

Business Process

Structured activities to achieve an organizational goal.

Module 1: Governance Fundamentals

Key term

Value Proposition

The unique value an initiative brings to the organization.

Module 1: Governance Fundamentals

Key term

Cost-Benefit Analysis

Comparing project costs to its potential benefits.

Module 1: Governance Fundamentals

Memory trick

Business Acumen & Strategic Alignment

To remember the importance of business acumen: 'CRISC professionals need C.A.S.H.' — Context, Acumen, Strategy, and How it impacts the business.

Module 1: Governance Fundamentals

Exam tip

Business Acumen & Strategic Alignment

The CRISC exam frequently tests your ability to connect risk management directly to business outcomes. Look for questions that ask how a risk professional should communicate with leadership or justify an investment; the answer will almost always involve business value, strategic alignment, or financial impact.

Module 1: Governance Fundamentals

Common mistake

Business Acumen & Strategic Alignment

Focusing solely on technical details without considering business impact.

Module 1: Governance Fundamentals

Common mistake

Business Acumen & Strategic Alignment

Communicating risks using only technical jargon to non-technical stakeholders.

Module 1: Governance Fundamentals

Common mistake

Business Acumen & Strategic Alignment

Proposing risk solutions without a clear business case or justification.

Module 1: Governance Fundamentals

Key term

Threat

Potential cause of an unwanted incident, resulting in harm to a system or organization.

Module 2: IT Risk Identification & Analysis

Key term

Vulnerability

Weakness that can be exploited by a threat source to cause harm.

Module 2: IT Risk Identification & Analysis

Key term

Impact

Result of an unwanted incident, causing harm to organizational objectives.

Module 2: IT Risk Identification & Analysis

Key term

Threat Landscape

Aggregate of all potential threats and vulnerabilities an organization faces.

Module 2: IT Risk Identification & Analysis

Key term

Exploit

Mechanism used to take advantage of a vulnerability.

Module 2: IT Risk Identification & Analysis

Memory trick

Identifying IT Risks & Threat Landscape

To remember the components of risk, think 'TV-I': Threat, Vulnerability, Impact. If you're missing any 'channel,' you don't have a complete 'picture' of the risk.

Module 2: IT Risk Identification & Analysis

Exam tip

Identifying IT Risks & Threat Landscape

The CRISC exam frequently tests your ability to distinguish between threats, vulnerabilities, and risks. Remember that a risk only exists when a threat can exploit a vulnerability to cause an impact. Keywords like 'potential cause' (threat) vs. 'weakness' (vulnerability) vs. 'likelihood x impact' (risk) are critical.

Module 2: IT Risk Identification & Analysis

Common mistake

Identifying IT Risks & Threat Landscape

Confusing a threat with a vulnerability: A threat is the 'bad actor' or event, while a vulnerability is the 'open door' they can use.

Module 2: IT Risk Identification & Analysis

Common mistake

Identifying IT Risks & Threat Landscape

Failing to consider internal threats: Many significant risks originate from within the organization, whether malicious or accidental.

Module 2: IT Risk Identification & Analysis

Common mistake

Identifying IT Risks & Threat Landscape

Ignoring the dynamic nature of the threat landscape: What was safe yesterday might be vulnerable today due to new exploits or technologies.

Module 2: IT Risk Identification & Analysis

Key term

Qualitative Risk Analysis

Categorizes and ranks risks using descriptive scales.

Module 2: IT Risk Identification & Analysis

Key term

Quantitative Risk Analysis

Assigns numerical values to risks for financial assessment.

Module 2: IT Risk Identification & Analysis

Key term

Risk Matrix

Plots likelihood vs. impact for visual risk prioritization.

Module 2: IT Risk Identification & Analysis

Key term

Annualized Loss Expectancy (ALE)

Expected monetary loss from a risk over a year.

Module 2: IT Risk Identification & Analysis

Key term

Single Loss Expectancy (SLE)

Expected monetary loss from a single risk event.

Module 2: IT Risk Identification & Analysis

Key term

Annualized Rate of Occurrence (ARO)

Estimated frequency of a risk event per year.

Module 2: IT Risk Identification & Analysis

Key term

Risk Evaluation

Comparing analyzed risks against established criteria.

Module 2: IT Risk Identification & Analysis

Key term

Business Impact Analysis (BIA)

Identifies critical business functions and their recovery needs.

Module 2: IT Risk Identification & Analysis

Memory trick

IT Risk Analysis and Evaluation Techniques

To remember the quantitative formula: 'S.A.L.E.' - Single (Loss Expectancy) x Annualized (Rate of Occurrence) = Loss Expectancy (Annualized).

Module 2: IT Risk Identification & Analysis

Exam tip

IT Risk Analysis and Evaluation Techniques

The CRISC exam frequently tests your understanding of when to apply qualitative versus quantitative analysis. Look for keywords like 'initial assessment,' 'limited data,' or 'high-level' for qualitative. For quantitative, keywords include 'financial justification,' 'cost-benefit,' 'ROI,' or 'specific monetary loss.'

Module 2: IT Risk Identification & Analysis

Common mistake

IT Risk Analysis and Evaluation Techniques

Confusing qualitative and quantitative analysis and using the wrong method for a given scenario.

Module 2: IT Risk Identification & Analysis

Common mistake

IT Risk Analysis and Evaluation Techniques

Failing to define clear risk criteria before starting risk evaluation, leading to inconsistent prioritization.

Module 2: IT Risk Identification & Analysis

Common mistake

IT Risk Analysis and Evaluation Techniques

Over-relying on a single analysis technique instead of combining methods for a comprehensive view.

Module 2: IT Risk Identification & Analysis

Key term

Risk Scenario

A narrative describing a potential event and its impact.

Module 2: IT Risk Identification & Analysis

Key term

Actor

The entity initiating a risk event.

Module 2: IT Risk Identification & Analysis

Key term

Top-Down Approach

Risk scenario development from objectives to risks.

Module 2: IT Risk Identification & Analysis

Key term

Bottom-Up Approach

Risk scenario development from threats/assets.

Module 2: IT Risk Identification & Analysis

Key term

OCTAVE

A risk assessment framework for scenario development.

Module 2: IT Risk Identification & Analysis

Memory trick

Developing Effective Risk Scenarios

To remember the key components, think: 'A T V E I A C' – Actor, Threat, Vulnerability, Event, Impact, Asset, Controls. Like 'A TV EATS A Carrot'!

Module 2: IT Risk Identification & Analysis

Exam tip

Developing Effective Risk Scenarios

The CRISC exam emphasizes that risk scenarios must be specific enough to enable effective risk response planning and resource allocation. Look for keywords like 'actionable,' 'quantifiable,' and 'business impact.'

Module 2: IT Risk Identification & Analysis

Common mistake

Developing Effective Risk Scenarios

Creating scenarios that are too vague or generic, making them difficult to act upon.

Module 2: IT Risk Identification & Analysis

Common mistake

Developing Effective Risk Scenarios

Focusing only on technical details without linking them to business impact and objectives.

Module 2: IT Risk Identification & Analysis

Common mistake

Developing Effective Risk Scenarios

Developing scenarios for highly improbable events, wasting resources on low-priority risks.

Module 2: IT Risk Identification & Analysis

Key term

IT Risk Register

Central repository for identified IT risks and their management details.

Module 2: IT Risk Identification & Analysis

Key term

Risk Owner

Individual accountable for managing a specific risk and its treatment.

Module 2: IT Risk Identification & Analysis

Key term

Key Risk Indicator (KRI)

Metric used to provide an early warning of increasing risk exposure.

Module 2: IT Risk Identification & Analysis

Key term

Risk Mitigation

Actions taken to reduce the likelihood or impact of a risk.

Module 2: IT Risk Identification & Analysis

Key term

Risk Status

Current state of a risk (e.g., Open, In Progress, Closed).

Module 2: IT Risk Identification & Analysis

Key term

Risk Treatment

Overall process of modifying risk, including mitigation, transfer, acceptance.

Module 2: IT Risk Identification & Analysis

Memory trick

Maintaining the IT Risk Register

To remember the key elements of a risk register entry, think: 'RID-COPS'. Risk ID, Impact, Description, Control, Owner, Probability (Likelihood), Status.

Module 2: IT Risk Identification & Analysis

Exam tip

Maintaining the IT Risk Register

The exam often tests the dynamic nature of the risk register. Look for questions emphasizing continuous monitoring, regular updates, and the role of KRIs in proactive risk management. Remember, it's a 'living document,' not a static report.

Module 2: IT Risk Identification & Analysis

Common mistake

Maintaining the IT Risk Register

Treating the risk register as a static document that is rarely updated.

Module 2: IT Risk Identification & Analysis

Common mistake

Maintaining the IT Risk Register

Failing to assign clear ownership for each identified risk.

Module 2: IT Risk Identification & Analysis

Common mistake

Maintaining the IT Risk Register

Not linking mitigation actions directly to specific risks in the register.

Module 2: IT Risk Identification & Analysis

Key term

Risk Avoidance

Eliminating a risk by ceasing the activity that causes it.

Module 3: Risk Response & Control

Key term

Risk Transfer

Shifting the financial consequences of a risk to a third party.

Module 3: Risk Response & Control

Key term

Risk Acceptance

Consciously deciding to take no action against a risk.

Module 3: Risk Response & Control

Key term

Residual Risk

The risk remaining after risk response actions have been taken.

Module 3: Risk Response & Control

Memory trick

Strategies for IT Risk Response

Remember the 4 T's of Risk Response: Terminate (Avoid), Treat (Mitigate), Transfer, Tolerate (Accept).

Module 3: Risk Response & Control

Exam tip

Strategies for IT Risk Response

The CRISC exam frequently tests your ability to distinguish between risk avoidance and risk mitigation. Remember: avoidance eliminates the source of risk, while mitigation reduces its impact or likelihood. Look for keywords like 'stop the activity' for avoidance and 'implement controls' for mitigation.

Module 3: Risk Response & Control

Common mistake

Strategies for IT Risk Response

Confusing risk avoidance with risk mitigation; avoidance eliminates the activity, mitigation reduces the risk within the activity.

Module 3: Risk Response & Control

Common mistake

Strategies for IT Risk Response

Accepting a risk by default due to inaction, rather than through a conscious, documented decision.

Module 3: Risk Response & Control

Common mistake

Strategies for IT Risk Response

Failing to consider residual risk after implementing a response strategy.

Module 3: Risk Response & Control

Key term

Risk Ownership

Individual/entity with primary responsibility for managing a specific risk.

Module 3: Risk Response & Control

Key term

Accountability

Obligation to answer for results of actions, including control effectiveness.

Module 3: Risk Response & Control

Key term

Control Ownership

Individual/team responsible for specific control design, implementation, and operation.

Module 3: Risk Response & Control

Key term

Risk Register

Document listing identified risks, their owners, and mitigation strategies.

Module 3: Risk Response & Control

Memory trick

Risk and Control Ownership & Accountability

O-A-C: Owners are Accountable for Controls. The 'O' (Owner) is the big picture, the 'A' (Accountable) is the ultimate responsibility, and 'C' (Controls) are the tools they use.

Module 3: Risk Response & Control

Exam tip

Risk and Control Ownership & Accountability

The CRISC exam frequently tests the distinction between 'risk owner' and 'control owner.' Remember that the risk owner is typically a business function, while the control owner is often an operational or technical team.

Module 3: Risk Response & Control

Common mistake

Risk and Control Ownership & Accountability

Confusing risk ownership with control ownership.

Module 3: Risk Response & Control

Common mistake

Risk and Control Ownership & Accountability

Assigning risk ownership to a technical team instead of a business unit.

Module 3: Risk Response & Control

Common mistake

Risk and Control Ownership & Accountability

Failing to clearly document who owns which risk and control.

Module 3: Risk Response & Control

Key term

Preventive Control

Stops an undesirable event from occurring.

Module 3: Risk Response & Control

Key term

Detective Control

Identifies an event after it has occurred.

Module 3: Risk Response & Control

Key term

Corrective Control

Minimizes impact and restores normal operations.

Module 3: Risk Response & Control

Key term

Control Effectiveness

The degree to which a control achieves its objective.

Module 3: Risk Response & Control

Key term

Control Automation

Using technology to perform control activities.

Module 3: Risk Response & Control

Key term

Control Integration

Ensuring controls work together seamlessly.

Module 3: Risk Response & Control

Key term

Proportionality

Control cost and effort should match risk level.

Module 3: Risk Response & Control

Memory trick

Designing & Implementing Effective Controls

P-D-C: 'Please Don't Crash!' P-reventive, D-etective, C-orrective. Remember the order of defense!

Module 3: Risk Response & Control

Exam tip

Designing & Implementing Effective Controls

On the exam, pay close attention to scenarios describing control failures. Identify whether the failure was due to poor design (e.g., not appropriate), poor implementation (e.g., not tested), or poor operation (e.g., not maintained). Keywords like 'before the event,' 'after the event,' and 'restore' are critical for distinguishing control types.

Module 3: Risk Response & Control

Common mistake

Designing & Implementing Effective Controls

Implementing controls without proper testing, leading to unforeseen vulnerabilities or operational disruptions.

Module 3: Risk Response & Control

Common mistake

Designing & Implementing Effective Controls

Designing controls that are too complex or burdensome, causing users to find workarounds that negate their effectiveness.

Module 3: Risk Response & Control

Common mistake

Designing & Implementing Effective Controls

Failing to integrate controls with existing processes or other controls, creating security gaps or redundancies.

Module 3: Risk Response & Control

Key term

Continuous Control Monitoring (CCM)

Ongoing process to ensure controls operate effectively.

Module 3: Risk Response & Control

Key term

Control Reporting

Communicating control performance to stakeholders.

Module 3: Risk Response & Control

Key term

Control Documentation

Written records describing control details.

Module 3: Risk Response & Control

Key term

Control Self-Assessment

Periodic review of controls by process owners.

Module 3: Risk Response & Control

Key term

SIEM

Security Information and Event Management system.

Module 3: Risk Response & Control

Key term

GRC Platform

Software for managing governance, risk, and compliance.

Module 3: Risk Response & Control

Key term

Performance Metrics

Quantifiable measures of control effectiveness.

Module 3: Risk Response & Control

Memory trick

Monitoring, Reporting & Documenting Controls

MR. DOC: Monitor, Report, Document Controls. Like a doctor who checks your health regularly and keeps records!

Module 3: Risk Response & Control

Exam tip

Monitoring, Reporting & Documenting Controls

The CRISC exam often emphasizes the 'continuous' aspect of monitoring. Look for questions that highlight the dynamic nature of risk and the need for ongoing evaluation, not just point-in-time assessments. Remember that reporting must be 'actionable' and 'tailored' to the audience.

Module 3: Risk Response & Control

Common mistake

Monitoring, Reporting & Documenting Controls

Assuming controls, once implemented, will always remain effective without ongoing monitoring.

Module 3: Risk Response & Control

Common mistake

Monitoring, Reporting & Documenting Controls

Providing generic control reports to all stakeholders instead of tailoring the information to their specific needs.

Module 3: Risk Response & Control

Common mistake

Monitoring, Reporting & Documenting Controls

Neglecting to update control documentation when processes or systems change, leading to outdated and misleading information.

Module 3: Risk Response & Control

Key term

Hardware

Physical components of an IT system, like servers or network devices.

Module 4: IT & Security Foundations

Key term

Software

Programs and data that instruct hardware, including OS and applications.

Module 4: IT & Security Foundations

Key term

Operating System (OS)

Software that manages computer hardware and software resources.

Module 4: IT & Security Foundations

Key term

Network

Interconnected devices that can share resources and exchange data.

Module 4: IT & Security Foundations

Key term

Cloud Computing

Delivery of on-demand computing services over the Internet.

Module 4: IT & Security Foundations

Key term

IaaS

Infrastructure as a Service; provides virtualized computing resources.

Module 4: IT & Security Foundations

Key term

PaaS

Platform as a Service; provides a platform for developing applications.

Module 4: IT & Security Foundations

Key term

SaaS

Software as a Service; delivers ready-to-use applications over the internet.

Module 4: IT & Security Foundations

Memory trick

Core Information Technology Concepts

Hardware is Hard, Software is Soft. Hard you can touch (server), Soft you can't (program).

Module 4: IT & Security Foundations

Exam tip

Core Information Technology Concepts

The CRISC exam often tests your ability to apply IT concepts to risk scenarios. Pay close attention to how different IT components (hardware, software, network, cloud) introduce specific risks and require distinct controls. For example, understand that a SaaS model shifts much of the infrastructure risk to the vendor, but introduces vendor lock-in and data residency risks for the consumer.

Module 4: IT & Security Foundations

Common mistake

Core Information Technology Concepts

Confusing the responsibilities in IaaS, PaaS, and SaaS models; remember the shared responsibility model.

Module 4: IT & Security Foundations

Common mistake

Core Information Technology Concepts

Underestimating the impact of network latency or bandwidth on application performance and user experience.

Module 4: IT & Security Foundations

Common mistake

Core Information Technology Concepts

Overlooking the security implications of data stored in different locations (on-premise vs. cloud).

Module 4: IT & Security Foundations

Key term

CIA Triad

Confidentiality, Integrity, Availability: core security principles.

Module 4: IT & Security Foundations

Key term

Confidentiality

Preventing unauthorized disclosure of information.

Module 4: IT & Security Foundations

Key term

Integrity

Ensuring data is accurate, complete, and unaltered.

Module 4: IT & Security Foundations

Key term

Availability

Ensuring systems and data are accessible when needed.

Module 4: IT & Security Foundations

Key term

NIST CSF

National Institute of Standards and Technology Cybersecurity Framework.

Module 4: IT & Security Foundations

Key term

ISO/IEC 27001

International standard for Information Security Management Systems.

Module 4: IT & Security Foundations

Key term

Security Control

Safeguard or countermeasure to reduce identified risks.

Module 4: IT & Security Foundations

Key term

Non-repudiation

Proof that an action occurred and cannot be denied.

Module 4: IT & Security Foundations

Memory trick

Information Security Principles & Frameworks

To remember the CIA Triad: 'C' is for C-overt (secret), 'I' is for I-dentical (unchanged), 'A' is for A-lways there.

Module 4: IT & Security Foundations

Exam tip

Information Security Principles & Frameworks

The CRISC exam frequently tests your understanding of the CIA Triad and how different security controls map to these principles. Be prepared to identify which principle is being addressed by a given control (e.g., encryption for confidentiality). Also, know the primary purpose of major frameworks like NIST CSF (risk-based guidance) and ISO 27001 (ISMS certification).

Module 4: IT & Security Foundations

Common mistake

Information Security Principles & Frameworks

Confusing confidentiality with integrity; they both deal with data, but confidentiality is about who sees it, integrity is about its accuracy.

Module 4: IT & Security Foundations

Common mistake

Information Security Principles & Frameworks

Assuming one security framework fits all organizations; the best framework depends on specific needs and context.

Module 4: IT & Security Foundations

Common mistake

Information Security Principles & Frameworks

Forgetting that availability is just as important as confidentiality and integrity; a secure system that can't be used is useless.

Module 4: IT & Security Foundations

Key term

IT Operations

Daily activities managing IT infrastructure and services.

Module 4: IT & Security Foundations

Key term

Project Management

Applying processes to achieve specific project objectives.

Module 4: IT & Security Foundations

Key term

Incident Management

Restoring normal service operation as quickly as possible.

Module 4: IT & Security Foundations

Key term

Problem Management

Identifying and resolving the root cause of incidents.

Module 4: IT & Security Foundations

Key term

Change Management

Controlling changes to IT infrastructure and services.

Module 4: IT & Security Foundations

Key term

Service Level Agreement (SLA)

Contract defining service expectations and responsibilities.

Module 4: IT & Security Foundations

Key term

Waterfall Methodology

Sequential project approach, phases complete before next.

Module 4: IT & Security Foundations

Key term

Agile Methodology

Iterative and incremental project approach, flexible.

Module 4: IT & Security Foundations

Memory trick

IT Operations & Project Management

To remember the core ITIL operational processes: I P C S. 'I'ncident, 'P'roblem, 'C'hange, 'S'ervice Level. 'I P C S' - 'I Protect Critical Systems'.

Module 4: IT & Security Foundations

Exam tip

IT Operations & Project Management

The exam often tests your understanding of how project management methodologies (e.g., Waterfall vs. Agile) impact risk, and how operational processes (e.g., incident vs. problem management) contribute to overall risk posture. Look for keywords like 'root cause' for problem management.

Module 4: IT & Security Foundations

Common mistake

IT Operations & Project Management

Confusing incident management (restoring service) with problem management (root cause analysis).

Module 4: IT & Security Foundations

Common mistake

IT Operations & Project Management

Underestimating the importance of change management in preventing operational risks.

Module 4: IT & Security Foundations

Common mistake

IT Operations & Project Management

Failing to integrate risk assessments into both project planning and operational reviews.

Module 4: IT & Security Foundations

Key term

Disaster Recovery (DR)

Restoring IT systems and infrastructure after a disruptive event.

Module 4: IT & Security Foundations

Key term

Business Continuity (BC)

Organization's ability to maintain essential functions during disruptions.

Module 4: IT & Security Foundations

Key term

Recovery Time Objective (RTO)

Maximum acceptable downtime for a system or process.

Module 4: IT & Security Foundations

Key term

Recovery Point Objective (RPO)

Maximum acceptable data loss measured in time.

Module 4: IT & Security Foundations

Key term

Hot Site

Fully equipped, operational recovery facility for immediate use.

Module 4: IT & Security Foundations

Key term

Warm Site

Partially equipped recovery facility requiring some setup.

Module 4: IT & Security Foundations

Key term

Cold Site

Basic facility with infrastructure, no equipment or data.

Module 4: IT & Security Foundations

Memory trick

Disaster Recovery & Business Continuity

To remember the difference: DR is about getting the 'D'ata and 'R'esources back online. BC is about keeping the 'B'usiness 'C'ontinuing, no matter what.

Module 4: IT & Security Foundations

Exam tip

Disaster Recovery & Business Continuity

The CRISC exam often tests the distinction between DR and BC, and the roles of RTO/RPO. Remember that BC is broader and includes DR. A BIA is always the starting point for both.

Module 4: IT & Security Foundations

Common mistake

Disaster Recovery & Business Continuity

Confusing DR solely with BC; DR is a subset of BC.

Module 4: IT & Security Foundations

Common mistake

Disaster Recovery & Business Continuity

Failing to regularly test and update DRPs and BC plans.

Module 4: IT & Security Foundations

Common mistake

Disaster Recovery & Business Continuity

Not conducting a thorough BIA, leading to incorrect RTO/RPO settings.

Module 4: IT & Security Foundations