|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/is-risk-and-control-exams-in-2025/
课程评论:没有评论
课程名称:IS风险与控制 - 2025年考试 课程概述: IS风险与控制认证将使您成为风险管理的专家。本课程采用敏捷方法论的积极 approach,学习内容旨在增强公司业务的韧性、提供利益相关者的价值,并优化企业范围内的风险管理。 课程内容简介: 1. **治理领域(26%)** - 本领域审视您对组织商业和IT环境的信息、组织战略及目标的理解,并评估IT风险对组织业务目标和运营的潜在或已实现影响,包括企业风险管理及风险管理框架。 - 主要内容包括:组织治理、企业风险管理、法律和合规要求、风险承受能力等。 2. **IT风险评估(20%)** - 本领域验证您对组织员工、过程和技术的威胁与脆弱性的知识,以及威胁、脆弱性和风险场景的可能性和影响。 - 主要内容涵盖IT风险识别、风险分析和评估方法、业务影响分析等。 3. **风险响应与报告(32%)** - 本领域关注关键利益相关者之间风险处理计划的开发与管理、现有控制的评估和有效性改进,以及相关风险与控制信息的评估。 - 主要包括风险响应选项、控制设计与实施、风险监控与报告技术等。 4. **信息技术与安全(22%)** - 本领域考察业务实践与风险管理及信息安全框架和标准的一致性,培养风险意识文化并实施安全意识培训。 - 主要内容包括企业架构、信息安全原则、数据隐私和保护原则等。 通过本课程的学习,参与者将能掌握关键的风险管理知识,为提高组织的业务韧性、优化风险管理以及提升利益相关者的价值作出贡献。
IS Risk and Control IS Risk and Control certification will make you a Risk Management expert. Studying a proactive approach based on Agile methodology, you'll learn how to enhance your company's business resilience, deliver stakeholder value and optimize Risk Management across the enterprise.26% DOMAIN 1 - GOVERNANCEThe governance domain interrogates your knowledge of information about an organization's business and IT environments, organizational strategy, goals and objectives, and examines potential or realized impacts of IT risk to the organization's business objectives and operations, including Enterprise Risk Management and Risk Management Framework.A-ORGANIZATIONAL GOVERNANCEOrganizational Strategy, Goals, and ObjectivesOrganizational Structure, Roles and ResponsibilitiesOrganizational CulturePolicies and StandardsBusiness ProcessesOrganizational AssetsB-RISK GOVERNANCEEnterprise Risk Management and Risk Management FrameworkThree Lines of DefenseRisk ProfileRisk Appetite and Risk ToleranceLegal, Regulatory and Contractual RequirementsProfessional Ethics of Risk Management20% DOMAIN 2 - IT RISK ASSESSMENTThis domain will certify your knowledge of threats and vulnerabilities to the organization's people, processes and technology as well as the likelihood and impact of threats, vulnerabilities and risk scenarios.A-IT RISK IDENTIFICATIONRisk Events (e.g., contributing conditions, loss result)Threat Modelling and Threat LandscapeVulnerability and Control Deficiency Analysis (e.g., root cause analysis)Risk Scenario DevelopmentB-IT RISK ANALYSIS AND EVALUATIONRisk Assessment Concepts, Standards and FrameworksRisk RegisterRisk Analysis MethodologiesBusiness Impact AnalysisInherent and Residual Risk32% DOMAIN 3 - RISK RESPONSE AND REPORTINGThis domain deals with the development and management of risk treatment plans among key stakeholders, the evaluation of existing controls and improving effectiveness for IT risk mitigation, and the assessment of relevant risk and control information to applicable stakeholders.A-RISK RESPONSERisk Treatment / Risk Response OptionsRisk and Control OwnershipThird-Party Risk ManagementIssue, Finding and Exception ManagementManagement of Emerging RiskB-CONTROL DESIGN AND IMPLEMENTATIONControl Types, Standards and FrameworksControl Design, Selection and AnalysisControl ImplementationControl Testing and Effectiveness EvaluationC-RISK MONITORING AND REPORTINGRisk Treatment PlansData Collection, Aggregation, Analysis and ValidationRisk and Control Monitoring TechniquesRisk and Control Reporting Techniques (heatmap, scorecards, dashboards)Key Performance IndicatorsKey Risk Indicators (KRIs)Key Control Indicators (KCIs)22% DOMAIN 4 - INFORMATION TECHNOLOGY AND SECURITYIn this domain we interrogate the alignment of business practices with Risk Management and Information Security frameworks and standards, as well as the development of a risk-aware culture and implementation of security awareness training.A-INFORMATION TECHNOLOGY PRINCIPLESEnterprise ArchitectureIT Operations Management (e.g., change management, IT assets, problems, incidents)Project ManagementDisaster Recovery Management (DRM)Data Lifecycle ManagementSystem Development Life Cycle (SDLC)Emerging TechnologiesB-INFORMATION SECURITY PRINCIPLESInformation Security Concepts, Frameworks and StandardsInformation Security Awareness TrainingBusiness Continuity ManagementData Privacy and Data Protection Principles