← Home
ISC2 · Full exam outline

CGRC

Governance, Risk and Compliance Certification

Governance, risk & complianceCore certification
1Information Security Risk Management Program16%
1.1Principles of information security risk management
1.2Risk management framework and system authorization
1.3Roles and responsibilities in the programme
1.4Risk management strategy and risk appetite
2Scope of the System11%
2.1Define the system boundary and information types
2.2Categorize the system
2.3Describe the system and record the results
3Selection and Approval of Framework, Security and Privacy Controls15%
3.1Identify and document baseline controls
3.2Tailor and supplement the control set
3.3Develop the continuous monitoring strategy
3.4Review and approve the security and privacy plan
4Implementation of Security and Privacy Controls16%
4.1Implement the selected controls
4.2Document control implementation and deviations
5Assessment/Audit of Security and Privacy Controls16%
5.1Prepare for the assessment
5.2Conduct the assessment and develop initial findings
5.3Develop and review remediation actions
5.4Produce the final assessment report
6Authorization/Approval of System10%
6.1Develop the plan of action and milestones
6.2Assemble the authorization package
6.3Determine risk and make the authorization decision
7Continuous Monitoring16%
7.1Monitor changes to the system and its environment
7.2Ongoing assessment of control effectiveness
7.3Ongoing risk determination and response
7.4Security status reporting
7.5Decommission the system
Weights are the certification body’s published values and are checked against each outline revision.