SecLeaderAcademy
← Home
ISC2 · Full exam outline
CGRC
Governance, Risk and Compliance Certification
Governance, risk & compliance
Core certification
1
Information Security Risk Management Program
16%
1.1
Principles of information security risk management
1.2
Risk management framework and system authorization
1.3
Roles and responsibilities in the programme
1.4
Risk management strategy and risk appetite
2
Scope of the System
11%
2.1
Define the system boundary and information types
2.2
Categorize the system
2.3
Describe the system and record the results
3
Selection and Approval of Framework, Security and Privacy Controls
15%
3.1
Identify and document baseline controls
3.2
Tailor and supplement the control set
3.3
Develop the continuous monitoring strategy
3.4
Review and approve the security and privacy plan
4
Implementation of Security and Privacy Controls
16%
4.1
Implement the selected controls
4.2
Document control implementation and deviations
5
Assessment/Audit of Security and Privacy Controls
16%
5.1
Prepare for the assessment
5.2
Conduct the assessment and develop initial findings
5.3
Develop and review remediation actions
5.4
Produce the final assessment report
6
Authorization/Approval of System
10%
6.1
Develop the plan of action and milestones
6.2
Assemble the authorization package
6.3
Determine risk and make the authorization decision
7
Continuous Monitoring
16%
7.1
Monitor changes to the system and its environment
7.2
Ongoing assessment of control effectiveness
7.3
Ongoing risk determination and response
7.4
Security status reporting
7.5
Decommission the system
Weights are the certification body’s published values and are checked against each outline revision.