ISACA,a global association of 86,000 IT audit,risk,governance and security professionals,is all set to introduce a new risk-related certification.
The Certified in Risk and Information Systems Control (CRISC) label is for IT professionals who identify and manage risks through the development,implementation and maintenance of information systems (IS) controls.
These professionals help firms achieve business goals ranging from effective and proficient operations,reliable financial reporting to compliance with regulatory requirements.
A grandfathering program,through which professionals with experience can earn the certification without passing an exam,will start in April. The first CRISC exam will be administered in 2011.
ISACA established CRISC (pronounced see risk) to recognize IT professionals with skills and abilities related to:
*Risk identification,assessment and evaluation
*Risk response
*Risk monitoring
*Information Systems control design & implementation
*Information Systems control monitoring & maintenance
The CRISC label will demonstrate to the prospective employers that the certificate holder is able to identify and evaluate the risks unique to the specific requirements of their organisation and help the company accomplish its business objectives by designing,implementing,monitoring and maintaining risk-based,efficient and effective IS controls, said Urs Fischer,chair of ISACAs CRISC Task Force.
We conducted an extensive amount of research globally and found that enterprises are becoming more risk-aware and are looking to identify professionals who possess the skills to help them protect their assets and enhance their businesses, Fischer elaborated.
CRISC complements ISACAs already existing certifications: Certified Information Systems Auditor (CISA) established in 1978 and earned by more than 70,000 professionals since its inception. Certified Information Security Manager (CISM),earned by more than 12,000 professionals since it was launched in 2002,and of late the Certified in the Governance of Enterprise IT (CGEIT),earned by more than 4,000 professionals since it was developed in 2006.
CISA is designed for IT professionals who perform independent reviews of control design and operational effectiveness. CRISC is for IT and business professionals who design,implement and maintain IS controls while CISM is for individuals who manage,design,oversee and/or assess an enterprises information security,including the identification and management of information security risks.
CGEIT is for IT and business professionals who have a significant management,advisory or assurance role relating to the governance of IT.
CRISC is for IT professionals whose roles also encompass operational and compliance considerations.
About ISACA
With more than 86,000 constituents in more than 160 countries,ISACA is a leading global provider of knowledge,certifications,community,advocacy and education on information systems assurance and security,enterprise governance of IT,and IT-related risk and compliance. Founded in 1969,ISACA sponsors international conferences,publishes the ISACA Journal,and develops international information systems auditing and control standards.
It also administers the globally respected Certified Information Systems Auditor (CISA),Certified Information Security Manager (CISM),Certified in the Governance of Enterprise IT (CGEIT) and Certified in Risk and Information Systems Control (CRISC) designations.




