Temat: [biuletyn RISK-IT] Nowy certyfikat ISACA: The Certified...


The Certified in Risk and Information Systems Control (CRISC)

Stowarzyszenie ds. Audytu i Kontroli Systemów Informatycznych (ISACA) ogłosiło powstanie nowego certyfikatu dla osób, które zawodowo zajmują identyfikacją i zarządzaniem ryzykiem poprzez rozwój, wdrożenie i utrzymanie mechanizmów kontroli i sterowania systemów informatycznych/informacyjnych. Ci pracownicy pomagają przedsiębiorstwom osiągnąć cele biznesowe takie jak: skuteczne i efektywne działania, rzetelne raporty finansowe oraz zgodność z wymogami regulacyjnymi.

Od kwietnia 2010 doświadczeni specjaliści będą mogli otrzymać certyfikat bez egzaminu, pierwsze egzaminy CRISC (wym. 'see risk') są planowane na rok 2011. Wymagane doświadczenie i umiejęstności w dziedzinach
- identyfikacja, szacowanie i ocena ryzyka (Risk identification, assessment and evaluation)
- reakcja na ryzyko (Risk response)
- monitorowanie ryzyka (Risk monitoring)
- projektowanie i wdrożenie mechanizmów kontrolnych IS (IS control design and implementation)
- monitorowanie i utrzymanie mechanizmów kontrolnych IS (IS control monitoring and maintenance)

Informacje ISACA o CRISC (po angielsku):


Stowarzyszenie ISACA zrzesza ponad 86.000 członków na całym swiecie. CRISC będzie czwartym certyfikatem ISACA, uzupełniającym istniejące: CISA (70.000), CISM (12.000) i CGEIT (4.000 posiadaczy).

A czy są gdzieś określone zasady uzyskiwania certyfikatu bez egzaminu?
Zapewne będzie podobnie jak w przypadku CGEIT
1) 5-8 lat doświadczenia + wyższa opłata ('grandfathering')
2) 3-5 lat doświadczenia + niższa opłata + egzamin
Adres skrócony:

Myślę, że niedługo będzie tu więcej informacji :)
Pojawiły się wymagania

Requirements for CRISC Certification
1. Successful completion of the CRISC examination
2. Information systems auditing, control or security experience
3. Adherence to the Code of Professional Ethics
4. Adherence to the continuing professional education program
Pojawiły się nowe informacje:

"Certified in Risk and Information Systems Control (CRISC, pronounced “see-risk”) designation under its grandfathering program. This program is designed to recognize experienced professionals who are responsible for:
Risk identification, assessment and evaluation
Risk response
Risk monitoring
IS control design and implementation
IS control monitoring and maintenance

To earn the credential through the grandfathering program, an applicant must provide evidence of at least eight (8) years of IT or business experience with a minimum of six (6) years of cumulative work experience across all 5 CRISC domains and a minimum of three (3) years of cumulative work experience in CRISC risk domains 1, 2 and 3 (as defined and described by the CRISC job practice domains and task statements).

The grandfathering program will run from April 2010 through March 2011.

“Enterprises around the world are continuing to become more risk-aware, and the CRISC designation will provide assurance to employers that professionals who earn and maintain a CRISC certification are experienced in identifying and evaluating the risks unique to their specific organization,” said Urs Fischer, chair of ISACA’s CRISC Task Force. “It also helps risk and control professionals demonstrate that they have proven experience and abilities in designing, implementing and maintaining risk-based, efficient and effective information systems controls.”

More information will be available in time for the 1 April opening date."
I rzeczywiście ten program rusza:

"The CRISC Grandfathering Application Process

In order to be considered for CRISC certification under the grandfathering provision an applicant must:
Obtain an ISACA identification (ID) number (this will be needed for your application). If you do not currently have an ISACA ID number, to obtain one and to create a profile with ISACA, please go to
Remit (pay) the appropriate application fee.
Submit a completed CRISC application for certification under the grandfathering provision.

CRISC Application:
To download the CRISC Application under the Grandfathering Provision, visit

CRISC Grandfathering Application Fee:
The payment of an application fee is required to be considered for CRISC certification under the grandfathering provision. Your application will not be reviewed until payment in full is received.

Payment for the fee can be made online at: The amount of the fee is dependent on your ISACA membership status and the date of application. The application fee is as follows:
Member rate Nonmember rate
Application and payment received by 31 October 2010 $495 $625
Application and payment received between 1 November 2010 and 31 March 2011 $595 $725"
No się zaczęło :))

- 8 lat praktyki IT/Biznes, z czego:
- 5 lat praktyki we wszystkich domenach CRISC (1-5), z czego:
- 3 lata praktyki w zarządzaniu ryzykiem, domeny 1-3

