EVIDENCE · NOT SCORES
SIGN IN
← ALL CERTIFICATIONS

ISC2

Certified in Governance, Risk and Compliance

CERTIFIED IN GOVERNANCE, RISK AND COMPLIANCEEXAM CGRCBLUEPRINT CGRC-JUNE-2024

BUILD MY CERTIFICATION PATH

EXAM BLUEPRINT

The published domains and objectives for CGRC. Your missions come from these objectives, and your progress is recorded against them.

  • 16%

    1

    Security and Privacy Governance, Risk Management, and Compliance Program

    • 1.1Demonstrate knowledge in security and privacy governance, risk management, and compliance program
    • 1.2Demonstrate knowledge in security and privacy governance, risk management and compliance program processes
    • 1.3Demonstrate knowledge of compliance frameworks, regulations, privacy, and security requirements
  • 10%

    2

    Scope of the System

    • 2.1Describe the system
    • 2.2Determine security compliance required
  • 14%

    3

    Selection and Approval of Framework, Security, and Privacy Controls

    • 3.1Identify and document baseline and inherited controls
    • 3.2Select and tailor controls
  • 17%

    4

    Implementation of Security and Privacy Controls

    • 4.1Develop implementation strategy (e.g., resourcing, funding, timeline, effectiveness)
    • 4.2Implement selected controls
    • 4.3Document control implementation
  • 16%

    5

    Assessment/Audit of Security and Privacy Controls

    • 5.1Prepare for assessment/audit
    • 5.2Conduct assessment/audit
    • 5.3Prepare the initial assessment/audit report
    • 5.4Review initial assessment/audit report and plan risk response actions
    • 5.5Develop final assessment/audit report
    • 5.6Develop risk response plan
  • 14%

    6

    System Compliance

    • 6.1Review and submit security/privacy documents
    • 6.2Determine system risk posture
    • 6.3Document system compliance
  • 13%

    7

    Compliance Maintenance

    • 7.1Perform system change management
    • 7.2Perform ongoing compliance activities based on requirements
    • 7.3Engage in audits activities based on compliance requirements
    • 7.4Decommission system when applicable