EVIDENCE · NOT SCORES
SIGN IN← ALL CERTIFICATIONS
ISC2
Certified in Governance, Risk and Compliance
CERTIFIED IN GOVERNANCE, RISK AND COMPLIANCEEXAM CGRCBLUEPRINT CGRC-JUNE-2024
EXAM BLUEPRINT
The published domains and objectives for CGRC. Your missions come from these objectives, and your progress is recorded against them.
16%
1
Security and Privacy Governance, Risk Management, and Compliance Program
- 1.1Demonstrate knowledge in security and privacy governance, risk management, and compliance program
- 1.2Demonstrate knowledge in security and privacy governance, risk management and compliance program processes
- 1.3Demonstrate knowledge of compliance frameworks, regulations, privacy, and security requirements
10%
2
Scope of the System
- 2.1Describe the system
- 2.2Determine security compliance required
14%
3
Selection and Approval of Framework, Security, and Privacy Controls
- 3.1Identify and document baseline and inherited controls
- 3.2Select and tailor controls
17%
4
Implementation of Security and Privacy Controls
- 4.1Develop implementation strategy (e.g., resourcing, funding, timeline, effectiveness)
- 4.2Implement selected controls
- 4.3Document control implementation
16%
5
Assessment/Audit of Security and Privacy Controls
- 5.1Prepare for assessment/audit
- 5.2Conduct assessment/audit
- 5.3Prepare the initial assessment/audit report
- 5.4Review initial assessment/audit report and plan risk response actions
- 5.5Develop final assessment/audit report
- 5.6Develop risk response plan
14%
6
System Compliance
- 6.1Review and submit security/privacy documents
- 6.2Determine system risk posture
- 6.3Document system compliance
13%
7
Compliance Maintenance
- 7.1Perform system change management
- 7.2Perform ongoing compliance activities based on requirements
- 7.3Engage in audits activities based on compliance requirements
- 7.4Decommission system when applicable