<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CGRC vs CRISC in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/75393#M1240</link>
    <description>&lt;P&gt;I received my CGRC earlier this year. The "best" textbook is probably &lt;A href="https://csrc.nist.gov/pubs/sp/800/37/r2/final" target="_blank" rel="noopener"&gt;NIST SP 800-37&lt;/A&gt;. It's the primary reference that the CGRC is based on. ISC2 published a study guide (back when CGRC was still called CAP). It's okay, but it's over 10 years old now. See my review here: &lt;A href="https://www.goodreads.com/review/show/5971773506" target="_blank" rel="noopener"&gt;https://www.goodreads.com/review/show/5971773506&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read two other books as well, and my reviews for them are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ISO 27001/ISO 27002: A guide to information security management systems: &lt;A href="https://www.goodreads.com/review/show/6300405669" target="_blank" rel="noopener"&gt;https://www.goodreads.com/review/show/6300405669&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Information Security Risk Management for ISO 27001/ISO 27002: &lt;A href="https://www.goodreads.com/review/show/6297499126" target="_blank" rel="noopener"&gt;https://www.goodreads.com/review/show/6297499126&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;There are also some self-study aids here: &lt;A href="https://www.isc2.org/certifications/cgrc/cgrc-self-study-resources" target="_blank" rel="noopener"&gt;https://www.isc2.org/certifications/cgrc/cgrc-self-study-resources&lt;/A&gt;. The practice exam is new since I took my exam in March. The flash cards are helpful for definitions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
    <pubDate>Fri, 29 Nov 2024 14:51:16 GMT</pubDate>
    <dc:creator>jmikesmith</dc:creator>
    <dc:date>2024-11-29T14:51:16Z</dc:date>
    <item>
      <title>CGRC vs CRISC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/66693#M1068</link>
      <description>&lt;P&gt;Hi all, looking for opinions and advice on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking for a risk management certification that will help me develop my risk assessment and risk reporting skills. I looked at the CGRC because I already hold some ISC2 certs (CISSP, SSCP, CISSP) and keeping things "in house" made sense from a CPE and membership fee perspective. However, from looking at the limited information on the domains, it looks like the CGRC will go through the steps to conduct a risk assessment of a system, select controls, implementation of remediations, and monitoring; but doesn't look at risk management as an overall function and, specifically, risk and control reporting techniques.&lt;/P&gt;&lt;P&gt;My role involves preparing risk dashboards for board presentations so this is something important to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The CRISC appears to tick the boxes I need but is another organisation, duplicating CPE and maintenance fees/efforts etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So before I pull the trigger on either one I was hoping somebody who has sat the CGRC training and exam could give me some insight into the course content. Does it actually give you good knowledge of effective risk and control reporting techniques, or is it more the risk assessment and process of selecting and implementing controls?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any and all input welcome.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 14:02:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/66693#M1068</guid>
      <dc:creator>piezor</dc:creator>
      <dc:date>2024-01-29T14:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: CGRC vs CRISC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/66696#M1069</link>
      <description>I’m afraid that there are probably more questions to answer here.&lt;BR /&gt;&lt;BR /&gt;I can say for sure in Banking, In Singapore the guys I knew were going to technical risk via ISACA - the other one they looked at was these guys &lt;A href="https://www.rims.org/certification" target="_blank"&gt;https://www.rims.org/certification&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;Knowledge wise I think you probably know the answer in that you buy/borrow the latest book from each and see which one looks better. The only other potentially helpful thing you might try is to search for jobs like yours or jobs you want to do and see what the cert counts are like - at least you get something quantifiable.&lt;BR /&gt;&lt;BR /&gt;It also looks like there is a fair bit of sectoral breakdown/rallying around certain orgs qualifications.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.indeed.com/career-advice/career-development/risk-management-certification" target="_blank"&gt;https://www.indeed.com/career-advice/career-development/risk-management-certification&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.techtarget.com/searchcio/feature/Top-enterprise-risk-management-certifications-to-consider" target="_blank"&gt;https://www.techtarget.com/searchcio/feature/Top-enterprise-risk-management-certifications-to-consider&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Good luck and would be nice to learn what you discover.</description>
      <pubDate>Mon, 29 Jan 2024 16:53:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/66696#M1069</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2024-01-29T16:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: CGRC vs CRISC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/66732#M1070</link>
      <description>&lt;P&gt;If risk management is what you are after, then the choice is clear and that is CRISC. The CGRC is centered solely around the NIST RMF framework. So, if you work for a federal agency in the US, or a contractor with them, and need to be well versed with the NIST RMF, then you have a reason to do CGRC. You can also do it, if you merely want the CGRC in your resume just because it has the the letters "GRC". But apart from these two reasons, I don't see any other valid reason to do it. CGRC covers risk management, but only as part of the overall RMF.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 03:50:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/66732#M1070</guid>
      <dc:creator>dips0502</dc:creator>
      <dc:date>2024-01-30T03:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: CGRC vs CRISC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/66739#M1071</link>
      <description>&lt;P&gt;thanks&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/622626293"&gt;@dips0502&lt;/a&gt;.&amp;nbsp;that is helpful and confirms what i thought. many thanks for the reply&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 09:27:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/66739#M1071</guid>
      <dc:creator>piezor</dc:creator>
      <dc:date>2024-01-30T09:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: CGRC vs CRISC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/66995#M1077</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1304099573"&gt;@piezor&lt;/a&gt;&amp;nbsp;keep in mind that effective June 15, 2024, the CGRC exam will be based on an updated exam outline.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Take a look at the updated CGRC Exam Outline:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.isc2.org/-/media/Project/ISC2/Main/Media/documents/domain-refresh/CGRC-Detailed-Content-Outline-with-Weights-2024.pdf" target="_blank"&gt;https://www.isc2.org/-/media/Project/ISC2/Main/Media/documents/domain-refresh/CGRC-Detailed-Content-Outline-with-Weights-2024.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 16:37:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/66995#M1077</guid>
      <dc:creator>tldutton</dc:creator>
      <dc:date>2024-02-07T16:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: CGRC vs CRISC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/67299#M1086</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone considered FAIR and the Open Group certification for Quantitative Risk approach?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.opengroup.org/certifications/openfair" target="_blank"&gt;https://www.opengroup.org/certifications/openfair&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Professionally I am seeing a shift toward FAIR and Quantitative risk approach, rather than a Qualitative risk approach, which many Government, including ISO 31000 standards etc take, which make it some what subjective.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.fairinstitute.org/" target="_blank"&gt;https://www.fairinstitute.org/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 04:47:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/67299#M1086</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2024-02-16T04:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: CGRC vs CRISC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/67556#M1089</link>
      <description>&lt;P&gt;CPEs overlap, you don't need to double the effort. You should be cautious in choosing the right moment for your education due to different CPE windows.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 20:09:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/67556#M1089</guid>
      <dc:creator>SaskiaKaaks</dc:creator>
      <dc:date>2024-02-23T20:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: CGRC vs CRISC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/75042#M1232</link>
      <description>&lt;P&gt;Now I see why it used to be called the Certified Authorization Professional (CAP) since authorize is one of the RMF steps. CGRC seems like a more marketable name than CAP.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2024 20:44:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/75042#M1232</guid>
      <dc:creator>MartinN</dc:creator>
      <dc:date>2024-11-09T20:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: CGRC vs CRISC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/75383#M1239</link>
      <description>&lt;P&gt;&lt;STRONG&gt;i need help on the best textbook for CGRC.&amp;nbsp; i will appreciate suggestion on the best book that can help me to pass the exam&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 02:35:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/75383#M1239</guid>
      <dc:creator>GABSONSOHO</dc:creator>
      <dc:date>2024-11-29T02:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: CGRC vs CRISC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/75393#M1240</link>
      <description>&lt;P&gt;I received my CGRC earlier this year. The "best" textbook is probably &lt;A href="https://csrc.nist.gov/pubs/sp/800/37/r2/final" target="_blank" rel="noopener"&gt;NIST SP 800-37&lt;/A&gt;. It's the primary reference that the CGRC is based on. ISC2 published a study guide (back when CGRC was still called CAP). It's okay, but it's over 10 years old now. See my review here: &lt;A href="https://www.goodreads.com/review/show/5971773506" target="_blank" rel="noopener"&gt;https://www.goodreads.com/review/show/5971773506&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read two other books as well, and my reviews for them are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ISO 27001/ISO 27002: A guide to information security management systems: &lt;A href="https://www.goodreads.com/review/show/6300405669" target="_blank" rel="noopener"&gt;https://www.goodreads.com/review/show/6300405669&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Information Security Risk Management for ISO 27001/ISO 27002: &lt;A href="https://www.goodreads.com/review/show/6297499126" target="_blank" rel="noopener"&gt;https://www.goodreads.com/review/show/6297499126&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;There are also some self-study aids here: &lt;A href="https://www.isc2.org/certifications/cgrc/cgrc-self-study-resources" target="_blank" rel="noopener"&gt;https://www.isc2.org/certifications/cgrc/cgrc-self-study-resources&lt;/A&gt;. The practice exam is new since I took my exam in March. The flash cards are helpful for definitions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 14:51:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/75393#M1240</guid>
      <dc:creator>jmikesmith</dc:creator>
      <dc:date>2024-11-29T14:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: CGRC vs CRISC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/75398#M1241</link>
      <description>&lt;P&gt;I have not looked into this, but does ISC2 make accommodations to "co-term" multiple certs so members don't need to keep track of different CPE windows? Like for a 5 year lease of printers, if you add a new printer in the 2nd year it can be co-termed to the original 5 year term.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 16:52:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/75398#M1241</guid>
      <dc:creator>MartinN</dc:creator>
      <dc:date>2024-11-29T16:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: CGRC vs CRISC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/75399#M1242</link>
      <description>&lt;P&gt;From talking to a seasoned CISO and my own thoughts, quantitative risk assessment is difficult without third party tools/data. How can you accurately value an asset or come up with a number for exposure factor, for each asset? A qualitative approach can be used first then from there you prioritize the risks and can then use a quantitative approach on those if needed. I think a tool like this may be helpful&amp;nbsp;&lt;A href="https://www.cybersaint.io/cybersecurity/cyberstrong/risk-hub" target="_blank"&gt;https://www.cybersaint.io/cybersecurity/cyberstrong/risk-hub&lt;/A&gt;&amp;nbsp;(I have no affiliation with this company. I saw a webinar for this on BrightTalk and thought it was interesting).&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 17:03:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/75399#M1242</guid>
      <dc:creator>MartinN</dc:creator>
      <dc:date>2024-11-29T17:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: CGRC vs CRISC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/75400#M1243</link>
      <description>&lt;P&gt;Let me know if you find something decent for CGRC. The latest book on Amz (&lt;A href="https://www.amazon.com/dp/B0DKJX4L16" target="_blank"&gt;https://www.amazon.com/dp/B0DKJX4L16&lt;/A&gt;) does not seem to be good. I may ask my employer to send me to the course.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 17:08:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/CGRC-vs-CRISC/m-p/75400#M1243</guid>
      <dc:creator>MartinN</dc:creator>
      <dc:date>2024-11-29T17:08:51Z</dc:date>
    </item>
  </channel>
</rss>

