CRISC

Certified in Risk and Information Systems Control

ISACA | 4 domains · 48 modules | Ready

This track is built to help you understand how ISACA frames risk — so you can think through scenarios the way the exam expects, not just recall definitions.

0 of 48 modules completed (0%)

What You'll Learn

  • Understand how ISACA frames risk across governance, assessment, response, and monitoring
  • Build decision frameworks for approaching IT risk scenarios under uncertainty
  • Practice scenario-based questions that mirror ISACA's exam style
  • Develop structured readiness self-assessments to know when you're exam-ready
Domain 1 — Governance

Organizational business and IT environments, strategy, goals and objectives, and the potential or realized impacts of IT risk to business objectives and operations.

Module A — Organizational Governance

  1. 1 Organizational Strategy, Goals, and Objectives Available
  2. 2 Organizational Structure, Roles and Responsibilities Available
  3. 3 Organizational Culture Available
  4. 4 Policies and Standards Available
  5. 5 Business Processes Available
  6. 6 Organizational Assets Available
  7. Section A Review: Organizational Governance Available

Module B — Risk Governance

  1. 7 Enterprise Risk Management and Risk Management Framework Available
  2. 8 Three Lines of Defense Available
  3. 9 Risk Profile Available
  4. 10 Risk Appetite and Risk Tolerance Available
  5. 11 Legal, Regulatory and Contractual Requirements Available
  6. 12 Professional Ethics of Risk Management Available
  7. Section B Review: Risk Governance Available

Domain 1 Review

  1. Capstone Review: GOVERNANCE Available
Domain 2 — Risk Assessment

Threats and vulnerabilities to the organization's people, processes and technology, as well as the likelihood and impact of threats, vulnerabilities and risk scenarios.

Module A — IT Risk Identification

  1. 13 Risk Events Available
  2. 14 Threat Modelling and Threat Landscape Available
  3. 15 Vulnerability and Control Deficiency Analysis Available
  4. 16 Risk Scenario Development Available
  5. Section A Review: IT Risk Identification Available

Module B — IT Risk Analysis and Evaluation

  1. 17 Risk Assessment Concepts, Standards and Frameworks Available
  2. 18 Risk Register Available
  3. 19 Risk Analysis Methodologies Available
  4. 20 Business Impact Analysis Available
  5. 21 Inherent and Residual Risk Available
  6. Section B Review: IT Risk Analysis & Evaluation Available

Domain 2 Review

  1. Capstone Review: RISK ASSESSMENT Available
Domain 3 — Risk Response and Reporting

Development and management of risk treatment plans, evaluation of existing controls for IT risk mitigation, and assessment of relevant risk and control information to applicable stakeholders.

Module A — Risk Response

  1. 22 Risk Treatment / Risk Response Options Available
  2. 23 Risk and Control Ownership Available
  3. 24 Third-Party Risk Management Available
  4. 25 Issue, Finding and Exception Management Available
  5. 26 Management of Emerging Risk Available
  6. Section A Review: Risk Response Available

Module B — Control Design and Implementation

  1. 27 Control Types, Standards and Frameworks Available
  2. 28 Control Design, Selection and Analysis Available
  3. 29 Control Implementation Available
  4. 30 Control Testing and Effectiveness Evaluation Available
  5. Section B Review: Control Design & Implementation Available

Module C — Risk Monitoring and Reporting

  1. 31 Risk Treatment Plans Available
  2. 32 Data Collection, Aggregation, Analysis and Validation Available
  3. 33 Risk and Control Monitoring Techniques Available
  4. 34 Risk and Control Reporting Techniques Available
  5. 35 Key Performance Indicators Available
  6. 36 Key Risk Indicators (KRIs) Available
  7. 37 Key Control Indicators (KCIs) Available
  8. Section C Review: Risk Monitoring & Reporting Available

Domain 3 Review

  1. Capstone Review: RISK RESPONSE AND REPORTING Available
Domain 4 — Technology and Security

Alignment of business practices with risk management and information security frameworks and standards, risk-aware culture, and security awareness training.

Module A — Information Technology Principles

  1. 38 Enterprise Architecture Available
  2. 39 IT Operations Management Available
  3. 40 Project Management Available
  4. 41 Disaster Recovery Management (DRM) Available
  5. 42 Data Lifecycle Management Available
  6. 43 System Development Life Cycle (SDLC) Available
  7. 44 Emerging Technologies Available
  8. Section A Review: Information Technology Principles Available

Module B — Information Security Principles

  1. 45 Information Security Concepts, Frameworks and Standards Available
  2. 46 Information Security Awareness Training Available
  3. 47 Business Continuity Management Available
  4. 48 Data Privacy and Data Protection Principles Available
  5. Section B Review: Information Security Principles Available

Domain 4 Review

  1. Capstone Review: TECHNOLOGY AND SECURITY Available
Practice Exam CRISC Practice Exam — 150 Questions