CRISC
Certified in Risk and Information Systems Control
This track is built to help you understand how ISACA frames risk — so you can think through scenarios the way the exam expects, not just recall definitions.
Exam Details
| Detail | CRISC |
|---|---|
| Format | 150 multiple-choice questions |
| Time | 4 hours |
| Standard Exam Fee (USD; verify current price) | $575 USD (ISACA member) / $760 USD (non-member) |
| Passing Score | 450 out of 800 |
| Experience | 3 years of relevant professional experience across at least 2 of the 4 CRISC domains, earned within the 10 years before applying. No experience waiver or substitution is available, and certification applications are due within 5 years of passing the exam |
| Renewal | 120 CPE hours per 3-year cycle, with at least 20 each year; annual fee $45 (member) / $85 (non-member) |
Source and Scope Note
Track scope checked August 24, 2026. The reference was ISACA’s CRISC Examination Content Outline (Effective 2025). ISACA made the revised exam available on November 3, 2025.
This note records the outline used for the track; it does not mean ISACA reviewed or endorsed the lessons. The practice material is original and does not reproduce live exam items. Report a content issue.
What You'll Learn
- Understand how ISACA frames risk across governance, assessment, response, and monitoring
- Build decision frameworks for approaching IT risk scenarios under uncertainty
- Practice original scenario-based questions aligned to the published CRISC outline
- Use reading, practice, and domain evidence to choose what to review next
Domain 1 — Governance (26%)
Organizational business and IT environments, strategy, goals and objectives, and the potential or realized impacts of IT risk to business objectives and operations.
Module A — Organizational Governance
- 1 Organizational Strategy, Goals, and Objectives Free Free Preview
- 2 Organizational Structure, Roles and Responsibilities Full Access
- 3 Organizational Culture Full Access
- 4 Policies and Standards Full Access
- 5 Business Processes Full Access
- 6 Organizational Assets Full Access
- ✓ Section A Review: Organizational Governance Full Access
Module B — Risk Governance
- 7 Enterprise Risk Management and Risk Management Framework Full Access
- 8 Three Lines of Defense Full Access
- 9 Risk Profile Full Access
- 10 Risk Appetite and Risk Tolerance Full Access
- 11 Legal, Regulatory and Contractual Requirements Full Access
- 12 Professional Ethics of Risk Management Full Access
- ✓ Section B Review: Risk Governance Full Access
Domain 1 Review
- ★ Capstone Review: GOVERNANCE Full Access
Domain 2 — Risk Assessment (22%)
Threats and vulnerabilities to the organization's people, processes and technology, as well as the likelihood and impact of threats, vulnerabilities and risk scenarios.
Module A — Risk Identification
- 13 Risk Events Free Free Preview
- 14 Threat Modelling and Threat Landscape Full Access
- 15 Vulnerability and Control Deficiency Analysis Full Access
- 16 Risk Scenario Development Full Access
- ✓ Section A Review: Risk Identification Full Access
Module B — Risk Analysis and Evaluation
- 17 Risk Assessment Concepts, Standards and Frameworks Full Access
- 18 Risk Register Full Access
- 19 Risk Analysis Methodologies Full Access
- 20 Business Impact Analysis Full Access
- 21 Inherent and Residual Risk Full Access
- ✓ Section B Review: Risk Analysis & Evaluation Full Access
Domain 2 Review
- ★ Capstone Review: RISK ASSESSMENT Full Access
Domain 3 — Risk Response and Reporting (32%)
Development and management of risk treatment plans, evaluation of existing controls for IT risk mitigation, and assessment of relevant risk and control information to applicable stakeholders.
Module A — Risk Response
- 22 Risk Treatment / Risk Response Options Free Free Preview
- 23 Risk and Control Ownership Full Access
- 24 Third-Party Risk Management Full Access
- 25 Issue, Finding and Exception Management Full Access
- 26 Management of Emerging Risk Full Access
- ✓ Section A Review: Risk Response Full Access
Module B — Control Design and Implementation
- 27 Control Types, Standards and Frameworks Full Access
- 28 Control Design, Selection and Analysis Full Access
- 29 Control Implementation Full Access
- 30 Control Testing and Effectiveness Evaluation Full Access
- ✓ Section B Review: Control Design & Implementation Full Access
Module C — Risk Monitoring and Reporting
- 31 Risk Treatment Plans Full Access
- 32 Data Collection, Aggregation, Analysis and Validation Full Access
- 33 Risk and Control Monitoring Techniques Full Access
- 34 Risk and Control Reporting Techniques Full Access
- 35 Key Performance Indicators Full Access
- 36 Key Risk Indicators (KRIs) Full Access
- 37 Key Control Indicators (KCIs) Full Access
- ✓ Section C Review: Risk Monitoring & Reporting Full Access
Domain 3 Review
- ★ Capstone Review: RISK RESPONSE AND REPORTING Full Access
Domain 4 — Technology and Security (20%)
Alignment of business practices with risk management and information security frameworks and standards, risk-aware culture, and security awareness training.
Module A — Information Technology Principles
- 38 Enterprise Architecture Free Free Preview
- 39 IT Operations Management Full Access
- 40 Project Management Full Access
- 41 Disaster Recovery Management (DRM) Full Access
- 42 Data Lifecycle Management Full Access
- 43 System Development Life Cycle (SDLC) Full Access
- 44 Emerging Technologies Full Access
- ✓ Section A Review: Information Technology Principles Full Access
Module B — Information Security Principles
- 45 Information Security Concepts, Frameworks and Standards Full Access
- 46 Information Security Awareness Training Full Access
- 47 Business Continuity Management Full Access
- 48 Data Privacy and Data Protection Principles Full Access
- ✓ Section B Review: Information Security Principles Full Access
Domain 4 Review
- ★ Capstone Review: TECHNOLOGY AND SECURITY Full Access
Career Benefits
- Relevant to IT risk, control, audit, compliance, and GRC roles
- An ISACA certification focused on IT risk management and control design
- Listed as a qualification option for certain DoD 8140 work roles; verify the current matrix for a specific position
- May be requested or valued for IT risk, control, and GRC roles
How It Compares
CRISC focuses specifically on IT risk management and control, while CISM covers broader security management including governance, programs, and incident response. CRISC may align more closely with risk and GRC work; CISM may align more closely with security program leadership. See the full comparison →
Head-to-head comparisons: CRISC vs CISM · CRISC vs CISSP · Security+ vs CRISC