ISACA Certification

CRISC

Certified in Risk and Information Systems Control

ISACA | 4 domains · 61 lessons and reviews | Free Preview

This track is built to help you understand how ISACA frames risk — so you can think through scenarios the way the exam expects, not just recall definitions.

Exam Details

CRISC exam details
Detail CRISC
Format 150 multiple-choice questions
Time 4 hours
Standard Exam Fee (USD; verify current price) $575 USD (ISACA member) / $760 USD (non-member)
Passing Score 450 out of 800
Experience 3 years of relevant professional experience across at least 2 of the 4 CRISC domains, earned within the 10 years before applying. No experience waiver or substitution is available, and certification applications are due within 5 years of passing the exam
Renewal 120 CPE hours per 3-year cycle, with at least 20 each year; annual fee $45 (member) / $85 (non-member)

Source and Scope Note

Track scope checked August 24, 2026. The reference was ISACA’s CRISC Examination Content Outline (Effective 2025). ISACA made the revised exam available on November 3, 2025.

This note records the outline used for the track; it does not mean ISACA reviewed or endorsed the lessons. The practice material is original and does not reproduce live exam items. Report a content issue.

What You'll Learn

  • Understand how ISACA frames risk across governance, assessment, response, and monitoring
  • Build decision frameworks for approaching IT risk scenarios under uncertainty
  • Practice original scenario-based questions aligned to the published CRISC outline
  • Use reading, practice, and domain evidence to choose what to review next
Start a Free Lesson →
Domain 1 — Governance (26%)

Organizational business and IT environments, strategy, goals and objectives, and the potential or realized impacts of IT risk to business objectives and operations.

Module A — Organizational Governance

  1. 1 Organizational Strategy, Goals, and Objectives Free Free Preview
  2. 2 Organizational Structure, Roles and Responsibilities Full Access
  3. 3 Organizational Culture Full Access
  4. 4 Policies and Standards Full Access
  5. 5 Business Processes Full Access
  6. 6 Organizational Assets Full Access
  7. Section A Review: Organizational Governance Full Access

Module B — Risk Governance

  1. 7 Enterprise Risk Management and Risk Management Framework Full Access
  2. 8 Three Lines of Defense Full Access
  3. 9 Risk Profile Full Access
  4. 10 Risk Appetite and Risk Tolerance Full Access
  5. 11 Legal, Regulatory and Contractual Requirements Full Access
  6. 12 Professional Ethics of Risk Management Full Access
  7. Section B Review: Risk Governance Full Access

Domain 1 Review

  1. Capstone Review: GOVERNANCE Full Access
Domain 2 — Risk Assessment (22%)

Threats and vulnerabilities to the organization's people, processes and technology, as well as the likelihood and impact of threats, vulnerabilities and risk scenarios.

Module A — Risk Identification

  1. 13 Risk Events Free Free Preview
  2. 14 Threat Modelling and Threat Landscape Full Access
  3. 15 Vulnerability and Control Deficiency Analysis Full Access
  4. 16 Risk Scenario Development Full Access
  5. Section A Review: Risk Identification Full Access

Module B — Risk Analysis and Evaluation

  1. 17 Risk Assessment Concepts, Standards and Frameworks Full Access
  2. 18 Risk Register Full Access
  3. 19 Risk Analysis Methodologies Full Access
  4. 20 Business Impact Analysis Full Access
  5. 21 Inherent and Residual Risk Full Access
  6. Section B Review: Risk Analysis & Evaluation Full Access

Domain 2 Review

  1. Capstone Review: RISK ASSESSMENT Full Access
Domain 3 — Risk Response and Reporting (32%)

Development and management of risk treatment plans, evaluation of existing controls for IT risk mitigation, and assessment of relevant risk and control information to applicable stakeholders.

Module A — Risk Response

  1. 22 Risk Treatment / Risk Response Options Free Free Preview
  2. 23 Risk and Control Ownership Full Access
  3. 24 Third-Party Risk Management Full Access
  4. 25 Issue, Finding and Exception Management Full Access
  5. 26 Management of Emerging Risk Full Access
  6. Section A Review: Risk Response Full Access

Module B — Control Design and Implementation

  1. 27 Control Types, Standards and Frameworks Full Access
  2. 28 Control Design, Selection and Analysis Full Access
  3. 29 Control Implementation Full Access
  4. 30 Control Testing and Effectiveness Evaluation Full Access
  5. Section B Review: Control Design & Implementation Full Access

Module C — Risk Monitoring and Reporting

  1. 31 Risk Treatment Plans Full Access
  2. 32 Data Collection, Aggregation, Analysis and Validation Full Access
  3. 33 Risk and Control Monitoring Techniques Full Access
  4. 34 Risk and Control Reporting Techniques Full Access
  5. 35 Key Performance Indicators Full Access
  6. 36 Key Risk Indicators (KRIs) Full Access
  7. 37 Key Control Indicators (KCIs) Full Access
  8. Section C Review: Risk Monitoring & Reporting Full Access

Domain 3 Review

  1. Capstone Review: RISK RESPONSE AND REPORTING Full Access
Domain 4 — Technology and Security (20%)

Alignment of business practices with risk management and information security frameworks and standards, risk-aware culture, and security awareness training.

Module A — Information Technology Principles

  1. 38 Enterprise Architecture Free Free Preview
  2. 39 IT Operations Management Full Access
  3. 40 Project Management Full Access
  4. 41 Disaster Recovery Management (DRM) Full Access
  5. 42 Data Lifecycle Management Full Access
  6. 43 System Development Life Cycle (SDLC) Full Access
  7. 44 Emerging Technologies Full Access
  8. Section A Review: Information Technology Principles Full Access

Module B — Information Security Principles

  1. 45 Information Security Concepts, Frameworks and Standards Full Access
  2. 46 Information Security Awareness Training Full Access
  3. 47 Business Continuity Management Full Access
  4. 48 Data Privacy and Data Protection Principles Full Access
  5. Section B Review: Information Security Principles Full Access

Domain 4 Review

  1. Capstone Review: TECHNOLOGY AND SECURITY Full Access

Career Benefits

  • Relevant to IT risk, control, audit, compliance, and GRC roles
  • An ISACA certification focused on IT risk management and control design
  • Listed as a qualification option for certain DoD 8140 work roles; verify the current matrix for a specific position
  • May be requested or valued for IT risk, control, and GRC roles

How It Compares

CRISC focuses specifically on IT risk management and control, while CISM covers broader security management including governance, programs, and incident response. CRISC may align more closely with risk and GRC work; CISM may align more closely with security program leadership. See the full comparison →

Head-to-head comparisons: CRISC vs CISM · CRISC vs CISSP · Security+ vs CRISC