Certified in Risk and Information
Systems Control (CRISC)
Course Description
The CRISC Exam Preparation course is a fast-paced, four-day exam prep program to prepare individuals
who are planning to sit for the Certified in Risk and Information System Controls™ (CRISC) exam. The
course focuses on the key points covered in the CRISC Review Manual 7th Edition and includes class
lectures, exam-like questions practice and post-session activities. The course is intended for individuals
with familiarity and experience in IT and enterprise risk management.
Prerequisites
There are no prerequisite requirements for taking CRISC Exam Preparation Course or the CRISC exam.
However, in order to apply for CRISC certification, the candidate must meet the necessary experience
requirements determined by ISACA.
Course Objectives
Participants in the CRISC Exam Preparation course will be provided instruction designed to:
• Follow the format and structure of the CRISC certification exam
• Identify the various topics and technical areas covered by the exam
• Implement specific strategies, tips and techniques for taking and passing the exam
• Apply practice questions with debriefs of answers or situation.
Course Overview
This four-session (virtual) exam-prep course brings together the knowledge and practice. It gives learners
the knowledge and concepts necessary to successfully take and pass the CRISC Exam.
Course Approach
The content is laid out in a workshop format structured to provide a holistic learning experience leading to
proficiency. This is not a self-paced course. This course may also contain case study material based on
real-life scenarios but does not reference any particular company or situation.
Content Types
Workshop: Main course content, typically a slide deck or recorded,
lecture-style format. Workshop
Enrichment: Additional content provided for the learning experience
in the course. These are items that, while not required, may provide a
bigger picture or more context around content presented in the course. Questions/ Enrichment
These are content elements including (but not limited to) learning aids, Activities
journal articles, podcasts, whitepapers, webinars or links from other
trusted sources.
Questions/Activities: This course contains practice questions in the same format as the CRISC exam.
Students will gain experience mapping their current knowledge to successfully answer questions while
taking the exam. Activities allow students to apply their knowledge to concepts learned in the course.
©2023. ISACA. All Rights Reserved
Session 1 – Governance
Learning Objectives:
• Outline how the key concepts of risk impact the enterprise.
• Distinguish between governance and management functions.
• Describe the relationship between enterprise risk and IT risk.
• Define roles and responsibilities within the organizational structure and relation to risk management.
• Outline the impact of organizational culture on risk management.
• Identify organizational assets and how they are valued.
• Explain how policies and standards provide direction to the enterprise.
• Describe how the business process reviews help improve enterprise effectiveness.
• Describe the concepts of enterprise risk management.
• Assess risk frameworks and their role enterprise risk management.
• Explain role of the risk practitioner in the three lines of defense.
• Define the types of risk profiles.
• Describe the relationship between risk appetite and risk tolerance.
• Describe the impact of legal, regulatory, and contractual obligations regarding risk management.
• Explain the importance of professional ethics in risk management.
Session topics:
• 1.1 Risk Assessment Concepts, Standards and Frameworks
• 1.2 Organizational Strategy, Goals and Objectives
• 1.3 Organizational Structure, Roles and Responsibilities
• 1.4 Organizational Culture and Assets
• 1.5 Policies, Standards and Business Processes
• 1.6 Enterprise Risk Management, Risk Management Frameworks and Three Lines of Defense
• 1.7 Risk Profile, Risk Appetite and Risk Tolerance
• 1.8 Professional Ethics of Risk Management and Requirements in Laws, Regulations and Controls
Enrichment (optional, self-paced):
• Risk Management Strength and Financial Disclosure Quality
• Pandemic-Driven Remote Working and Risk Management Strategies
• Role of IT Governance During COVID-19 and Beyond: Keeping Momentum, ISACA Journal, Vol 6.
• The Non-IT Manager’s Role in Enterprise IT Risk Management
• Fintech Governance Challenges, Levels and Theories
• The Sheer Gravity of Underestimating Culture as an IT Governance Risk
• Are Organizations Actually Performing Risk-Based Audits?
• Connecting Good Governance With Key Risk
• Successful Outcomes by Crowdsourcing Risk Management
• Moving Risk Management From Fear and Avoidance to Performance and Value
• Roles of Three Lines of Defense for Information Security and Governance
• Human Error: A Vastly Underestimated Risk in Digital Transformation Technology
©2023. ISACA. All Rights Reserved
Session 2 – IT Risk Assessment
Learning Objective:
• Define the types of risk events and threats an enterprise can face.
• Explain the risk identification process.
• Identify threat modeling techniques.
• Compile a threat profile using threat modeling techniques.
• Describe the process and benefits of developing risk scenarios.
• Explain the risk assessment process.
• Define common risk assessment standards and frameworks.
• Describe the value of the risk register to the enterprise.
• Explain risk analysis methodologies and how they are used.
• Illustrate the relationship between business impact analysis and risk assessment.
• Outline the effect of inherent and residual risk on the enterprise.
Session topics:
• 2.1 Risk Events, Threat Modeling and Threat Landscape
• 2.2 Vulnerability and Control Deficiency Analysis
• 2.3 Risk Scenario Development
• 2.4 Risk Register
• 2.5 Risk Analysis Methodologies
• 2.6 Business Impact Analysis
• 2.7 Inherent, Residual and Current Risk
Enrichment (optional, self-paced):
• IS Audit in Practice: Watching Out for Workforce Risk in the New Normal
• Managing Technology Risk to Protect Privacy and Confidentiality
• How to Balance Insider Threats and Employee Privacy
• The Practical Aspect: Working from Home—Reassessing Risk and Opportunities
• Tips for Improving Risk Assessment and Analysis
• The First Steps of Quantitative Risk Management
• Evolving From Qualitative to Quantitative Risk Assessment
©2023. ISACA. All Rights Reserved
Session 3 – Risk Response and Reporting
Learning Objective:
• Determine roles accountable for risk and control ownership.
• Align risk treatment and response options with enterprise risk appetite and tolerance.
• Address risk originating from outside the enterprise (or from third parties).
• Apply procedures to processes and functions containing high amounts of variability.
• Evaluate emerging technologies and changes for threats, vulnerabilities and opportunities.
• Categorize controls relative to the type of risk response required.
• Leverage common standards and frameworks in designing and implementing controls.
• Identify the current state of existing controls and evaluate their effectiveness for IT risk mitigation.
• Assess gaps between current and desired states of the IT risk environment.
• Collaborate with control owners on the selection, design and implementation of controls.
• Conduct aggregation, analysis and validation of risk and control data.
• Validate risk responses have been executed according to risk treatment plans.
• Describe the types of risk data available to monitor and report risk.
• Identify types of control assessments.
• Explain the process of compiling and reporting the status of controls.
• Apply the steps of control monitoring process.
• Establish a process to define, monitor and analyze metrics relevant to enterprise risk.
Session topics:
• 3.1 Risk Treatment/Risk Response Options
• 3.2 Risk and Control Ownership
• 3.3 Managing Risk from Processes, Third Parties and Emerging Sources
• 3.4 Control Types, Standards and Frameworks
• 3.5 Control Design, Selection and Analysis
• 3.6 Control Implementation, Testing and Effectiveness
• 3.7 Risk Treatment Plans
• 3.8 Data Collection, Aggregation, Analysis and Validation
• 3.9 Risk and Control Monitoring and Reporting Techniques
• 3.10 Performance, Risk and Control Metrics
Enrichment (optional, self-paced):
• Addressing Key Pain Points to Develop a Mature Third-Party Risk Management
• Digital Banking Poses Challenges for Third-Party Risk Management
• Access Controls Over Third-Party Applications
• Addressing Risk Using the New Enterprise Security Risk Management Cycle
• Effective Reporting to the BoD on Critical Assets, Cyberthreats and Key Controls
• Qualitative and Quantitative Model
• Reporting Cybersecurity Risk to the Board of Directors
• Enterprise Risk Monitoring Methodology, Part 4: Risk Executive Summary
©2023. ISACA. All Rights Reserved
Session 4 – Information Technology and Security
Learning Objectives:
• Explain the key components of enterprise architecture and the frameworks used to implement them.
• Identify IT components and their areas of concern relating to enterprise risk.
• Describe the project risk and how it is addressed in the project management process.
• Outline the steps and requirements needed to maintain enterprise resiliency.
• Assess areas of risk throughout the data life cycle.
• Articulate key security and support tasks to perform during the system development life cycle.
• Evaluate emerging technologies and changes for threats, vulnerabilities and opportunities.
• Identify factors that can impact security and risk in the enterprise.
• Leverage information security frameworks and standards to manage information systems and data.
• Review the scope of information security training and awareness programs against identified threats.
• Apply data privacy and data protection principles to risk assessment activities.
Session topics:
• 4.1 Enterprise Architecture
• 4.2 IT Operations Management
• 4.3 Project Management
• 4.4 Disaster Recovery Management
• 4.5 Data Life Cycle Management
• 4.6 System Development Life Cycle
• 4.7 Emerging Technologies
• 4.8 Information Security Concepts, Frameworks, Standards and Awareness Training
• 4.9 Business Continuity Management
• 4.10 Data Privacy and Protection Principles
Enrichment (optional, self-paced):
• Security for Internet of Things Device Manufacturers
• California Consumer Privacy Act and Encryption: Theory, Practice, Risk Assessment and Mitigation
• Data Ownership: Considerations for Risk Management
©2023. ISACA. All Rights Reserved
CRISC Program Update
The refreshed exam reflects updated job practice that takes into account evolving needs of practitioners,
including areas of:
• corporate governance
• business continuity and resilience
• data privacy and protection.
Domains covered in the CRISC exam include:
• governance (organizational governance, risk governance) 26%,
• IT risk assessment (identification, analysis and evaluation) 20% (continued),
• risk response and reporting (control design and implementation) 32%,
• information technology and security (principles) 22%.
The CRISC program is designed to demonstrate knowledge and experience in risk mitigation, and
implementation and maintenance of information systems controls. The program validates practitioners’
experience in building a well-defined, agile risk-management program, based on best practices and able
to effectively and efficiently identify, analyze, evaluate, assess, prioritize and respond to risks.
©2023. ISACA. All Rights Reserved