ISACA
Advanced
40 hours
CRISC

Certified in Risk and Information Systems Control (CRISC)

CRISC is ISACA's premier certification for IT risk management professionals. It validates expertise in identifying, assessing, evaluating, and managing IT risk within the context of business objectives. CRISC-certified professionals design and implement information systems controls to mitigate risk, making it one of the most sought-after credentials for risk management and governance roles worldwide.

What is the Certified in Risk and Information Systems Control (CRISC)?

CRISC is ISACA's premier certification for IT risk management professionals. It validates expertise in identifying, assessing, evaluating, and managing IT risk within the context of business objectives. CRISC-certified professionals design and implement information systems controls to mitigate risk, making it one of the most sought-after credentials for risk management and governance roles worldwide.

Who Should Take This Course?

  • IT Risk Managers and Risk Analysts
  • Business Analysts with IT risk responsibilities
  • Information Security Professionals focused on risk
  • Project Managers overseeing IT risk governance
  • Control Professionals and IT Auditors
  • Compliance Officers in technology organizations
  • Consultants advising on enterprise risk frameworks

What You Will Learn in the CRISC Course

A comprehensive curriculum covering all exam objectives with hands-on labs and real-world practice.

Domain 1: Governance

Align IT risk management with enterprise governance structures.

  • Organizational strategy, goals, and risk appetite
  • Risk management frameworks: NIST, ISO 31000, COBIT
  • Three lines of defense model
  • Risk culture and communication

Domain 2: IT Risk Assessment

Identify, evaluate, and prioritize IT risks to the organization.

  • Threat and vulnerability identification methodologies
  • Qualitative and quantitative risk assessment techniques
  • Risk scenario development and analysis
  • Control deficiency and gap analysis

Domain 3: Risk Response and Reporting

Select and implement risk responses and communicate risk posture.

  • Risk treatment options: accept, avoid, transfer, mitigate
  • Risk response plans and accountability
  • Key Risk Indicators (KRIs) and monitoring
  • Risk reporting to senior management and board

Domain 4: Information Technology and Security

Apply IT and security knowledge to effectively manage risk.

  • Enterprise architecture and IT infrastructure risk
  • Emerging technologies: cloud, IoT, AI risk implications
  • Cybersecurity controls and frameworks
  • Business continuity and disaster recovery planning

Course Prerequisites

Pre-requisites training is free when you purchase the course from ProSupport

  • 3 years of IT risk management and IS control experience required
  • Experience must span at least 2 of the 4 CRISC domains
  • Adherence to ISACA Code of Professional Ethics
  • Experience must be verified within 5 years of passing the exam

Exam Information

Everything you need to know about the CRISC certification exam.

Exam ComponentDetails
Exam Name
Certified in Risk and Information Systems Control
Exam Code
CRISC
Exam Type
Multiple Choice
Total Questions
150
Passing Score
450 (out of 800)
Exam Duration
240 minutes
Language
English, Chinese Simplified, Japanese, Korean, Spanish
Exam Provider
PSI Exams (in-person or online)
Exam Focus
IT risk governance, risk assessment, risk response, and IS controls
Exam Registration
ISACA portal (isaca.org/certification/crisc-certified-in-risk-and-information-systems-control)
Retake Policy
1-year waiting period; maximum 3 attempts per year
Certification Validity
3 years (120 CPE hours required for renewal)

Exam Topics

Governance — 26%
IT Risk Assessment — 20%
Risk Response and Reporting — 32%
Information Technology and Security — 22%

Training Plans

Select the plan that matches your career goals

Basic

Certification Program

USD699
  • Certification syllabus training
  • Private instructor-led live classes
  • Hands-on labs
  • Practice exams
  • Certification exam guidance
Get Started

Pro

Certification + Projects

USD919
  • Everything in Basic
  • Real-world industry projects
  • Case studies
  • GitHub portfolio project
  • Assignment reviews
  • Capstone mini project
Get Started
Most Popular

Premium

Career Acceleration

USD1,189
  • Everything in Pro
  • Resume building
  • LinkedIn profile optimization
  • Interview preparation
  • Mock interviews
  • Career mentoring sessions
  • Capstone project
  • Certification exam strategy
  • Industry use-case training
Get Started

Need custom enterprise pricing? support@prosupportconsulting.in

Learning Path

Your certification journey — from prerequisites to advanced roles.

3 years IT risk management experience
This Certification

CRISC — Certified in Risk and IS Control

Prerequisite This Certification Next Steps

Ready to Get Certified?

Start your Certified in Risk and Information Systems Control (CRISC) journey with private 1-to-1 training from certified industry developers.

support@prosupportconsulting.in