image

Developed around the latest ISACA certification framework, this course equips you to assess IT and enterprise risk, develop effective risk response plans, and monitor control performance. You'll gain the insight and preparation you need to pursue the CRISC certification exam, enhance your governance capabilities, and meet the challenges of modern compliance and risk management roles.

This training prepares you to:

  • Identify and assess IT and enterprise risk in support of strategic business goals
  • Recommend and implement appropriate information security and IS controls
  • Build risk response and mitigation plans aligned to business priorities
  • Establish governance processes for continuous monitoring and reporting
  • Prepare for the CRISC certification exam through real-world examples, CRISC exam prep, and sample CRISC questions

You’ll leave this course ready to pass the CRISC, meet ISACA’s professional standards, and contribute to your organization’s resilience and regulatory readiness.

Virtual Instructor-Led Training 3 days / 24 hours

Who should attend Certified in Risk and Information Systems Control (CRISC) Course

IT risk management professionals with at least 3 years of relevant professional work experience in IT risk and information systems control including:

  • Security Directors/Managers/Consultants
  • Compliance/Risk/Privacy Directors and Managers
  • IT Audit Directors/Managers/Consultants
  • Compliance/Risk/Control Staff

Prerequisites for Certified in Risk and Information Systems Control (CRISC) Course

As part of the CRISC prerequisites, candidates must have a minimum of three years of professional work experience in information systems auditing, control, or security

Certified in Risk and Information Systems Control (CRISC) Course Outline

  • Risk Assessment Concepts, Standards and Frameworks
  • Organizational Strategy, Goals and Objectives
  • Organizational Structure, Roles and Responsibilities
  • Organizational Culture and Assets
  • Policies, Standards and Business Processes
  • Enterprise Risk Management, Risk Management Frameworks and Three Lines of Defense
  • Risk Profile, Risk Appetite and Risk Tolerance
  • Navigating Professional Ethics of Risk Management and Requirements in Laws, Regulations and Controls
  • Risk Events, Threat Modeling and Threat Landscape
  • Vulnerability and Control Deficiency Analysis
  • Risk Scenario Development
  • Risk Register
  • Risk Analysis Methodologies
  • Business Impact Analysis
  • Inherent, Residual and Current Risk
  • Risk Treatment/Risk Response Options
  • Risk and Control Ownership
  • Managing Risk from Processes, Third Parties and Emerging Sources
  • Control Types, Standards and Frameworks
  • Control Design, Selection and Analysis
  • Control Implementation, Testing and Effectiveness
  • Risk Treatment Plans
  • Data Collection, Aggregation, Analysis and Validation
  • Risk and Control Monitoring and Reporting Techniques
  • Performance, Risk and Control Metrics
  • Enterprise Architecture
  • IT Operations Management
  • Project Management
  • Disaster Recovery Management
  • Data Life Cycle Management
  • System Development Life Cycle
  • Emerging Technologies
  • Information Security Concepts, Frameworks, Standards and Awareness Training
  • Business Continuity Management
  • Data Privacy and Protection Principles

Resources

FAQs on Certified in Risk and Information Systems Control (CRISC)

IT risk management professionals such as security directors/managers, compliance/risk/privacy directors and managers, IT audit directors/managers, and compliance/risk/control staff with relevant experience in IT risk and information systems control.

Candidates must have a minimum of three years of professional work experience in information systems auditing, control, or security to meet CRISC certification prerequisites.

The course covers four domains: Governance, IT Risk Assessment, Risk Response and Reporting, and Information Technology and Security, including risk frameworks, control design, risk registers, and governance processes.

You will be able to identify and assess IT and enterprise risk, recommend and implement information security controls, build risk response plans, and establish governance processes for continuous monitoring and reporting.

Yes, the course includes exam prep, real-world examples, and sample questions to help you pass the CRISC exam and meet ISACA’s professional certification standards.