CRISC Exam Prep

Study Guide

Certified in Risk and Information Systems Control Study Guide

Use the saved domain outline to connect governance and risk management frameworks, risk identification, assessment, and analysis, risk response and reporting, technology, security, and resilience controls to scenario-based questions and explanations.

How the Exam Is Structured

Certified in Risk and Information Systems Control (CRISC) validates governance and risk management frameworks, risk identification, assessment, and analysis, risk response and reporting, technology, security, and resilience controls. The ExamPal practice bank includes 144 premium questions and 40 free questions mapped across the official blueprint.

DomainWeightFocus
Domain 1 — Governance and Risk Management Frameworks 26% Task 1.1 — Establish and maintain the risk governance framework; Define governance structures and escalation paths
Domain 2 — Risk Identification, Assessment, and Analysis 22% Task 2.1 — Establish risk context and assessment criteria; Define assessment scope and boundaries
Domain 3 — Risk Response and Reporting 32% Task 3.1 — Select and evaluate risk treatment options; Compare treatment strategies
Domain 4 — Technology, Security, and Resilience Controls 20% Task 4.1 — Evaluate identity, access, and authorization controls; Assess authentication and privileged access

26% of exam

Domain 1 — Governance and Risk Management Frameworks

Covers enterprise risk governance, organizational roles, risk culture, policy structure, compliance obligations, and alignment of risk management with business strategy.

Task 1.1 — Establish and maintain the risk governance framework
Define governance structures and escalation paths
Align governance with enterprise objectives
Integrate with governance, compliance, and control functions
Periodically review and update governance
Task 1.2 — Define risk appetite, tolerance, and capacity
Distinguish appetite, tolerance, and capacity

22% of exam

Domain 2 — Risk Identification, Assessment, and Analysis

Covers identifying risk scenarios, evaluating threats and vulnerabilities, assessing likelihood and impact, and maintaining risk information for decision-making.

Task 2.1 — Establish risk context and assessment criteria
Define assessment scope and boundaries
Determine risk criteria and scales
Identify internal and external factors
Align criteria with priorities
Task 2.2 — Identify assets, processes, threats, and vulnerabilities
Inventory critical assets and dependencies

32% of exam

Domain 3 — Risk Response and Reporting

Covers selecting treatment strategies, designing response plans, monitoring risks and controls, issue management, third-party risk, and communicating risk information.

Task 3.1 — Select and evaluate risk treatment options
Compare treatment strategies
Assess cost, benefit, and feasibility
Determine compensating controls
Recommend treatment approaches
Task 3.2 — Develop risk treatment and action plans
Define treatment actions and ownership

20% of exam

Domain 4 — Technology, Security, and Resilience Controls

Covers information security, IT general controls, architecture and operational safeguards, continuity capabilities, and technology-specific risk considerations.

Task 4.1 — Evaluate identity, access, and authorization controls
Assess authentication and privileged access
Verify access based on business need
Review joiner-mover-leaver and SoD
Evaluate logging and recertification
Task 4.2 — Assess infrastructure, network, and endpoint protections
Evaluate network and perimeter controls

Key Terms to Know

These terms are loaded from the shared terminology pack and appear across the question explanations.

Authentication factor
A category of identity evidence, such as something a user knows, has, or is.
Board risk oversight
The board’s responsibility to supervise how risk is identified, managed, and governed across the organization.
Business unit risk appetite
A business-unit-specific interpretation of enterprise risk appetite that defines local limits and priorities.
Cloud infrastructure
The underlying cloud services, platforms, hardware, and facilities managed to support cloud operations.
Control exception tracking
The process of documenting, monitoring, and reviewing approved deviations from established control requirements.
Discrete logarithm
A mathematical problem used in some cryptographic systems that may become solvable efficiently by quantum computing.
Dynamic risk assessment
Continuous evaluation of hazards and risks in real time as conditions or circumstances change.
Enterprise Risk Management (ERM) framework
A structured organization-wide approach for identifying, assessing, responding to, and monitoring risk.
Failure Mode and Effects Analysis (FMEA)
A structured technique for identifying potential failure points in a process and evaluating their effects.
Failure mode
A specific way in which a process, system, or component could fail.
Impact
The magnitude of consequences or effect if a risk event occurs.
Inherent risk
The level of risk that exists before any controls or mitigation measures are applied.
Least privilege
An access control principle that gives users only the minimum permissions needed to perform their job functions.
Likelihood
The probability that a risk event will occur.
Material risk disclosure
The requirement to report significant risks that a reasonable investor would consider important in decision-making.
Multi-factor authentication (MFA)
An authentication method requiring two or more different verification factors to confirm identity.
Network Access Control (NAC)
A security technology that checks and enforces policy compliance for devices before allowing network access.
Quantum computing threat
The risk that quantum computers could break current cryptographic methods much faster than classical computers.

Official Materials and Guidance

This page is built from ISACA official materials and ExamPal shared release pack, the shared syllabus, topic tree, terminology pack, free pack, and premium pack.

  • -Guidance: ISACA official page and exam content outline saved locally
  • -Domain outline: Governance 26%; IT risk assessment 20%; Risk response/reporting 32%; IT/security 22%.