1. Home
  2. Isaca
  3. CRISC Exam Syllabus

Isaca CRISC Exam Syllabus

Start Free CRISC Exam Practice After Reviewing the Topics

Before starting your CRISC exam preparation, it is recommended to review the complete Isaca Certified in Risk and Information Systems Control exam syllabus and carefully go through the exam objectives listed below. Once you understand the exam structure and objectives, you should practice using our free CRISC questions. We also provide premium CRISC practice test, fully updated according to the latest exam objectives, to help you accurately assess your preparedness for the actual exam.

Isaca
Vendor
CRISC
Exam Code
1895
Total Questions
4
Total Exam Domains

START FREE CRISC EXAM PRACTICE

NO SIGNUP REQUIRED  •  100% FREE TO START

CRISC EXAM QUESTIONS

Isaca CRISC Exam Objectives

Section 1: GOVERNANCE
Weight:
26%
The governance domain interrogates your knowledge of information about an organization’s business and IT environments, organizational strategy, goals and objectives, and examines potential or realized impacts of IT risk to the organization’s business objectives and operations, including Enterprise Risk Management and Risk Management Framework.

A: ORGANIZATIONAL GOVERNANCE
  • Strategy, Goals, and Objectives
  • Organizational Structure, Roles, and Responsibilities
  • Organizational Culture and Ethics
  • Policies and Standards
  • Business Processes and Resilience (e.g., DRP, BCP)
  • Organizational Asset Management
B: RISK GOVERNANCE
  • Enterprise Risk Management (ERM)
  • Lines of Defense
  • Risk Profile
  • Risk Appetite and Risk Tolerance
  • Risk Frameworks, Legal, Regulatory, and Contractual Requirements
Section 2: RISK ASSESSMENT
Weight:
22%
This domain will certify your knowledge of threats and vulnerabilities to the organization’s people, processes and technology as well as the likelihood and impact of threats, vulnerabilities and risk scenarios.

A: RISK IDENTIFICATION
  • Risk Events
  • Threat Modeling and Threat Landscape
  • Vulnerability Management
  • Risk Scenario Development and Evaluation
B: RISK ANALYSIS
  • Risk Assessment Concepts and Standards
  • Business Impact Analysis (BIA)
  • Risk Register
  • Risk Analysis Methodologies
  • Inherent and Residual Risk
Section 3: RISK RESPONSE AND REPORTING
Weight:
32%
This domain deals with the development and management of risk treatment plans among key stakeholders, the evaluation of existing controls and improving effectiveness for IT risk mitigation, and the assessment of relevant risk and control information to applicable stakeholders.

A: RISK RESPONSE
  • Risk Response Options
  • Risk and Control Ownership
  • Vendor/Supply Chain Risk Management
  • Issues, Findings, Exceptions and Exemptions Management
B: CONTROL DESIGN AND IMPLEMENTATION
  • Control Frameworks, Types, and Standards
  • Control Design, Selection, Implementation, and Analysis
  • Control Testing Methodologies
C: RISK MONITORING AND REPORTING
  • Risk Action Plans
  • Data Collection, Aggregation, Analysis, and Validation
  • Risk and Control Metrics (e.g., KRIs, KCIs, KPIs)
  • Risk and Control Monitoring Techniques
  • Risk and Control Reporting Techniques (e.g., heatmap, scorecards, dashboards)
  • Monitoring and Reporting of Emerging Risks
Section 4: TECHNOLOGY AND SECURITY
Weight:
20%
In this domain we interrogate the alignment of business practices with Risk Management and Information Security frameworks and standards, as well as the development of a risk-aware culture and implementation of security awareness training.

A: Technology and Security
  • Technology Principles
  • Technology Roadmaps and Enterprise Architecture (EA)
  • Operations Management (e.g., change management, assets, DevOps, problems, incidents)
  • System Development Life Cycle (SDLC)
  • Data Lifecycle Management
  • Portfolio and Project Management (e.g. Agile)
  • Technology Resilience and Disaster Response/Recovery
  • Emerging Technologies
B: INFORMATION SECURITY PRINCIPLES
  • Security Concepts, Frameworks, and Standards
  • Security/Risk Awareness and Training
  • Data Privacy and Data Protection Principles
Info