← Home
ISACA · Full exam outline

CRISC

Certified in Risk and Information Systems Control

IT risk managementCore certification
1Governance26%
1.1Organizational strategy, goals and objectives
1.2Risk governance policies, standards and frameworks
1.3Enterprise risk management and the risk profile
1.4Business processes and organizational structure
1.5Three lines of defence and risk culture
2IT Risk Assessment20%
2.1Risk events, threats and vulnerabilities
2.2Risk scenario development
2.3Risk assessment concepts and methods
2.4Risk analysis, ranking and ownership
3Risk Response and Reporting32%
3.1Risk treatment and response options
3.2Control design, selection and implementation
3.3Control testing and effectiveness evaluation
3.4Risk and control monitoring
3.5Risk reporting, key risk and performance indicators
4Information Technology and Security22%
4.1Enterprise architecture and IT operations
4.2Project and change management
4.3Data lifecycle and emerging technologies
4.4Information security concepts and controls
4.5Business continuity and disaster recovery management
Weights are the certification body’s published values and are checked against each outline revision.