SecLeaderAcademy
← Home
ISACA · Full exam outline
CRISC
Certified in Risk and Information Systems Control
IT risk management
Core certification
1
Governance
26%
1.1
Organizational strategy, goals and objectives
1.2
Risk governance policies, standards and frameworks
1.3
Enterprise risk management and the risk profile
1.4
Business processes and organizational structure
1.5
Three lines of defence and risk culture
2
IT Risk Assessment
20%
2.1
Risk events, threats and vulnerabilities
2.2
Risk scenario development
2.3
Risk assessment concepts and methods
2.4
Risk analysis, ranking and ownership
3
Risk Response and Reporting
32%
3.1
Risk treatment and response options
3.2
Control design, selection and implementation
3.3
Control testing and effectiveness evaluation
3.4
Risk and control monitoring
3.5
Risk reporting, key risk and performance indicators
4
Information Technology and Security
22%
4.1
Enterprise architecture and IT operations
4.2
Project and change management
4.3
Data lifecycle and emerging technologies
4.4
Information security concepts and controls
4.5
Business continuity and disaster recovery management
Weights are the certification body’s published values and are checked against each outline revision.