CRISC - Certified in Risk and Information Systems Control®

A CRISC certification helps you stay one step ahead of real-world threats across your enterprise

Course Description

The CRISC Exam Preparation course is an intensive, four-day review program to prepare individuals who are planning to sit for the Certified in Risk and Information System Controls™ (CRISC) exam. The course focuses on the key points covered in the CRISC Review Manual 7th Edition and includes class lectures, group discussions, exam practice and answer debriefs. The course is intended for individuals with familiarity with and experience in IT and enterprise risk management.

What Is the CRISC Certification?

Introduced in 2010, the CRISC certification is a globally recognized standard of achievement for IT risk professionals— including risk and compliance professionals, business analysts and project managers— More than 20,000 professionals have earned the CRISC designation since inception. CRISC retention is more than 96 percent. Clearly, holders of a CRISC certification highly value the designation.

Who Should Seek CRISC Certification?

The CRISC certification is sought by those professionals who identify and manage risks through the development, implementation and maintenance of appropriate information systems (IS) controls. CRISCs are recognized internationally as professionals with knowledge and experience in the job practices of risk identification, risk assessment, risk response and mitigation, and risk and control monitoring and reporting.

General Information

Globally accepted management-focused certification for professionals with three or more years of experience. This credential demonstrates expertise in identifying and managing enterprise IT risk and implementing and maintaining information systems controls. There are 150 Questions on the exam which must be completed in 4 hours. It is available online via remote proctoring and at in-person testing centers where available

The CRISC Certification is intended for

IT risk management professionals with at least 3 years of relevant professional work experience in IT risk and information systems control including:

• Security Directors/Managers/Consultants

• Compliance/Risk/Privacy Directors and Managers

• IT Audit Directors/Managers/Consultants

• Compliance/Risk/Control Staff

Exam details

  • Number of questions:  150 questions
  • Duration of the exam:  4 hours
  • Course Duration:  4 days

For additional information, you can view the examination guide here.

RQMcert

Trainer

Eliza Popa

I am a Diplomat Economist who has been working with CII organizations for over 30 years. Out of this tenure, 14 years have been dedicated to IT digital transformation projects and operations, followed by over 10 years in information security roles with both end-user organizations and consultancy firms. My professional certifications include CISSP, CISA, CRISC, CISM, CDPSE, CCSK v4, ITIL v3, Oracle SQL DBA, and PECB ISO/IEC 27001 Master, ISO/IEC 27002 Sr. Lead Manager, ISO/IEC 27005 Sr. Lead Risk Manager, Sr. Lead Cybersecurity Manager, CISO, Sr. Lead Cloud Security Manager, ISO/IEC 38500 Sr. Lead IT Corporate Governance Manager, ISO/IEC 20000 Sr. Lead Auditor, ISO 37301 Sr. Lead Implementer, ISO 31000 Sr. Lead Risk Manager, ISO 21502 Sr. Lead Project Manager, and ISO 9001 Sr. Lead Auditor. I provided informal training to CISA and CISSP candidates from 2016 until 2019, when I became an ISC2 Official Training Instructor for CISSP and a PECB Certified Trainer. Furthermore, in 2022 I became an ISC2 Official Training Instructor for CC and a CSA Authorized Trainer for CCSK v4 Foundation and Plus (AWS / Azure labs). My expertise and capabilities captured the attention of PECB, who, in 2023, appointed me to develop and record the eLearning training content and Skills content for ISO/IEC 27001 Lead Implementer and ISO/IEC Lead Auditor courses. https://www.linkedin.com/in/elizapopa/

Accredited Training Center

Course Topics

 Domain 1: IT Risk Identification
 Identify the universe of IT risk to contribute to the execution of the IT risk management strategy in support of business objectives and in alignment with the enterprise risk management (ERM) strategy. 

  • Collect and review information, including existing documentation, regarding the organization’s internal and external business and IT environments to identify potential or realized impacts of IT risk to the organization’s business objectives and operations.
  • Identify potential threats and vulnerabilities to the organization’s people, processes and technology to enable IT risk analysis.
  • Develop a comprehensive set of IT risk scenarios based on available information to determine the potential impact to business objectives and operations.
  • Identify key stakeholders for IT risk scenarios to help establish accountability.
  • Establish an IT risk register to help ensure that identified IT risk scenarios are accounted for and incorporated into the enterprise-wide risk profile.
  • Identify risk appetite and tolerance defined by senior leadership and key stakeholders to ensure alignment with business objectives.
  • Collaborate in the development of a risk awareness program, and conduct training to ensure that stakeholders understand risk and to promote a risk-aware culture.

 Domain 2: IT Risk Assessment
 Analyze and evaluate IT risk to determine the likelihood and impact on business objectives to enable risk-based decision making.

  • Analyze risk scenarios based on organizational criteria (e.g., organizational structure, policies, standards, technology, architecture, controls) to determine the likelihood and impact of an identified risk.
  • Identify the current state of existing controls and evaluate their effectiveness for IT risk mitigation.
  • Review the results of risk and control analysis to assess any gaps between current and desired states of the IT risk environment.
  • Ensure that risk ownership is assigned at the appropriate level to establish clear lines of accountability.
  • Communicate the results of risk assessments to senior management and appropriate stakeholders to enable riskbased decision making.
  • Update the risk register with the results of the risk assessment.

 Domain 3: Risk Response Mitigation
 Determine risk response options and evaluate their efficiency and effectiveness to manage risk in alignment with business objectives.

  • Consult with risk owners to select and align recommended risk responses with business objectives and enable informed risk decisions.
  • Consult with, or assist, risk owners on the development of risk action plans to ensure that plans include key elements (e.g., response, cost, target date).
  • Consult on the design and implementation or adjustment of mitigating controls to ensure that the risk is managed to an acceptable level.
  • Ensure that control ownership is assigned to establish clear lines of accountability.
  • Assist control owners in developing control procedures and documentation to enable efficient and effective control execution.
  • Update the risk register to reflect changes in risk and management’s risk response.
  • Validate that risk responses have been executed according to the risk action plans.
     

Domain 4: Risk and Control Monitoring and Reporting
 Continuously monitor and report on IT risk and controls to relevant stakeholders to ensure the continued efficiency and effectiveness of the IT risk management strategy and its alignment to business objectives.

  • Define and establish key risk indicators (KRIs) and thresholds based on available data, to enable monitoring of changes in risk.
  • Monitor and analyze key risk indicators (KRIs) to identify changes or trends in the IT risk profile.
  • Report on changes or trends related to the IT risk profile to assist management and relevant stakeholders in decision making.
  • Facilitate the identification of metrics and key performance indicators (KPIs) to enable the measurement of control performance.
  • Monitor and analyze key performance indicators (KPIs) to identify changes or trends related to the control environment and determine the efficiency and effectiveness of controls.
  • Review the results of control assessments to determine the effectiveness of the control environment.
  • Report on the performance of, changes to, or trends in the overall risk profile and control environment to relevant stakeholders to enable decision making

Prerequisites

There are no prerequisite requirements for taking the CRISC Exam Preparation Course or the CRISC exam; however, in order to apply for CRISC certification, the candidate must meet the necessary experience requirements determined by ISACA.

Course Objectives

Participants in the CRISC Exam Preparation course will be provided instruction designed to provide the following:

  • Follow the format and structure of the CRISC certification exam
  • Identify the various topics and technical areas covered by the exam
  • Implement specific strategies, tips and techniques for taking and passing the exam
  • Apply practice questions with debriefs of answers

Included in the course fee

Review manual: A comprehensive reference guide designed to help you prepare for the CRISC exam and understand IT-related business Risk Management roles and responsibilities.

QAE Database: A 12-month subscription to a comprehensive 600-question pool of items. Build a custom study plan with a personalized dashboard to track progress and review previously answered questions.

Exam: By successfully passing this exam, you demonstrate your understanding of the key concepts of the CRISC domains, and it is required to complete certification.

Course Dates and Prices