The CRISC certification overview covers what the exam tests and who it is for. This guide goes a level deeper: what to study first, the sub-topics ISACA actually tests within each domain, the frameworks you need to know cold, and how to manage the exam itself.
CRISC is written from the perspective of the professional who owns risk decisions, not the engineer who implements a control. For every topic, ask who should own this risk decision and what evidence would justify it, rather than how you would technically fix it.
Study in this order. It follows how the domains build on each other, not just their exam weight.
Start here. It sets the enterprise risk management structure, risk appetite and tolerance, and the lines of defense that every other domain assumes already exists. You cannot reason about a risk response without first knowing the organization's risk appetite.
With governance context in place, layer on how risk is identified, modeled and analyzed: threat landscape, risk registers, and inherent versus residual risk.
The largest domain, and where governance and assessment get operationalized: response selection, control design and testing, and the metrics and reporting that prove any of it is working. Budget the most study time here.
Finish with the technical foundation: architecture, SDLC, data lifecycle and security principles that underpin sound risk and control decisions in the other three domains.
Domains 1 and 3 together are 58 percent of the exam, so if your study time is limited, protect the hours you have allocated to governance and risk response first.
Two sub-areas, per ISACA's official content outline. Organizational Governance covers strategy, goals and objectives, organizational structure and roles, culture and ethics, policies and standards, business resilience including DRP and BCP, and asset management. Risk Governance covers enterprise risk management, lines of defense, the risk profile, risk appetite and tolerance, and applicable risk frameworks and legal, regulatory and contractual requirements.
What to actually master: the lines of defense model, where the first line owns and manages risk day to day, the second line oversees and challenges, and the third line provides independent assurance. Then how risk appetite and tolerance thresholds, set by leadership rather than by risk practitioners, bound every downstream response decision.
Common trap: recommending a risk response based on what is technically achievable rather than what fits within the organization's stated risk appetite.
Two sub-areas. Risk Identification covers risk events, threat modeling and the threat landscape, vulnerability management, and risk scenario development and evaluation. Risk Analysis covers risk assessment concepts and standards, business impact analysis, the risk register, risk analysis methodologies, and inherent versus residual risk.
What to actually master: the distinction between inherent risk, before any controls, and residual risk, after controls are applied. CRISC tests this constantly, because the whole point of a control is to move risk from inherent toward an acceptable residual level. Also know how a risk register is maintained and rolled up into the enterprise-wide risk profile.
Common trap: reporting inherent risk as if it were the current risk level when controls are already in place. The exam expects you to know which figure applies to which decision.
Three sub-areas, and the most sub-topic-dense domain on the exam. Risk Response covers response options, risk and control ownership, vendor and supply-chain risk, and issues, findings and exceptions management. Control Design and Implementation covers control frameworks and standards, control design, selection, implementation and analysis, and control testing methodologies. Risk Monitoring and Reporting covers risk action plans, data aggregation and validation, risk and control metrics including KRIs, KCIs and KPIs, monitoring and reporting techniques such as heatmaps, scorecards and dashboards, and monitoring of emerging risks.
What to actually master: the four standard risk response options, accept, mitigate, transfer and avoid, and matching a scenario to the right one. The difference between a key risk indicator, which is forward-looking, and a key control indicator, which looks backward at control performance. And vendor and supply-chain risk, which is frequently underweighted relative to how often it is tested.
Common trap: treating "we selected a control" as equivalent to "we tested and validated the control". Like CISM, CRISC draws a hard line between control design and selection on one side and control testing on the other.
Two sub-areas. Technology and Security covers technology principles, technology roadmaps and enterprise architecture, operations management including change management, DevOps and incidents, the system development life cycle, data lifecycle management, portfolio and project management including Agile, technology resilience and disaster response and recovery, and emerging technologies. Information Security Principles covers security concepts, frameworks and standards, security and risk awareness training, and data privacy and protection principles.
What to actually master: where risk controls need to be embedded in the SDLC, since the earlier a control is designed in the cheaper it is to fix problems. And how emerging technology introduces new risk scenarios rather than just new technical capability. CRISC tests your ability to spot the risk angle in a technology change, not the technology itself.
Common trap: answering a Domain 4 question as a pure technology question rather than tying the technology back to a risk or control implication. This domain is still a risk-management domain wearing a technical topic list.
You do not need to be a practitioner in any of these. CRISC tests whether you know when and why a risk professional would reference each one, not how to implement them.
Check ISACA's current CRISC page for the exact requirement. Unlike CISM's published five-year threshold, CRISC's experience and waiver policy is subject to more frequent updates, so confirm it directly with ISACA before you register.
Managerial, with a technical foundation in Domain 4. It assumes enough technology literacy to evaluate risk in a system or process, but it tests risk-ownership judgment throughout.
Domain 3, Risk Response and Reporting, at 32 percent, followed by Domain 1, Governance, at 26 percent. Together they are well over half the exam.
CRISC focuses on identifying, assessing and responding to IT and enterprise risk and the controls that manage it. CISM focuses on building and leading the security program and team that implements those controls. They pair well together but test different roles.
Governance at 26 percent, Risk Assessment at 22 percent, Risk Response and Reporting at 32 percent, and Technology and Security at 20 percent.
A key risk indicator is forward-looking and signals that risk exposure is changing. A key control indicator looks backward at how well a control has been performing. CRISC expects you to know which one a given scenario calls for.
450 on a 200 to 800 scaled range. Not all questions are scored, since some are unscored pretest items, so you cannot work out your standing during the exam.
Domain weights and sub-topics are sourced from ISACA's official CRISC Exam Content Outline. Confirm current fees, experience requirements, CPE policy and exam details at isaca.org before you register.