CRISC – Certified in Risk and Information Systems Control
The Certified in Risk and Information Systems Control (CRISC) exam by ISACA is a globally recognized certification designed for IT professionals, risk management professionals, and control professionals who identify and manage risks through the development, implementation, and maintenance of information systems (IS) controls.
Key Facts About the CRISC Exam
- Offered by: ISACA (Information Systems Audit and Control Association)
- Focus: Enterprise IT risk management and control
- Certification Goal: Validate expertise in identifying, assessing, and mitigating enterprise risks, and implementing and maintaining information systems controls.
Ideal Candidates
The CRISC exam is designed for:
- Risk professionals
- Control professionals
- IT professionals involved in risk management or system control
- Security professionals working on enterprise governance, risk, and compliance (GRC)
Benefits of CRISC Certification
- Demonstrates expertise in enterprise IT risk management.
- Enhances credibility with stakeholders, clients, and regulators.
- Provides better career opportunities in risk management and IT governance.
- Supports organizations in aligning IT risk management with business goals.
CRISC Domains (Effective 2021)
The exam is based on four key domains:
- Domain 1: Governance (26%)
- Domain 2: IT Risk Assessment (20%)
- Domain 3: Risk Response and Reporting (32%)
- Domain 4: Information Technology and Security (22%)
Training Methodology
- Instructor-led training online via Zoom/MS Teams
- Presentation/slides
Course Information
- Timing: 9:00 AM – 5:00 PM or 3 hours daily as per mutual agreement
- Course duration: 32 Hours
- Venue: Online
- Language: Mainly English
Curriculum
- 4 Sections
- 9 Lessons
- 2 Weeks
- DOMAIN 1 – GOVERNANCEThe governance domain interrogates your knowledge of information about an organization’s business and IT environments, organizational strategy, goals and objectives, and examines potential or realized impacts of IT risk to the organization’s business objectives and operations, including Enterprise Risk Management and Risk Management Framework.2
- DOMAIN 2 – IT RISK ASSESSMENTThis domain will certify your knowledge of threats and vulnerabilities to the organization’s people, processes and technology as well as the likelihood and impact of threats, vulnerabilities and risk scenarios.2
- DOMAIN 3 – RISK RESPONSE AND REPORTINGThis domain deals with the development and management of risk treatment plans among key stakeholders, the evaluation of existing controls and improving effectiveness for IT risk mitigation, and the assessment of relevant risk and control information to applicable stakeholders.3
- DOMAIN 4 – INFORMATION TECHNOLOGY AND SECURITYIn this domain we interrogate the alignment of business practices with Risk Management and Information Security frameworks and standards, as well as the development of a risk-aware culture and implementation of security awareness training.2
A seasoned professional with 17+ years of experience in the Payment Industry, Financial Industry (Commercial and Microfinance Banks), FMCG, and ISP sector.
Besides academic qualifications of MS in Computer Science and B.Sc. (Hons) in Computer Science, his professional qualification includes International certifications of CISSP, CCSP, CRISC, CISA, CISM, CGEIT, ISMS LA ISO27001, ISO27005 SLRM, and ITIL.
He holds top-rated professional certifications. He is also a regular/professional trainer for CISSP, CCSP, CISA, CISM, CGEIT, CRISC, and ITIL.
He has experience in Information/Cyber Security Management, IT Governance and management, Risk and Compliance Management, IS Audit & Controls, IT Services Management, Business Solutions & IT Operations, Business Continuity & DR Management, and Project Management.
His multiple courses are available on Udemy.com and are highly rated.
Courses you might be interested in
-
10 Lessons
-
36 Lessons
-
8 Lessons
-
9 Lessons