ISACA Certified in Risk and Information Systems Control (CRISC) Cert Prep
6h 3mBeginner2025-12-11
Authors

Cybrary
Course details
A Certified in Risk and Information Systems Control (CRISC) Certification by ISACA enables professionals to demonstrate their IT risk management expertise. This certification prep course provides you with a comprehensive overview of what you will need to pass the certification exam. Explore the four main domain areas covered in the certification exam: Governance, Risk Assessment, Risk Response and Reporting, and Technology and Security. Delve into IT governance, risk identification, assessment, analysis, treatment, and reporting. Review key ideas around enterprise risk management within the IT risk environment. Plus, build your knowledge of key technology and security definitions, concepts, and phrases that are key to IT risk management.
Use real-world examples, frameworks, and case studies to connect concepts within the ISACA prep material to your own experience. In doing so, you will learn this material not only for the exam, but for your professional experiences for years to come.
Learning objectives
Understand and identify the key parts of organizational, IT and risk governance, as well as why it matters to the broader enterprise and its stakeholders.
Use qualitative and quantitative methods to identify, assess and analyze inherent and residual risk
Analyze inherent risk with the broader context to select the appropriate response options.
Design and implement controls that appropriately mitigate risk.
Report on risk using a mix of qualitative and quantitative methods to describe inherent, residual, accepted and emerging risk.
Understand and explain key information technology and security foundational knowledge and apply it to IT Risk concepts.
Use real-world examples, frameworks, and case studies to connect concepts within the ISACA prep material to your own experience. In doing so, you will learn this material not only for the exam, but for your professional experiences for years to come.
Learning objectives
Understand and identify the key parts of organizational, IT and risk governance, as well as why it matters to the broader enterprise and its stakeholders.
Use qualitative and quantitative methods to identify, assess and analyze inherent and residual risk
Analyze inherent risk with the broader context to select the appropriate response options.
Design and implement controls that appropriately mitigate risk.
Report on risk using a mix of qualitative and quantitative methods to describe inherent, residual, accepted and emerging risk.
Understand and explain key information technology and security foundational knowledge and apply it to IT Risk concepts.
Concepts
Introduction
- Welcome to the CRISC course and instructor introduction
Module 1 Course Overview and Instructor Introduction
- IT risk management lifecycle
- Key terms and definitions
Module 2 Domain 1 - Governance
- Organizational governance and risk governance
- Strategy, goals, objectives and risk management
- Organizational culture, ethics and behavior
- External requirements and governance documents
- Risk management standards and guidance from the industry
- Business process reviews and types of business risk
- Asset management
- Business continuity, technology resilience, and disaster recovery
- Enterprise risk management and risk appetite
- Lines of defense model
Module 3 Domain 2 - Risk Assessment
- Risk events and risk factors
- Methods to identify risk and potential changes
- Threats
- Vulnerability management
- IT risk scenarios
- Risk assessment techniques
- Risk ranking
- Risk and control ownership and accountability
- Risk register
- Inherent, residual, and current risk
- Important term differentiation
Module 4 Domain 3 - Risk Response and Reporting
- Risk response options and selection
- Third-party risk and control
- Risk action plans
- Control standards, frameworks, and types of controls
- Control design and selection
- Control testing
- Data collection and reporting
- Metrics
- Monitoring, reporting and associated techniques
- Issues, findings and exceptions
Module 5 Domain 4 - Technology and Security
- Architecture and IT operations
- Networks and configuration management
- SDLC
- Data lifecycle management and data privacy
- Portfolio and project management
- Emerging tech
- Security topics
- Security and risk awareness training
Conclusion
- Course conclusion