
Discover how this CRISC course covers governance, IT risk assessment, risk response and reporting, and information technology and security to prepare you for CRISC.
Explore governance and IT risk management in CRISC, highlighting four governance questions, board accountability, risk practitioner advisory role, RACI concepts, and the risk cycle from identify to monitor with controls.
Explore key risk concepts for CRISC, including taxonomy, likelihood, consequence, threats, opportunities, vulnerabilities, and risk scenarios. Learn to communicate risk to senior management using quantitative impacts and cost benefit reasoning.
Understand the value of IT risk management and its alignment with business goals. See how identifying threats, prioritizing responses, and senior management support drive project success and compliance.
This lecture explains the RACI chart and its four roles—responsible, accountable, consulted, informed—how it defines team roles and accountability in risk, with exam-style examples.
Explore CRISC risk management roles including the risk manager, risk analyst, risk owner, control owner, control steward, and SMEs, with clear accountability, responsibility, and consulted or informed duties.
Align organizational structure with a risk-aware culture and establish enterprise mandates that enable cross-department communication, collaboration, and proactive ownership of risk management.
Learn how culture drives risk behavior from senior leadership to the boots on the ground. See how risk awareness fosters risk culture, governance, and information security controls.
Learn how risk culture arises from behavior toward risk, policy compliance, and negative outcomes, and how misalignment with risk appetite, along with the blame culture, undermines risk management.
Learn how risk communication turns data into actionable information, guiding senior management and external stakeholders through balanced reporting and informed decision making.
Explore how policies, standards, and procedures shape governance, compliance, and risk management in CRISC, with ISO 27001 guidance, risk appetite, exceptions, and compensating controls.
Align risk management with business goals by reviewing and documenting current processes, engaging knowledgeable people from all departments, and applying gap analysis to drive continuous improvement.
Explore risk management principles, processes, and controls, and learn to align IT risk with business objectives through cost-benefit analysis, open communication, and continuous improvement.
Explore how IT risk relates to other business functions, balancing risk appetite, risk capacity, and tolerances while integrating BCM, audits, and controls to protect the enterprise.
Explore how project risk anchors information technology risk management to protect value and enterprise goals, highlighting scoping, scope creep, change management, and the change advisory board in the risk lifecycle.
Explore how people and technology interact to create risk in IT environments, covering culture, cross-training, retention, incentives, and data lifecycle from hardware refresh and disposal to data retention and accountability.
Identify data and intellectual property as core assets, classify data by business value and security needs, and protect trademarks, copyrights, patents, and trade secrets with NDAs and access controls.
Apply IT risk management best practices through coordinated activities to direct and control risk and support business goals. Maintain comprehensive, auditable, compliant, and continuously monitored risk management with clear scoping.
Explore the three lines of defense model for risk and information systems control, detailing operational management, risk and compliance functions, and audit to clarify roles and enhance communication.
Explore how a risk profile delivers a dynamic view of risk posture, appetite, tolerance, capacity, and controls for proactive identification and response.
Explore ISACA CRISC concepts of risk appetite, tolerance, and capacity, defining residual risk and the roles of the board and senior management in setting policies and risk response.
Explore how legal, contractual, and regulatory requirements shape risk management in CRISC, including HIPAA, GDPR, PCI DSS, and Sarbanes-Oxley, with guidance on compliance decisions and ethics.
Explore identifying risk events in this CRISC course, learn to assess threats by probability and impact, identify assets, consult with business process owners, and craft risk responses.
Identify risk factors to understand how contextual and capability factors shape risk events against assets, using COBIT 2019 domains and the risk register for analysis, evaluation, and management.
Learn how changes in the risk environment impact risk identification, monitoring, and response through incident and change management, forecasting, and continuous improvement.
Learn to map the threat landscape and model threats by classifying internal, external, and emerging threats. Document threats and use information from providers, audits, and product vendors to shape responses.
Explore threat modeling and abuse case modeling, identifying threat actors, indicators of compromise and attack, and risk identification, with methods like stride, pasta, Lindoun, and attack trees.
Explore sources of vulnerabilities across networks, physical access, web apps, and cloud and big data. Learn to identify misconfigurations and weak access controls, and apply risk identification and monitoring.
Distinguish vulnerability assessments and penetration testing as distinct processes, and explore manual versus automated testing, scope, OSINT, and gap analysis within CRISC.
develop and analyze risk scenarios to identify potential threats, assess uncertain impacts, and align with business objectives using top-down and bottom-up approaches, guided by FAIR and HARM methodologies.
Explore risk assessment standards and frameworks and how they guide qualitative and quantitative analysis. Review methods like bow tie, Delphi, event tree, fault tree, Markov, Monte Carlo, and Swift.
Choose and apply risk assessment tools wisely to drive accurate risk responses. Maintain a living risk register, rank risks with Pareto analysis, and map outcomes with risk maps.
Explore qualitative and quantitative risk analysis methods, including EMV, ALE, Monte Carlo, and root cause analysis with the Ishikawa diagram, for informed CRISC risk responses.
Identify and prioritize critical services through business impact analysis, enabling disaster recovery and continuity planning with defined recovery time and data loss objectives, guiding risk responses and recovery strategies.
Explore inherent risk, residual risk, and current risk, and how risk appetite, risk tolerance, and risk responses—accept, avoid, mitigate, transfer—shape what's left.
Explore the four risk responses: mitigation, transference, avoidance, and acceptance, and how they align risk with business appetite, tolerance, and capacity through risk assessment, monitoring, and reporting.
Senior management consciously accepts risk within appetite, formalizing the decision with a paper trail and self-insurance reserves; reassess residual risk after mitigation through ongoing reviews.
Assign a single risk owner at the appropriate management level, document ownership in the risk register, drive risk management activities, and aggregate risks to align with strategic risk appetite.
Learn how to manage third-party risk through outsourcing, not transferring liability, with emphasis on data ownership, contracts, service level agreements, and incident and data retention considerations.
Identify issues and exceptions in risk management and apply formal configuration, change, and release controls to mitigate risk. Implement a change advisory board to document exceptions in the risk register.
Identify and manage emergent risk as a dynamic, continuous lifecycle, adapting controls amid evolving technology, cloud, and shadow IT through formal adoption, monitoring, and testing.
Leverage open standards and frameworks to select and implement preventative, detective, deterrent, corrective, and compensating controls across administrative, technical, and physical domains for risk mitigation and governance.
design and select physical, technical, and administrative controls, analyze the current state, perform gap analysis, and apply proactive safeguards or reactive countermeasures within the risk management life cycle.
Learn how to implement and test administrative, technical, and physical controls, using cloud-based test environments, change management, and three changeover methods to manage data migration and maintain business continuity.
Learn how to test controls effectively through post-implementation reviews, progressive and regressive testing, and best practices like data masking, environmental separation, and version control to ensure CRISC risk management.
Develop risk response plans by selecting from avoid, mitigate, transfer, or accept within risk appetite and tolerance, then document a risk treatment plan in the risk register.
Learn how risk practitioners collect, aggregate, analyze, and validate data from diverse sources—including audit reports, incident logs, gap analysis, and cloud tools—to identify and assess risk factors.
Master monitoring techniques for risk and information systems controls by planning observability, identifying risk control owners, engaging stakeholders, and applying audits, vulnerability assessments, and penetration testing.
Master reporting techniques for risk and control using heat maps, scorecards, and dashboards. Turn data quality, timely analysis, and visualizations into clear updates for management and the board.
Learn how key performance indicators (KPIs) measure process performance against SMART targets and guide risk monitoring, with dashboards tracking KPIs as leading indicators of mitigation effectiveness.
Identify key risk indicators (KRIs) and how they measure risk against thresholds, using leading and lagging indicators, balance and root-cause analysis, alongside KPIs, for proactive risk management.
Explore key control indicators (KCIs) that measure control effectiveness, quantify mitigation against risk tolerances, and serve as leading indicators for KRIs linked to that control.
Assess the scope of enterprise architecture to ensure we do the right things, the right way, and deliver benefits using frameworks like Togap and Zachman aligned with business objectives.
Explore hardware and software risk in information systems within CRISC. The lesson covers obsolescence, misconfiguration, physical access, supply chain, and software issues like patching, version control, and data exposure.
Explore networking fundamentals in a risk context, covering TCP/IP and the OSI model, encapsulation, and key infrastructure such as switches, routers, firewalls, DNS, DHCP, VPN, and VLANs.
Explore how virtualization gave rise to cloud, with public, private, and hybrid models, and how data at rest, in transit, and in use must be protected in outsourced cloud environments.
Discover how project management integrates risk assessment, communication, scheduling, cost, and quality across waterfall and agile approaches, including program management for efficient resource allocation.
Learn how disaster recovery and business continuity collaborate, guided by a business impact analysis that defines recovery point objective (RPO) and recovery time objective (RTO) for resilient operations.
Explore risk in the data lifecycle from creation to destruction, and apply data classification, whitelist and blacklist strategies, and cloud access controls with least privilege and separation of duty.
Explore the system development lifecycle from a CRISC perspective, documenting risks in a risk register, categorizing systems, and applying CIA/ICA, privacy, and vendor risk considerations.
Explore emerging technologies and their risks—from cloud and omnipresent connectivity to IoT, BYOD, AI deepfakes, and blockchain—through a CRISC lens.
Explore information security concepts from a CRISC perspective, focusing on protecting data, confidentiality and integrity, and establishing risk management with reliable policies and controls.
Review the CIA triangle—confidentiality, integrity, and availability—and how non-repudiation links them for risk management. Explore least privilege, need to know, system authorization, and the importance of high availability and redundancy.
Master access control by applying identification, authentication, authorization, and accountability, with least privilege and audit logs to govern data and system access.
Explain encryption as a mathematical method that turns plain text into ciphertext to protect confidentiality. Compare symmetric and asymmetric schemes, including AES, public and private keys, PKI, and digital signatures.
Learn how human factors drive information security risk and why security awareness training matters, covering social engineering, spearfishing, reporting incidents, and the role of policies, scope, and least privilege.
Explore data privacy fundamentals in CRISC, contrast privacy and confidentiality, and examine PII, GDPR, informed consent, PIA, minimization, destruction, and risk monitoring for regulatory compliance.
The ISACA Certified in Risk and Information Systems Control certification is one of the top risk management certifications in the world. This course will help prepare you to be acknowledged as a Risk Management expert. Taking a proactive approach based on Agile methodology, you’ll learn how to enhance your company’s business resilience, deliver stakeholder value and optimize Risk Management across the enterprise. This course covers areas of risk governance, policies and controls. You will also learn and understand the risk management lifecycle with a focus on IT systems security and control.
The CRISC certification course is designed to provide professionals with the knowledge and skills required to effectively manage IT risks and implement information systems controls within organizations. The course covers essential concepts related to risk identification, assessment, evaluation, response, and control, as well as the integration of risk management practices with overall business objectives.
CRISC is intended for professionals who work in the fields of IT risk management, control assurance, and governance.
While there are no strict prerequisites for attending a CRISC preparation course, it's recommended that participants have some background in IT risk management, information security, and related areas. The CRISC certification is typically intended for professionals who have at least three years of cumulative work experience in at least three of the four domains covered by the CRISC exam.