Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Masterclass - CRISC Exam (Updated 2026)
Bestseller
Rating: 4.5 out of 5(3,355 ratings)
19,055 students

Masterclass - CRISC Exam (Updated 2026)

Hemang Doshi's course for ISACA's Certified in Risk & Information Systems Control (CRISC) Exam (Updated 2026)
Created byHemang Doshi
Last updated 6/2026
English

What you'll learn

  • ISACA CRISC Lectures
  • Contains all the 4 Domains of CRISC Review Manual

Course content

5 sections213 lectures19h 0m total length
  • Meaning of Risk - Video Lecture6:00

    Explain that risk equals the product of probability and impact, with likelihood and severity guiding evaluation and mitigation.

  • Meaning of Risk - Notes1:40
  • Meaning of Risk - Practice Questions
  • ISACA's Thinking Hat - Video Lecture9:45

    Clarifies Isaka exam jargon and risk concepts, including probability, impact, and the risk assessment process. Compare threat and vulnerability and explain risk treatment options, appetite, tolerance, and capacity.

  • ISACA's Thinking Hat - Notes5:14
  • CIA Principles - Video Lecture8:24

    Explore the CIA principles—confidentiality, integrity, and availability—and non-repudiation, including need-to-know, least privilege, data protection, and recovery planning, plus PKI, encryption, and digital signatures.

  • CIA Principles - Notes3:36
  • CIA Principles - Practice Questions
  • IS Risks & Other Concepts - Video Lecture6:01

    Explore information system risk concepts and principles, including data confidentiality through encapsulation and encryption, role-based access control, impact analysis, risk ranking, and worst-case scenario planning for disasters.

  • IS Risks & Other Concepts - Notes3:06
  • Information Security Risks, Concepts and Principles - Practice Questions
  • Organization Goals, Objectives and Strategies - Video Lecture4:36

    Explore enterprise IT governance, focusing on strategic direction, monitoring, and control to align IT with business goals, manage risks, and add value.

  • Organization Goals, Objectives and Strategies - Notes4:01
  • Key Aspects - Organization Goals, Objectives and Strategy - Video Lecture3:47

    Explore how organizations set goals, objectives, and risk management strategies, align security with business goals, understand structure and governance roles, and ensure it strategy supports corporate objectives under the board.

  • Key Aspects - Organization Goals, Objectives and Strategy - Notes2:40
  • QAE - Organization Goals. Objectives and Strategy - Video Lecture8:09

    Align risk management strategy with business objectives and operations using an internal control framework. Prioritize appropriate controls, enterprise security architecture, and senior management support to safeguard organizational goals.

  • QAE - Organization Goals. Objectives and Strategy - Notes2:04
  • Organization Goals, Objectives and Strategy - Practice Questions
  • IT Risk Strategy of the Business - Video Lecture10:17

    Develop a global policy adaptable to local laws; senior management signs off on risk plans, governance based on organizational complexity and risk culture, appetite, and privacy laws guiding outsourcing.

  • IT Risk Strategy of the Business - Notes3:00
  • IT Risk Strategy of the Business - Practice Questions
  • Enterprise Risk Management Framework - Video Lecture3:19

    Adopt an enterprise wide risk management framework to ensure a consistent approach across all functions. Involve relevant stakeholders who understand business goals and processes to maximize the framework's effectiveness.

  • Enterprise Risk Management Framework - Notes1:12
  • IT Steering Committee - Video Lecture2:23

    Identify the IT steering committee role as monitoring and facilitating resource deployment for projects aligned with the business plan and requirements, with members from senior management, IT, and user management.

  • IT Steering Committee - Notes1:23
  • Aligning Risk Response with Business Objectives - Video Lecture5:19

    Align risk response with business objectives by prioritizing resources to areas with low risk tolerance and aligned risk appetite, and involving stakeholders to ensure risk management supports core goals.

  • Aligning Risk Response with Business Objectives - Notes1:37
  • Aligning Risk Response with Business Objective - Practice Questions
  • IT related Business Risks - Video Lecture4:03

    Identify and analyze it-related business risks, including confidentiality, availability, integrity, infrastructure, investment, project ownership, relevance, and schedule risks, to prepare for the CRISC exam.

  • IT related Business Risks - Notes2:20
  • IT Concept and Areas of Concerns for Risk Practitioner - Video Lecture5:02

    Learn how risk practitioners detect firewall configuration errors via peer review and ensure deployments align with security policy by auditing firewall parameter settings, while addressing farming attack and VPN risks.

  • IT Concept and Areas of Concerns for Risk Practitioner - Notes1:57
  • IT Concepts and Area of Concerns for the Risk Practitioner - Practice Questions
  • Roles in Risk Management - RACI - Video Lecture3:08

    Explore the four risk management roles in the RACI framework—responsible, accountable, consulted, and informed, and learn how each role contributes to the risk management effort.

  • Roles in Risk Management - RACI - Notes2:09
  • Roles in Risk Management - Practice Questions
  • Risk Culture and Communication - Video Lecture7:41

    Explore how risk culture shapes risk appetite and how open communication enables timely escalation of suspicious activity and transparency to external stakeholders.

  • Risk Culture and Communication - Notes2:32
  • Risk Culture & Communication - Practice Questions
  • Policy, Guidelines and Standards - Video Lecture5:03

    Explore how policies set organizational direction, how guidelines and procedures support them, and how standards like ISO 27001 become mandatory; examine data retention factors and policy exceptions.

  • Policy, Guidelines and Standards - Notes2:53
  • QAE - Policy, Guidelines and Standards - Video Lecture6:24

    Explore policies, guidelines, and standards for information security, including data classification policies, data retention in accordance with business requirements, and a global policy approach with regional amendments.

  • Policy, Guidelines and Standards - Practice Questions
  • Business Process Review - Video Lecture4:48

    Explore business process review objectives, measure effectiveness, identify issues, and gather information for improvement by engaging business process owners, then review documentation before risk assessment.

  • Business Process Review - Notes1:54
  • Business Process Review - Practice Questions
  • Elements of Risk - Video Lecture27:02

    Explore the elements of risk, distinguish threat and vulnerability, and learn how to assess and quantify risk, including configuration management and outsourcing contracts.

  • Elements of Risk - Notes2:25
  • Elements of Risk - Practice Questions
  • Three Lines of Defense - Notes1:29
  • Three Lines of Defense - Practice Questions
  • Risk Capacity, Risk Appetite and Risk Tolerance - Video Lecture5:47

    Explore risk capacity, risk appetite, and risk tolerance, and how they guide decisions and resource allocation. Understand alignment with business objectives and the role of the business process owner.

  • Risk Capacity, Risk Appetite and Risk Tolerance - Notes3:30
  • Key Aspects - Risk Capacity, Risk Appetite and Risk Tolerance - Video Lecture6:08

    Explore risk capacity, risk appetite, and risk tolerance, showing how aligning appetite with business objectives directs resources toward areas with low risk tolerance and controls residual risk.

  • Key Aspects - Risk Capacity, Risk Appetite and Risk Tolerance - Notes3:14
  • QAE - Risk Capacity, Risk Appetite and Risk Tolerance - Video Lecture4:15

    Align risk appetite with business objectives to prioritize high risk areas and guide mitigation by considering risk capacity, residual risk, risk tolerance, and risk culture.

  • Risk Capacity, Risk Appetite and Risk Tolerance - Practice Questions
  • Risk Framework, Legal, Regulatory and Contractual Requirements - Notes3:09
  • Risk Framework, Legal, Regulatory & Contractual Requirement - Practice Questions

Requirements

  • Not Applicable

Description

(Note: CISA Exam is conducted by ISACA. This course is private course and not affiliated with ISACA)

This course is aligned with ISACA's CRISC Review Manual (8th Edition) and updated in 2026. Please note that objective of this course is to support and supplement the content of the ISACA's official resources. This course is not meant to replace CRISC Review Manual and Question, Answer and Explanation Manual. Candidates are strongly advised to use ISACA's official resource as prime resource to study for CRISC exam. This course will help you to decipher the technicities used in official resources.


This course is designed on the basis of official resources of ISACA. It covers all the 4 domains of CRISC Review Manual. Topics are arranged segment wise and aligned with latest CRISC Review Manual.


Course is designed specifically for candidates from non-technical background. Video contents are designed after considering three major aspects:


(1) Whether content has capability to engage the audience throughout?

(2) Whether content is able to convey the meaning of CRISC Review Manual  in a effective manner.

(3) Whether video has capability to make audience understand and retain the key aspects for a longer duration.


CRISC  by Hemang Doshi

Features of this course are as follow:


  • This course is designed on the basis of official resources of ISACA.


  • Course is designed specifically for candidates from non-technical background.


  • Topics are arranged segment wise and aligned with latest CRISC Review Manual.

  • Exam oriented practice questions and practical example for CRISC aspirants.


  • Flashcards based learning mode.


  • Use of smartarts for easy learning


  • More than 500 plus practice questions


  • Course also includes 2 full CRISC Mock Test (150 questions each)



Who this course is for:

  • Risk Manager, IT Manager, Auditor
  • IT Auditor, IT Risk Practitioner