Gain instant recognition and credibility in risk management with the Certified in Risk and Information Systems Control credential.

  • Why you should get CRISC certified: Prepares IT professionals like you for real-world threats with relevant tools to assess, govern and mitigate risk.
  • Why CRISC matters: The global risk management market size was valued at $7.39 billion in 2019 and is projected to reach $28.87 billion by 2027, growing at a CAGR of 18.7% from 2020 to 2027.
  • Who should get CRISC certified: Mid- to high-level professionals with three or more years of experience in the management of IT risk, as well as the design, implementation, monitoring and maintenance of IS controls.

The ISACA CRISC is the only certification that prepares and enables IT professionals for the unique challenges of IT and enterprise risk management, and positions them to become strategic partners to the enterprise.

HRDC Claimable and Malaysian Bumiputeras are eligible for Yayasan Peneraju Financing Scheme. T&C applies.

Overview

The only globally accepted IT risk management certification for professionals with three or more years of experience.

This credential demonstrates expertise in identifying and managing enterprise IT risk and implementing and maintaining information systems controls. CRISC can enhance your IT team’s credibility with stakeholders and clients.

The artificial intelligence revolution is rewriting the rules of cybersecurity, and the financial stakes are massive. AI-powered cybersecurity will skyrocket from $15 billion in 2021 to a staggering $135 billion by the end of the decade – Artificial Intelligence in Cybersecurity Market Analysis

In this course, you’ll cover all four domains of the Certified in Risk and Information Systems Control (CRISC) exam and gain the knowledge and concepts required to obtain CRISC certification. Since its inception in 2010, the CRISC certification is for IT and business professionals who identify and manage risks through the development, implementation, and maintenance of appropriate information systems (IS) controls.

Here are five insightful blog posts about ISACA and its cybersecurity certifications. Each one focuses on a different aspect of how ISACA’s training can enhance your cybersecurity career, take a read: 

Explore more about cybersecurity certifications with our cybersecurity training and certifications guide.

Skills Covered

Students will master the four CRISC domains:

  • Governance
  • IT Risk Assessment
  • Risk Response and Reporting
  • Information Technology and Security

Prerequisites

IT risk management professionals with at least 3 years of relevant professional work experience in IT risk and information systems control.

Target Audience

The CRISC certification is designed for:

  • IT Managers
  • IT Risk Analysts
  • IT Consultants
  • IT Risk/Security Advisory Managers
  • IT Compliance Managers
  • IT Risk Assessment Specialists

Course Curriculum

Domain 1: Governance

A. Organizational Governance

  • Strategy, Goals, and Objectives
  • Organizational Structure, Roles, and Responsibilities
  • Organizational Culture and Ethics
  • Policies and Standards
  • Business Processes and Resilience (e.g., DRP, BCP)
  • Organizational Asset Management

B. Risk Governance

  • Enterprise Risk Management (ERM)
  • Lines of Defense
  • Risk Profile
  • Risk Appetite and Risk Tolerance
  • Risk Frameworks, Legal, Regulatory, and Contractual Requirements

Domain 2: Risk Assessment

A. Risk Identification

  • Threat Modeling and Threat Landscape
  • Vulnerability Management
  • Risk Scenario Development and Evaluation

B. Risk Analysis

  • Risk Assessment Concepts and Standards
  • Business Impact Analysis (BIA)
  • Risk Register
  • Risk Analysis Methodologies
  • Inherent and Residual Risk

Domain 3: Risk Response and Reporting

A. Risk Response

  • Risk Response Options
  • Risk and Control Ownership
  • Vendor/Supply Chain Risk Management
  • Issues, Findings, Exceptions and Exemptions Management

B. Control Design and Implementation

  • Control Frameworks, Types, and Standards
  • Control Design, Selection, Implementation, and Analysis
  • Control Testing Methodologies

C. Risk Monitoring and Reporting

  • Risk Action Plans
  • Data Collection, Aggregation, Analysis, and Validation
  • Risk and Control Metrics (e.g., KRIs, KCIs, KPIs)
  • Risk and Control Monitoring Techniques
  • Risk and Control Reporting Techniques (e.g., heatmap, scorecards, dashboards)
  • Monitoring and Reporting of Emerging Risks

Domain 4: Technology and Security

A. Technology Principles

  • Technology Roadmaps and Enterprise Architecture (EA)
  • Operations Management (e.g., change management, assets, DevOps, problems, incidents)
  • System Development Life Cycle (SDLC)
  • Data Lifecycle Management
  • Portfolio and Project Management (e.g. Agile)
  • Technology Resilience and Disaster Response/Recovery
  • Emerging Technologies

B. Information Security Principles

  • Security Concepts, Frameworks, and Standards
  • Security/Risk Awareness and Training
  • Data Privacy and Data Protection Principles

Dates & Locations

Let’s make it work for you

Can’t find a date that fits? Need to train your whole team? Looking for a discount?
Speak to one of our learning experts today.

November 10, 2026 - November 13, 2026

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
Included

November 10, 2026 - November 13, 2026

Location: Online
Modal: VILT
Availability: TBC
Exam:
Included
Trainocate exam and cert

Exam & Certification

CRISC: Certified in Risk and Information Systems Control

Get CRISC certified and join an elite group of IT professionals recognized and sought after for their expertise. This is a designation that will get you instant credibility with peers, stakeholders and regulators.

Training & Certification Guide

Exam Duration

  • 150 Questions
  • Must be completed in four (4) hours

Expired Required

  • 3+ years of work experience in IT risk and information systems control
  • To maintain your CRISC, you must earn and report a minimum of 120 CPE hours every 3-year reporting cycle and at least 20 hours annually.
  • CRISC awards up to 1 hour of CPE for every 1 hour of instructor-led training.
  • Online review course earns 15 CPEs and the Virtual Instructor-Led Training (VILT) earns 14 CPEs.

ISACA’s Certified in Risk and Information Systems Control (CRISC) reflects the latest work practices and knowledge used by CRISC practitioners, changes in the business landscape and the heightened focus on corporate governance and enhanced business resilience. Employers can rest assured that armed with CRISC, their IT team is following governance best practices and taking a proactive, agile approach to ITRM that mitigates risks and threats and optimizes resources and ROI.

The final step to becoming CRISC certified is to submit your CRISC Certification Application. Prior to doing so, you must meet the following requirements:

  • Pass the CRISC Exam within the last 5 years.
  • Have the relevant full-time work experience in the CRISC exam content outline.
  • Submit the CRISC Certification Application including the application processing fee.
  • The CISM certification, also from ISACA, targets advanced IT security managers.
  • Focusing on high-level IT security management, it enhances the perception of IT security teams and demands a deep understanding of business.
  • With four key areas of focus, CISM holders communicate vulnerabilities effectively and balance priorities.

Certified Information Systems Auditor (CISA)

  • The CISA certification from ISACA is for IT professionals auditing, monitoring, and assessing information technology and business systems.
  • With five key domains and at least five years of relevant experience, CISAs ensure compliance and minimize risks.
  • Recognized globally, CISA holders advance to senior roles like IT auditor or chief information security officer.

Certified in the Governance of Enterprise IT (CGEIT)

  • The CGEIT certification, also from ISACA, sets IT governance professionals apart. Focusing on assessing, designing, and managing IT governance systems aligned with organizational goals, CGEIT maximizes business value through effective governance.
  • With five key areas of focus, CGEIT holders lead strategic decision-making within the IT governance landscape.

Certified Data Privacy Solutions Engineer (CDPSE)

  • The CDPSE: Certified Data Privacy Solutions Engineer certification provides a valid and reliable means for enterprises to identify technologists who are competent in incorporating privacy by design into technology platforms, products and processes, communicating with legal professionals, and keeping the organization compliant efficiently and cost effectively.

Advanced in AI Audit (AAIA)

  • The ISACA Advanced in AI Audit (AAIA) certification empowers audit professionals to recognize, assess and respond to AI risks, opportunities and impacts—while also using AI to enhance audit workflows and deliver deeper insights.

Advanced in AI Security Management (AAISM)

  • ISACA Advanced in AI Security Management (AAISM) validates security management professionals’ ability to demonstrate their expertise in AI. This credential builds upon existing security best practices to enhance expertise and adapt to the evolving AI-driven landscape, ensuring robust protection and a strategic edge.

Frequently Asked Questions

ISACA’s Certified in Risk and Information Systems Control (CRISC) certification is ideal for mid-career IT/IS audit, risk and security professionals. Register now for the updated CRISC exam―prove your skills and knowledge in using governance best practices and continuous risk monitoring and reporting. enhance business resilience and stakeholder value and gain increased credibility with peers, stakeholders and regulators.

Speak to a Training Consultant

All courses are HRD Claimable.
Get in touch with our team via the form or WhatsApp us on +6011-5119 6631

Preferred mode of training
Checkboxes