ABOUT: The Certified in Risk and Information Systems Control (CRISC®) certification, awarded by ISACA®, is a globally recognized credential that demonstrates expertise in IT risk management and the design, implementation, and maintenance of information system controls. This certification validates your ability to manage risk and ensures your organization’s information systems are robust and secure.
CERTIFICATION BODY: ISACA® (Information Systems Audit and Control Association), a global leader in IT governance, risk management, and cybersecurity certifications.
LEARNING OBJECTIVE: The CRISC® certification aims to equip professionals with the skills and knowledge required to effectively identify, assess, and manage IT risks. It covers critical areas such as risk assessment, response strategies, and the implementation and monitoring of information system controls. The goal is to enhance your ability to contribute to business objectives by managing IT risks and ensuring the resilience and security of information systems.
EXAM INFORMATION:
- Format: Multiple-choice
- Number of Questions: 150
- Duration: 4 hours (240 minutes)
- Domains Covered:
- Governance (26%)
- IT Risk Assessment (20%)
- Risk Response and Reporting (32%)
- Information Technology and Security (22%)
RE-CERTIFICATION: To maintain CRISC certification, professionals must:
- Earn at least 20 Continuing Professional Education (CPE) credits annually and a total of 120 CPEs over a three-year period.
- Comply with ISACA’s Code of Professional Ethics.
- Pay an annual maintenance fee of $45 for members and $85 for nonmembers.
- Potentially participate in an Annual CPE Audit, which is selected randomly.
Curriculum
- 4 Sections
- 9 Lessons
- 40 Hours
- Governance2
- IT Risk Assessment2
- Risk Response and Reporting3
- Information Technology and Security2
Requirements
- Have a minimum of three years of cumulative work experience in IT risk management and information system control.
- Have experience in at least two of the four CRISC domains, with at least one domain being either Governance or IT Risk Assessment.
- While you can sit for the CRISC exam without the prerequisite experience, certification will only be granted once the experience requirements are met.
Target audiences
- IT professionals
- Risk professionals
- Business analysts
- Project managers
- Compliance professionals
- Anyone involved in risk identification, assessment, evaluation, response, monitoring, and the design, implementation, and maintenance of information systems controls.