ISACA CRISC Study Guide: Four Domains of IT Risk and Controls

Prepare for ISACA CRISC with the 2025 four-domain outline, exam weights, experience requirements, and a practical IT risk study plan.

ISACA CRISC (Certified in Risk and Information Systems Control) is for professionals who identify, assess, respond to, and monitor IT risk, and design or maintain information systems controls. The central skill is translating technology risk into business impact so organizations can make informed decisions.

This guide follows the 2025 CRISC exam outline. The exam covers Governance, Risk Assessment, Risk Response and Reporting, and Technology and Security. Use the current official outline when planning your studies.

Who is this exam for?

CRISC suits IT risk managers, risk analysts, control and compliance professionals, auditors, information security practitioners, system owners, and vendor risk managers. You may take the exam before meeting the experience requirement, but certification requires qualifying work experience.

Exam format and experience requirement

The CRISC exam has 150 multiple-choice questions and lasts four hours. ISACA reports scores on a 200–800 scale; 450 or higher is passing. After passing, certification generally requires at least three years of professional information systems audit, control, or security experience across at least two of the four CRISC domains, consistent with CRISC job practices. Experience must be gained within the ten years before application; the certification currently does not offer experience waivers. Apply within five years of passing. Check official certification requirements.

Four exam domains and weights

Domain Main topics Weight
1. Governance Organizational strategy, roles, risk governance, appetite, policy, resilience 26%
2. Risk Assessment Risk identification, threats and weaknesses, scenarios, impact and likelihood 22%
3. Risk Response and Reporting Risk treatment, control design and implementation, metrics, monitoring, reporting 32%
4. Technology and Security Technology operations, system life cycle, data, security principles, resilience 20%

Domain 3 carries the most weight, but effective risk response depends on sound governance and assessment. Study the full chain: “business objective → risk scenario → assessment → owner → response → monitoring → reporting.”

How to study the four domains

1. Governance

Understand organizational strategy, objectives, structure, roles, culture, policies, and asset management. Risk governance includes enterprise risk management, lines of defense, the risk profile, risk appetite and tolerance, and legal, regulatory, and contractual requirements.

Risk appetite expresses the organization’s overall willingness to accept risk; tolerance turns that preference into practical boundaries. Risk professionals help stakeholders define these limits and responsibilities, but should not accept risk on behalf of a business owner.

2. Risk Assessment

Identify risk events affecting people, processes, and technology. Analyze threats, weaknesses, and control deficiencies, and build business-relevant risk scenarios. Consider likelihood, impact, existing controls, inherent risk, and residual risk.

A risk register records scenarios, owners, assessments, treatment decisions, and status. Do not stop at listing technical vulnerabilities; explain how they could affect business objectives, critical services, finances, reputation, or compliance.

3. Risk Response and Reporting

Compare acceptance, reduction, transfer, and avoidance. Clarify risk and control ownership, manage supply chain risk, exceptions, and remediation findings. Study control frameworks, control design and implementation, testing, risk action plans, and ongoing monitoring.

Understand the different purposes of Key Risk Indicators (KRIs), Key Control Indicators (KCIs), and Key Performance Indicators (KPIs). Metrics should support decisions and expose trends, not exist just for reporting. Tailor reports to explain changes in risk, control status, and decisions needed by each stakeholder.

4. Technology and Security

Review enterprise architecture, technology roadmaps, change and asset management, DevOps, incident and problem management, the system development life cycle, data lifecycle, portfolio and project management, technology resilience, and emerging technology.

The information security section covers frameworks, standards, awareness, privacy, and data protection. CRISC focuses on understanding technology through risk and control: explain how a technology change introduces threats, alters controls, or affects business resilience instead of memorizing product settings.

Concepts that are easy to confuse

  • Risk appetite and tolerance: Appetite is the organization’s overall willingness to accept risk; tolerance is a boundary for a specific objective or measure.
  • Inherent and residual risk: Inherent risk is considered before controls; residual risk remains after existing controls operate.
  • Risk owner and control owner: The risk owner makes risk decisions; the control owner designs or operates a specific control.
  • KRI, KCI, and KPI: A KRI tracks risk, a KCI tracks a control, and a KPI measures performance; they answer different questions.
  • Risk treatment and control implementation: The risk owner decides on treatment; control teams design or implement controls, then work together to validate results.

Six-week study plan

Week Focus Suggested outcome
1 Governance, strategy, appetite, and responsibilities Explain risk governance and authority in relation to business goals
2 Risk identification, scenarios, analysis, and registers Assess a scenario that includes business impact
3 Risk response and risk/control ownership Compare treatment options and assign responsibilities
4 Control design, testing, supply chain, and remediation Explain how a control reduces a specific risk and how to verify it
5 Metrics, monitoring, reporting, technology, and security Select measures and communicate risk to decision makers
6 Integrated scenarios and weak-area review Connect identification, response, monitoring, and reporting

For each practice question, identify the business objective and risk boundary before deciding on the scenario, owner, control, and reporting audience. Classify missed questions by risk concepts, responsibility, response selection, or metric interpretation.

Exam readiness checklist

  • Explain all four domains and weights using the 2025 official outline.
  • Build risk scenarios that connect technology threats to business impact.
  • Distinguish inherent risk, residual risk, appetite, and tolerance.
  • Assign responsibilities to risk owners and control owners correctly.
  • Select a risk response and validate it through metrics, monitoring, and reporting.
  • Verify experience eligibility, application deadlines, and exam arrangements.

What to practice next

CRISC scenarios connect risk to business outcomes. Explain what could happen, what it would affect, who can decide on a response, and how to confirm the risk is within acceptable limits. Start CRISC practice

WeChat mini program

IT知习 mini program QR code

Search WeChat for: IT知习