A structured learning curriculum covering all four domains of the CRISC exam: risk identification, assessment, response and mitigation, and information security controls.
This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.
16 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.
Start Chapter 1Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.
Go to practice testEvery CRISCterm defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.
Browse glossaryExam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.
View exam guideIntroduction to IT Risk Management
Objective 1.1 · Identify and recognize the importance of IT risk management in the enterprise
Risk Identification Methodology and Techniques
Objective 1.2 · Identify and describe risk identification techniques and methodologies
The Risk Register and the Threat Landscape
Objective 1.3 · Identify and document internal and external threats, vulnerabilities, and risk scenarios
Risk Owners, Stakeholder Analysis, and Communication
Objective 1.4 · Define roles, responsibilities, and communication channels for risk management
Risk Assessment Approaches and Frameworks
Objective 2.1 · Describe risk assessment methodologies, including quantitative and qualitative approaches
Quantitative Risk Analysis: ALE, SLE, ARO, and More
Objective 2.2 · Perform quantitative risk analysis calculations and interpret results
Qualitative Risk Analysis: Probability and Impact Matrices
Objective 2.3 · Apply qualitative risk analysis using probability and impact scales and heat maps
Risk Assessment Outputs and Reporting
Objective 2.4 · Document and report risk assessment results to support decision-making
Risk Response Options and Strategies: Avoid, Transfer, Mitigate, Accept
Objective 3.1 · Identify and evaluate risk response options and develop response strategies
Risk Treatment Planning and Implementation
Objective 3.2 · Develop and implement risk treatment plans including control selection
Residual Risk, Risk Acceptance, and Risk Appetite Alignment
Objective 3.3 · Evaluate residual risk and facilitate risk acceptance decisions
Risk Mitigation Controls and Ownership
Objective 3.4 · Assign control ownership and monitor the effectiveness of mitigation controls
Information Security Control Frameworks and Standards
Objective 4.1 · Identify and apply information security control frameworks (e.g., NIST, ISO 27001, COBIT)
Control Design, Effectiveness, and Assurance
Objective 4.2 · Evaluate control design and operational effectiveness through testing and monitoring
Key Risk Indicators (KRIs) and Continuous Monitoring
Objective 4.3 · Define, implement, and use key risk indicators to monitor risk and control effectiveness
Incident Response, Business Continuity, and Disaster Recovery
Objective 4.4 · Integrate risk management with incident response, business continuity, and disaster recovery planning
Free CRISC practice questions with full explanations. Test what you learn chapter by chapter.
CRISC Practice Questions