Courseiva
CRISCFree Study Guide

Certified in Risk and Information Systems ControlThe Complete Beginner's Guide

A structured learning curriculum covering all four domains of the CRISC exam: risk identification, assessment, response and mitigation, and information security controls.

16 chapters
~3 hours total read
Free — no signup required
By Johnson Ajibi · Senior Network & Security Engineer · MSc IT Security

How to use this guide

This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.

① Read a chapter② Answer practice questions③ Review missed answers④ Repeat
Study Chapters

16 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.

Start Chapter 1
Practice Questions

Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.

Go to practice test
Glossary

Every CRISCterm defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.

Browse glossary
Exam Overview

Exam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.

View exam guide

Chapters — CRISC

1

Introduction to IT Risk Management

Objective 1.1 · Identify and recognize the importance of IT risk management in the enterprise

12m
2

Risk Identification Methodology and Techniques

Objective 1.2 · Identify and describe risk identification techniques and methodologies

12m
3

The Risk Register and the Threat Landscape

Objective 1.3 · Identify and document internal and external threats, vulnerabilities, and risk scenarios

12m
4

Risk Owners, Stakeholder Analysis, and Communication

Objective 1.4 · Define roles, responsibilities, and communication channels for risk management

12m
5

Risk Assessment Approaches and Frameworks

Objective 2.1 · Describe risk assessment methodologies, including quantitative and qualitative approaches

12m
6

Quantitative Risk Analysis: ALE, SLE, ARO, and More

Objective 2.2 · Perform quantitative risk analysis calculations and interpret results

12m
7

Qualitative Risk Analysis: Probability and Impact Matrices

Objective 2.3 · Apply qualitative risk analysis using probability and impact scales and heat maps

12m
8

Risk Assessment Outputs and Reporting

Objective 2.4 · Document and report risk assessment results to support decision-making

12m
9

Risk Response Options and Strategies: Avoid, Transfer, Mitigate, Accept

Objective 3.1 · Identify and evaluate risk response options and develop response strategies

12m
10

Risk Treatment Planning and Implementation

Objective 3.2 · Develop and implement risk treatment plans including control selection

12m
11

Residual Risk, Risk Acceptance, and Risk Appetite Alignment

Objective 3.3 · Evaluate residual risk and facilitate risk acceptance decisions

12m
12

Risk Mitigation Controls and Ownership

Objective 3.4 · Assign control ownership and monitor the effectiveness of mitigation controls

12m
13

Information Security Control Frameworks and Standards

Objective 4.1 · Identify and apply information security control frameworks (e.g., NIST, ISO 27001, COBIT)

12m
14

Control Design, Effectiveness, and Assurance

Objective 4.2 · Evaluate control design and operational effectiveness through testing and monitoring

12m
15

Key Risk Indicators (KRIs) and Continuous Monitoring

Objective 4.3 · Define, implement, and use key risk indicators to monitor risk and control effectiveness

12m
16

Incident Response, Business Continuity, and Disaster Recovery

Objective 4.4 · Integrate risk management with incident response, business continuity, and disaster recovery planning

12m

Ready to test your knowledge?

Free CRISC practice questions with full explanations. Test what you learn chapter by chapter.

CRISC Practice Questions