CRISC
Certified in Risk and Information Systems Control, an ISACA certification.
Getting Started: CRISC Exam Essentials
Free knowledge base
Everything from the course in one searchable place: 205 entries. Use it to review before a practice test or look up a word you forgot.
205 results
Certified in Risk and Information Systems Control, an ISACA certification.
Getting Started: CRISC Exam Essentials
Information Systems Audit and Control Association, global professional organization.
Getting Started: CRISC Exam Essentials
Potential for an IT-related event to negatively impact business objectives.
Getting Started: CRISC Exam Essentials
Policies, procedures, and mechanisms to manage IT risks.
Getting Started: CRISC Exam Essentials
Continuing Professional Education, hours required to maintain certification.
Getting Started: CRISC Exam Essentials
Framework ensuring IT aligns with business strategy and objectives.
Getting Started: CRISC Exam Essentials
The amount of risk an organization is willing to accept.
Getting Started: CRISC Exam Essentials
To remember the CRISC domains, think 'GRIT': Governance, Risk Assessment, Information Technology & Security, and (Risk) Response & Reporting. GRIT helps you manage risk!
Getting Started: CRISC Exam Essentials
The CRISC certification requires a minimum of three years of cumulative work experience in at least two of the four CRISC domains. This experience must be within the 10-year period preceding the application date or within five years of passing the exam. Memorize these specific timeframes and domain count.
Getting Started: CRISC Exam Essentials
Underestimating the required work experience: Many candidates pass the exam but fail to meet the experience requirements for certification.
Getting Started: CRISC Exam Essentials
Focusing only on technical controls: CRISC emphasizes a holistic view of risk, including business impact, not just technical solutions.
Getting Started: CRISC Exam Essentials
Neglecting CPE requirements: Failing to earn and report sufficient CPEs can lead to certification revocation.
Getting Started: CRISC Exam Essentials
A major section or area of knowledge covered by the CRISC exam.
Getting Started: CRISC Exam Essentials
The percentage of the exam dedicated to a specific domain, indicating its importance.
Getting Started: CRISC Exam Essentials
An exam question with a stem and four possible answer options.
Getting Started: CRISC Exam Essentials
A standardized score that adjusts for variations in exam difficulty.
Getting Started: CRISC Exam Essentials
The minimum scaled score required to pass the CRISC exam (450).
Getting Started: CRISC Exam Essentials
Strategically allocating time during the exam to answer all questions.
Getting Started: CRISC Exam Essentials
Go RIch, Risk Response, Monitor: G-R-R-M helps remember the domain order and emphasis.
Getting Started: CRISC Exam Essentials
Memorize the exact percentage weightings for each of the four CRISC domains. The exam frequently tests your understanding of the relative importance of these areas.
Getting Started: CRISC Exam Essentials
Underestimating the importance of higher-weighted domains like Governance and Risk Response.
Getting Started: CRISC Exam Essentials
Spending too much time on a single difficult question, jeopardizing completion of the entire exam.
Getting Started: CRISC Exam Essentials
Failing to read questions carefully, especially those asking for the 'BEST' or 'MOST appropriate' answer.
Getting Started: CRISC Exam Essentials
System directing and controlling an organization.
Module 1: Governance Fundamentals
Holistic framework for managing all organizational risks.
Module 1: Governance Fundamentals
Governance, Risk, and Compliance integrated approach.
Module 1: Governance Fundamentals
Any party with an interest in the organization.
Module 1: Governance Fundamentals
Acceptable deviation from risk appetite.
Module 1: Governance Fundamentals
High-level goal aligned with the organization's mission.
Module 1: Governance Fundamentals
To remember the ERM process, think: 'I Eat Risk Regularly, So Control It, Monitor Always!' (Internal Environment, Event Identification, Risk Assessment, Risk Response, Control Activities, Information/Communication, Monitoring Activities, Always Objective Setting)
Module 1: Governance Fundamentals
The exam often tests the relationship between governance and ERM. Look for questions asking how governance provides direction for risk management, or how ERM supports strategic objectives set by governance. Keywords like 'board oversight,' 'strategic alignment,' and 'risk appetite definition' are strong indicators.
Module 1: Governance Fundamentals
Confusing governance with management: Governance provides direction; management executes.
Module 1: Governance Fundamentals
Treating ERM as a separate, siloed function rather than integrated across the enterprise.
Module 1: Governance Fundamentals
Failing to align risk management activities with the organization's strategic objectives and risk appetite.
Module 1: Governance Fundamentals
Shared attitudes, values, and behaviors regarding risk.
Module 1: Governance Fundamentals
Operational management owning and managing risks.
Module 1: Governance Fundamentals
Risk management and compliance functions overseeing risks.
Module 1: Governance Fundamentals
Internal Audit providing independent assurance.
Module 1: Governance Fundamentals
Leadership's commitment to ethical and risk-aware behavior.
Module 1: Governance Fundamentals
Remember the '3 Lines of Defense' like a castle: The guards (line management) are on the walls, the general (risk management) plans defenses, and the king's advisor (internal audit) checks everything.
Module 1: Governance Fundamentals
The exam frequently distinguishes between the Board's oversight role (setting appetite) and executive management's implementation role (executing the framework). Pay attention to keywords like 'establish,' 'approve,' 'oversee' for the Board, and 'implement,' 'manage,' 'execute' for executive management.
Module 1: Governance Fundamentals
Confusing the Board's strategic oversight with executive management's operational implementation.
Module 1: Governance Fundamentals
Underestimating the importance of line management as the 'first line' of risk defense.
Module 1: Governance Fundamentals
Believing risk culture is just about policies, rather than shared behaviors and values.
Module 1: Governance Fundamentals
A system of rules enforced by government.
Module 1: Governance Fundamentals
A rule or directive made and maintained by an authority.
Module 1: Governance Fundamentals
A high-level internal statement of intent.
Module 1: Governance Fundamentals
A mandatory requirement for implementing policies.
Module 1: Governance Fundamentals
Detailed step-by-step instructions for tasks.
Module 1: Governance Fundamentals
Moral principles guiding behavior and decision-making.
Module 1: Governance Fundamentals
Adherence to rules, regulations, and laws.
Module 1: Governance Fundamentals
General Data Protection Regulation (EU data privacy law).
Module 1: Governance Fundamentals
L-R-P-S: Laws Rule People's Systems! (Laws, Regulations, Policies, Standards)
Module 1: Governance Fundamentals
The exam frequently tests your understanding of the hierarchy of governance documents. Be prepared to distinguish between laws, regulations, policies, and procedures. Keywords like 'mandatory external,' 'internal high-level,' and 'step-by-step' are key.
Module 1: Governance Fundamentals
Confusing a policy (what to do) with a procedure (how to do it).
Module 1: Governance Fundamentals
Assuming legal compliance automatically means ethical behavior.
Module 1: Governance Fundamentals
Failing to regularly review and update policies and controls as laws and regulations change.
Module 1: Governance Fundamentals
Understanding business operations, goals, and strategic context.
Module 1: Governance Fundamentals
Ensuring risk management supports organizational objectives.
Module 1: Governance Fundamentals
Document justifying an investment with costs and benefits.
Module 1: Governance Fundamentals
Structured activities to achieve an organizational goal.
Module 1: Governance Fundamentals
The unique value an initiative brings to the organization.
Module 1: Governance Fundamentals
Comparing project costs to its potential benefits.
Module 1: Governance Fundamentals
To remember the importance of business acumen: 'CRISC professionals need C.A.S.H.' — Context, Acumen, Strategy, and How it impacts the business.
Module 1: Governance Fundamentals
The CRISC exam frequently tests your ability to connect risk management directly to business outcomes. Look for questions that ask how a risk professional should communicate with leadership or justify an investment; the answer will almost always involve business value, strategic alignment, or financial impact.
Module 1: Governance Fundamentals
Focusing solely on technical details without considering business impact.
Module 1: Governance Fundamentals
Communicating risks using only technical jargon to non-technical stakeholders.
Module 1: Governance Fundamentals
Proposing risk solutions without a clear business case or justification.
Module 1: Governance Fundamentals
Potential cause of an unwanted incident, resulting in harm to a system or organization.
Module 2: IT Risk Identification & Analysis
Weakness that can be exploited by a threat source to cause harm.
Module 2: IT Risk Identification & Analysis
Result of an unwanted incident, causing harm to organizational objectives.
Module 2: IT Risk Identification & Analysis
Aggregate of all potential threats and vulnerabilities an organization faces.
Module 2: IT Risk Identification & Analysis
Mechanism used to take advantage of a vulnerability.
Module 2: IT Risk Identification & Analysis
To remember the components of risk, think 'TV-I': Threat, Vulnerability, Impact. If you're missing any 'channel,' you don't have a complete 'picture' of the risk.
Module 2: IT Risk Identification & Analysis
The CRISC exam frequently tests your ability to distinguish between threats, vulnerabilities, and risks. Remember that a risk only exists when a threat can exploit a vulnerability to cause an impact. Keywords like 'potential cause' (threat) vs. 'weakness' (vulnerability) vs. 'likelihood x impact' (risk) are critical.
Module 2: IT Risk Identification & Analysis
Confusing a threat with a vulnerability: A threat is the 'bad actor' or event, while a vulnerability is the 'open door' they can use.
Module 2: IT Risk Identification & Analysis
Failing to consider internal threats: Many significant risks originate from within the organization, whether malicious or accidental.
Module 2: IT Risk Identification & Analysis
Ignoring the dynamic nature of the threat landscape: What was safe yesterday might be vulnerable today due to new exploits or technologies.
Module 2: IT Risk Identification & Analysis
Categorizes and ranks risks using descriptive scales.
Module 2: IT Risk Identification & Analysis
Assigns numerical values to risks for financial assessment.
Module 2: IT Risk Identification & Analysis
Plots likelihood vs. impact for visual risk prioritization.
Module 2: IT Risk Identification & Analysis
Expected monetary loss from a risk over a year.
Module 2: IT Risk Identification & Analysis
Expected monetary loss from a single risk event.
Module 2: IT Risk Identification & Analysis
Estimated frequency of a risk event per year.
Module 2: IT Risk Identification & Analysis
Comparing analyzed risks against established criteria.
Module 2: IT Risk Identification & Analysis
Identifies critical business functions and their recovery needs.
Module 2: IT Risk Identification & Analysis
To remember the quantitative formula: 'S.A.L.E.' - Single (Loss Expectancy) x Annualized (Rate of Occurrence) = Loss Expectancy (Annualized).
Module 2: IT Risk Identification & Analysis
The CRISC exam frequently tests your understanding of when to apply qualitative versus quantitative analysis. Look for keywords like 'initial assessment,' 'limited data,' or 'high-level' for qualitative. For quantitative, keywords include 'financial justification,' 'cost-benefit,' 'ROI,' or 'specific monetary loss.'
Module 2: IT Risk Identification & Analysis
Confusing qualitative and quantitative analysis and using the wrong method for a given scenario.
Module 2: IT Risk Identification & Analysis
Failing to define clear risk criteria before starting risk evaluation, leading to inconsistent prioritization.
Module 2: IT Risk Identification & Analysis
Over-relying on a single analysis technique instead of combining methods for a comprehensive view.
Module 2: IT Risk Identification & Analysis
A narrative describing a potential event and its impact.
Module 2: IT Risk Identification & Analysis
The entity initiating a risk event.
Module 2: IT Risk Identification & Analysis
Risk scenario development from objectives to risks.
Module 2: IT Risk Identification & Analysis
Risk scenario development from threats/assets.
Module 2: IT Risk Identification & Analysis
A risk assessment framework for scenario development.
Module 2: IT Risk Identification & Analysis
To remember the key components, think: 'A T V E I A C' – Actor, Threat, Vulnerability, Event, Impact, Asset, Controls. Like 'A TV EATS A Carrot'!
Module 2: IT Risk Identification & Analysis
The CRISC exam emphasizes that risk scenarios must be specific enough to enable effective risk response planning and resource allocation. Look for keywords like 'actionable,' 'quantifiable,' and 'business impact.'
Module 2: IT Risk Identification & Analysis
Creating scenarios that are too vague or generic, making them difficult to act upon.
Module 2: IT Risk Identification & Analysis
Focusing only on technical details without linking them to business impact and objectives.
Module 2: IT Risk Identification & Analysis
Developing scenarios for highly improbable events, wasting resources on low-priority risks.
Module 2: IT Risk Identification & Analysis
Central repository for identified IT risks and their management details.
Module 2: IT Risk Identification & Analysis
Individual accountable for managing a specific risk and its treatment.
Module 2: IT Risk Identification & Analysis
Metric used to provide an early warning of increasing risk exposure.
Module 2: IT Risk Identification & Analysis
Actions taken to reduce the likelihood or impact of a risk.
Module 2: IT Risk Identification & Analysis
Current state of a risk (e.g., Open, In Progress, Closed).
Module 2: IT Risk Identification & Analysis
Overall process of modifying risk, including mitigation, transfer, acceptance.
Module 2: IT Risk Identification & Analysis
To remember the key elements of a risk register entry, think: 'RID-COPS'. Risk ID, Impact, Description, Control, Owner, Probability (Likelihood), Status.
Module 2: IT Risk Identification & Analysis
The exam often tests the dynamic nature of the risk register. Look for questions emphasizing continuous monitoring, regular updates, and the role of KRIs in proactive risk management. Remember, it's a 'living document,' not a static report.
Module 2: IT Risk Identification & Analysis
Treating the risk register as a static document that is rarely updated.
Module 2: IT Risk Identification & Analysis
Failing to assign clear ownership for each identified risk.
Module 2: IT Risk Identification & Analysis
Not linking mitigation actions directly to specific risks in the register.
Module 2: IT Risk Identification & Analysis
Eliminating a risk by ceasing the activity that causes it.
Module 3: Risk Response & Control
Shifting the financial consequences of a risk to a third party.
Module 3: Risk Response & Control
Consciously deciding to take no action against a risk.
Module 3: Risk Response & Control
The risk remaining after risk response actions have been taken.
Module 3: Risk Response & Control
Remember the 4 T's of Risk Response: Terminate (Avoid), Treat (Mitigate), Transfer, Tolerate (Accept).
Module 3: Risk Response & Control
The CRISC exam frequently tests your ability to distinguish between risk avoidance and risk mitigation. Remember: avoidance eliminates the source of risk, while mitigation reduces its impact or likelihood. Look for keywords like 'stop the activity' for avoidance and 'implement controls' for mitigation.
Module 3: Risk Response & Control
Confusing risk avoidance with risk mitigation; avoidance eliminates the activity, mitigation reduces the risk within the activity.
Module 3: Risk Response & Control
Accepting a risk by default due to inaction, rather than through a conscious, documented decision.
Module 3: Risk Response & Control
Failing to consider residual risk after implementing a response strategy.
Module 3: Risk Response & Control
Individual/entity with primary responsibility for managing a specific risk.
Module 3: Risk Response & Control
Obligation to answer for results of actions, including control effectiveness.
Module 3: Risk Response & Control
Individual/team responsible for specific control design, implementation, and operation.
Module 3: Risk Response & Control
Document listing identified risks, their owners, and mitigation strategies.
Module 3: Risk Response & Control
O-A-C: Owners are Accountable for Controls. The 'O' (Owner) is the big picture, the 'A' (Accountable) is the ultimate responsibility, and 'C' (Controls) are the tools they use.
Module 3: Risk Response & Control
The CRISC exam frequently tests the distinction between 'risk owner' and 'control owner.' Remember that the risk owner is typically a business function, while the control owner is often an operational or technical team.
Module 3: Risk Response & Control
Confusing risk ownership with control ownership.
Module 3: Risk Response & Control
Assigning risk ownership to a technical team instead of a business unit.
Module 3: Risk Response & Control
Failing to clearly document who owns which risk and control.
Module 3: Risk Response & Control
Stops an undesirable event from occurring.
Module 3: Risk Response & Control
Identifies an event after it has occurred.
Module 3: Risk Response & Control
Minimizes impact and restores normal operations.
Module 3: Risk Response & Control
The degree to which a control achieves its objective.
Module 3: Risk Response & Control
Using technology to perform control activities.
Module 3: Risk Response & Control
Ensuring controls work together seamlessly.
Module 3: Risk Response & Control
Control cost and effort should match risk level.
Module 3: Risk Response & Control
P-D-C: 'Please Don't Crash!' P-reventive, D-etective, C-orrective. Remember the order of defense!
Module 3: Risk Response & Control
On the exam, pay close attention to scenarios describing control failures. Identify whether the failure was due to poor design (e.g., not appropriate), poor implementation (e.g., not tested), or poor operation (e.g., not maintained). Keywords like 'before the event,' 'after the event,' and 'restore' are critical for distinguishing control types.
Module 3: Risk Response & Control
Implementing controls without proper testing, leading to unforeseen vulnerabilities or operational disruptions.
Module 3: Risk Response & Control
Designing controls that are too complex or burdensome, causing users to find workarounds that negate their effectiveness.
Module 3: Risk Response & Control
Failing to integrate controls with existing processes or other controls, creating security gaps or redundancies.
Module 3: Risk Response & Control
Ongoing process to ensure controls operate effectively.
Module 3: Risk Response & Control
Communicating control performance to stakeholders.
Module 3: Risk Response & Control
Written records describing control details.
Module 3: Risk Response & Control
Periodic review of controls by process owners.
Module 3: Risk Response & Control
Security Information and Event Management system.
Module 3: Risk Response & Control
Software for managing governance, risk, and compliance.
Module 3: Risk Response & Control
Quantifiable measures of control effectiveness.
Module 3: Risk Response & Control
MR. DOC: Monitor, Report, Document Controls. Like a doctor who checks your health regularly and keeps records!
Module 3: Risk Response & Control
The CRISC exam often emphasizes the 'continuous' aspect of monitoring. Look for questions that highlight the dynamic nature of risk and the need for ongoing evaluation, not just point-in-time assessments. Remember that reporting must be 'actionable' and 'tailored' to the audience.
Module 3: Risk Response & Control
Assuming controls, once implemented, will always remain effective without ongoing monitoring.
Module 3: Risk Response & Control
Providing generic control reports to all stakeholders instead of tailoring the information to their specific needs.
Module 3: Risk Response & Control
Neglecting to update control documentation when processes or systems change, leading to outdated and misleading information.
Module 3: Risk Response & Control
Physical components of an IT system, like servers or network devices.
Module 4: IT & Security Foundations
Programs and data that instruct hardware, including OS and applications.
Module 4: IT & Security Foundations
Software that manages computer hardware and software resources.
Module 4: IT & Security Foundations
Interconnected devices that can share resources and exchange data.
Module 4: IT & Security Foundations
Delivery of on-demand computing services over the Internet.
Module 4: IT & Security Foundations
Infrastructure as a Service; provides virtualized computing resources.
Module 4: IT & Security Foundations
Platform as a Service; provides a platform for developing applications.
Module 4: IT & Security Foundations
Software as a Service; delivers ready-to-use applications over the internet.
Module 4: IT & Security Foundations
Hardware is Hard, Software is Soft. Hard you can touch (server), Soft you can't (program).
Module 4: IT & Security Foundations
The CRISC exam often tests your ability to apply IT concepts to risk scenarios. Pay close attention to how different IT components (hardware, software, network, cloud) introduce specific risks and require distinct controls. For example, understand that a SaaS model shifts much of the infrastructure risk to the vendor, but introduces vendor lock-in and data residency risks for the consumer.
Module 4: IT & Security Foundations
Confusing the responsibilities in IaaS, PaaS, and SaaS models; remember the shared responsibility model.
Module 4: IT & Security Foundations
Underestimating the impact of network latency or bandwidth on application performance and user experience.
Module 4: IT & Security Foundations
Overlooking the security implications of data stored in different locations (on-premise vs. cloud).
Module 4: IT & Security Foundations
Confidentiality, Integrity, Availability: core security principles.
Module 4: IT & Security Foundations
Preventing unauthorized disclosure of information.
Module 4: IT & Security Foundations
Ensuring data is accurate, complete, and unaltered.
Module 4: IT & Security Foundations
Ensuring systems and data are accessible when needed.
Module 4: IT & Security Foundations
National Institute of Standards and Technology Cybersecurity Framework.
Module 4: IT & Security Foundations
International standard for Information Security Management Systems.
Module 4: IT & Security Foundations
Safeguard or countermeasure to reduce identified risks.
Module 4: IT & Security Foundations
Proof that an action occurred and cannot be denied.
Module 4: IT & Security Foundations
To remember the CIA Triad: 'C' is for C-overt (secret), 'I' is for I-dentical (unchanged), 'A' is for A-lways there.
Module 4: IT & Security Foundations
The CRISC exam frequently tests your understanding of the CIA Triad and how different security controls map to these principles. Be prepared to identify which principle is being addressed by a given control (e.g., encryption for confidentiality). Also, know the primary purpose of major frameworks like NIST CSF (risk-based guidance) and ISO 27001 (ISMS certification).
Module 4: IT & Security Foundations
Confusing confidentiality with integrity; they both deal with data, but confidentiality is about who sees it, integrity is about its accuracy.
Module 4: IT & Security Foundations
Assuming one security framework fits all organizations; the best framework depends on specific needs and context.
Module 4: IT & Security Foundations
Forgetting that availability is just as important as confidentiality and integrity; a secure system that can't be used is useless.
Module 4: IT & Security Foundations
Daily activities managing IT infrastructure and services.
Module 4: IT & Security Foundations
Applying processes to achieve specific project objectives.
Module 4: IT & Security Foundations
Restoring normal service operation as quickly as possible.
Module 4: IT & Security Foundations
Identifying and resolving the root cause of incidents.
Module 4: IT & Security Foundations
Controlling changes to IT infrastructure and services.
Module 4: IT & Security Foundations
Contract defining service expectations and responsibilities.
Module 4: IT & Security Foundations
Sequential project approach, phases complete before next.
Module 4: IT & Security Foundations
Iterative and incremental project approach, flexible.
Module 4: IT & Security Foundations
To remember the core ITIL operational processes: I P C S. 'I'ncident, 'P'roblem, 'C'hange, 'S'ervice Level. 'I P C S' - 'I Protect Critical Systems'.
Module 4: IT & Security Foundations
The exam often tests your understanding of how project management methodologies (e.g., Waterfall vs. Agile) impact risk, and how operational processes (e.g., incident vs. problem management) contribute to overall risk posture. Look for keywords like 'root cause' for problem management.
Module 4: IT & Security Foundations
Confusing incident management (restoring service) with problem management (root cause analysis).
Module 4: IT & Security Foundations
Underestimating the importance of change management in preventing operational risks.
Module 4: IT & Security Foundations
Failing to integrate risk assessments into both project planning and operational reviews.
Module 4: IT & Security Foundations
Restoring IT systems and infrastructure after a disruptive event.
Module 4: IT & Security Foundations
Organization's ability to maintain essential functions during disruptions.
Module 4: IT & Security Foundations
Maximum acceptable downtime for a system or process.
Module 4: IT & Security Foundations
Maximum acceptable data loss measured in time.
Module 4: IT & Security Foundations
Fully equipped, operational recovery facility for immediate use.
Module 4: IT & Security Foundations
Partially equipped recovery facility requiring some setup.
Module 4: IT & Security Foundations
Basic facility with infrastructure, no equipment or data.
Module 4: IT & Security Foundations
To remember the difference: DR is about getting the 'D'ata and 'R'esources back online. BC is about keeping the 'B'usiness 'C'ontinuing, no matter what.
Module 4: IT & Security Foundations
The CRISC exam often tests the distinction between DR and BC, and the roles of RTO/RPO. Remember that BC is broader and includes DR. A BIA is always the starting point for both.
Module 4: IT & Security Foundations
Confusing DR solely with BC; DR is a subset of BC.
Module 4: IT & Security Foundations
Failing to regularly test and update DRPs and BC plans.
Module 4: IT & Security Foundations
Not conducting a thorough BIA, leading to incorrect RTO/RPO settings.
Module 4: IT & Security Foundations