Classes Security

ISACA

Certified in Risk and Information Systems Control (CRISC)

  • 3 days
  • 2 upcoming dates
  • 2 guaranteed to run
  • May qualify for CEU/PDU credit

Upcoming dates

All times shown in the class's own timezone. 2 of 2 are guaranteed to run, meaning they go ahead regardless of enrollment.

Dates Starts Where Status Seat Book
Aug 24-26 9:00 AM to 5:00 PM EDT Live virtual GUARANTEED $2,037
Jan 18-20 9:00 AM to 5:00 PM EST Live virtual GUARANTEED $2,037

About this class

Looking to move up in risk management or earn one of the world’s top-paying IT certifications? The CRISC Certification Training course prepares you to take the CRISC exam and build practical expertise in risk and information systems control, essential skills for today’s digital enterprises.

Developed around the latest ISACA certification framework, this course equips you to assess IT and enterprise risk, develop effective risk response plans, and monitor control performance. You’ll gain the insight and preparation you need to pursue the CRISC certification exam, enhance your governance capabilities, and meet the challenges of modern compliance and risk management roles.

What you'll be able to do

This training prepares you to:

  • Identify and assess IT and enterprise risk in support of strategic business goals
  • Recommend and implement appropriate information security and IS controls
  • Build risk response and mitigation plans aligned to business priorities
  • Establish governance processes for continuous monitoring and reporting
  • Prepare for the CRISC certification exam through real-world examples, CRISC exam prep, and sample CRISC questions

You’ll leave this course ready to pass the CRISC, meet ISACA’s professional standards, and contribute to your organization’s resilience and regulatory readiness.

Course outline

Domain 1: Governance

  • Risk Assessment Concepts, Standards and Frameworks
  • Organizational Strategy, Goals and Objectives
  • Organizational Structure, Roles and Responsibilities
  • Organizational Culture and Assets
  • Policies, Standards and Business Processes
  • Enterprise Risk Management, Risk Management Frameworks and Three Lines of Defense
  • Risk Profile, Risk Appetite and Risk Tolerance
  • Navigating Professional Ethics of Risk Management and Requirements in Laws, Regulations and Controls

Domain 2: IT Risk Assessment

  • Risk Events, Threat Modeling and Threat Landscape
  • Vulnerability and Control Deficiency Analysis
  • Risk Scenario Development
  • Risk Register
  • Risk Analysis Methodologies
  • Business Impact Analysis
  • Inherent, Residual and Current Risk

Domain 3: Risk Response and Reporting

  • Risk Treatment/Risk Response Options
  • Risk and Control Ownership
  • Managing Risk from Processes, Third Parties and Emerging Sources
  • Control Types, Standards and Frameworks
  • Control Design, Selection and Analysis
  • Control Implementation, Testing and Effectiveness
  • Risk Treatment Plans
  • Data Collection, Aggregation, Analysis and Validation
  • Risk and Control Monitoring and Reporting Techniques
  • Performance, Risk and Control Metrics

Domain 4: Information Technology and Security

  • Enterprise Architecture
  • IT Operations Management
  • Project Management
  • Disaster Recovery Management
  • Data Life Cycle Management
  • System Development Life Cycle
  • Emerging Technologies
  • Information Security Concepts, Frameworks, Standards and Awareness Training
  • Business Continuity Management
  • Data Privacy and Protection Principles

Before you attend

As part of the CRISC prerequisites, candidates must have a minimum of three years of professional work experience in information systems auditing, control, or security

Who this is for

IT risk management professionals with at least 3 years of relevant professional work experience in IT risk and information systems control including: Security Directors/Managers/Consultants Compliance/Risk/Privacy Directors and Managers IT Audit Directors/Managers/Consultants Compliance/Risk/Control Staff

How reserving works. Your card is authorized, not charged. We confirm the seat with the training center, usually within one business day, and take payment only once it is held. If the class turns out to be full we release the authorization and you are not charged.

Request a quote

Tell us how many people and roughly when. We'll come back with dates, seat price, and a total by the end of the next business day.

Class Certified in Risk and Information Systems Control (CRISC)

No obligation, and we don't add you to a mailing list.