Certified in Risk and Information Systems Control (CRISC) cheat sheet
ISACA
Free to share. Examworthy is not affiliated with or endorsed by ISACA; CRISC and related marks belong to their respective owners.
At a glance
Format: Multiple choice, computer-based at PSI testing centres or remote proctored
Domain weight map
Heaviest first - spend your time hereHow this exam thinks
CRISC is a judgement exam: nearly every question is a scenario, and the right answer is the move that aligns the decision with the organisation's risk appetite and puts the accountable business owner, not the practitioner, in charge of the risk.
Spot the trap
Tempting wrong answers, and why they failTempting but wrong
Transferring a marginal over-appetite exposure to an insurer is the right call when controls would cost more than the loss.
Why it fails
Transfer adds premium cost on top of an exposure already smaller than further treatment spend, so it is hard to justify. When treatment cost exceeds the potential loss, documented acceptance is the rational response.
Risk Response and Reporting
Tempting but wrong
Mapping each IT risk scenario to the business objectives it could impair proves the risk approach is steered by strategy.
Why it fails
Mapping risks to objectives shows useful traceability and documents exposure, but it does not prove the overall approach is steered by strategy. Strategic alignment is shown by deriving appetite, tolerance and treatment priorities from the approved objectives.
Governance
Tempting but wrong
A detailed network and data-flow diagram of a platform constitutes a risk scenario.
Why it fails
An architecture diagram is an input that supports analysis, not a scenario in itself, because it names no event, no actor, and no loss outcome. A scenario must connect actor, event, asset, and consequence.
Risk Assessment
Tempting but wrong
A routine duplicate-platform purchase should be escalated straight to the audit committee for an independent buy or no-buy decision.
Why it fails
Audit-committee escalation sounds rigorous but bypasses the architecture review, which is the correct first-line mechanism for catching duplication and integration risk. It is also disproportionate to a routine procurement decision.
Information Technology and Security
Tempting but wrong
Withdrawing entirely from holding customer payment data online is the best response to catastrophic breach risk.
Why it fails
Avoidance removes the threat but guts the core retail business, an overreaction when the catastrophic financial impact can instead be transferred to an insurer while controls keep likelihood low.
Risk Response and Reporting
Tempting but wrong
When strategy shifts to overseas expansion, freezing the existing risk register until the expansion is complete keeps the approach aligned.
Why it fails
Freezing the register feels cautious but lets the approach drift out of step with a strategy whose risk profile is shifting right now. The right response is to reassess appetite and tolerance against the new exposures immediately.
Governance
Tempting but wrong
A threat-vulnerability pairing is only a genuine exposure once the asset owner has formally accepted the vulnerability.
Why it fails
Formal acceptance is a treatment decision recorded after assessment. It does not determine whether the threat-vulnerability pair creates a real exposure in the first place; a capable threat acting on a real vulnerability affecting a valued asset is what defines exposure.
Risk Assessment
Tempting but wrong
A vendor will probably extend support for a database engine indefinitely because too many large customers still depend on it.
Why it fails
Assuming an indefinite extension is wishful and unsupported by the published announcement. Relying on it leaves the genuine end-of-support exposure, unpatched future vulnerabilities, unidentified and unmanaged. Risk must be assessed against the stated cut-off date, not a hoped-for reprieve.
Information Technology and Security
Key terms
Exam-day rules
- Find the appetite and the owner first. Before judging the options, ask what the organisation's risk appetite is and who is accountable for this risk, because that pairing usually picks the answer.
- Reject answers where the practitioner oversteps. If an option has you accepting risk, choosing a treatment unilaterally or quietly working around a conflict, it is almost always the trap; the owner decides and accepts, you advise and disclose.
- Understand the risk before you treat it. When an option jumps to a control before the risk is assessed or scoped, prefer the answer that assesses or clarifies first; sequence matters on this exam.
- Run the cost-benefit on every control. Never pick a safeguard that costs more each year than the largest plausible loss it prevents; the proportionate, lower-cost treatment is usually correct.
- Match the report to its audience. Boards get exposure aggregated against appetite and the decisions they must make; operational owners get the detailed control and remediation status. The same data, shaped to the reader, is the right answer.
Revision schedule
- Day 1Map the blueprint and book a date
- Week 1Internalise the practitioner mindset
- Weeks 1 to 3Go deep on Response and Reporting, then Governance
- Weeks 3 to 4Lock risk assessment fundamentals
- Week 4Cover the technology and security knowledge