Examworthyexamworthy.com

Certified in Risk and Information Systems Control (CRISC) cheat sheet

ISACA

Exam version 2025Reviewed 2026-06-09

Free to share. Examworthy is not affiliated with or endorsed by ISACA; CRISC and related marks belong to their respective owners.

At a glance

150
Questions
240 min
Time allowed
450 / 800
Pass mark
$760
Cost (USD)

Format: Multiple choice, computer-based at PSI testing centres or remote proctored

Domain weight map

Heaviest first - spend your time here
Risk Response and Reporting32% · 93 Q
Governance26% · 75 Q
Risk Assessment22% · 64 Q
Information Technology and Security20% · 58 Q

How this exam thinks

CRISC is a judgement exam: nearly every question is a scenario, and the right answer is the move that aligns the decision with the organisation's risk appetite and puts the accountable business owner, not the practitioner, in charge of the risk.

Spot the trap

Tempting wrong answers, and why they fail

Tempting but wrong

Transferring a marginal over-appetite exposure to an insurer is the right call when controls would cost more than the loss.

Why it fails

Transfer adds premium cost on top of an exposure already smaller than further treatment spend, so it is hard to justify. When treatment cost exceeds the potential loss, documented acceptance is the rational response.

Risk Response and Reporting

Tempting but wrong

Mapping each IT risk scenario to the business objectives it could impair proves the risk approach is steered by strategy.

Why it fails

Mapping risks to objectives shows useful traceability and documents exposure, but it does not prove the overall approach is steered by strategy. Strategic alignment is shown by deriving appetite, tolerance and treatment priorities from the approved objectives.

Governance

Tempting but wrong

A detailed network and data-flow diagram of a platform constitutes a risk scenario.

Why it fails

An architecture diagram is an input that supports analysis, not a scenario in itself, because it names no event, no actor, and no loss outcome. A scenario must connect actor, event, asset, and consequence.

Risk Assessment

Tempting but wrong

A routine duplicate-platform purchase should be escalated straight to the audit committee for an independent buy or no-buy decision.

Why it fails

Audit-committee escalation sounds rigorous but bypasses the architecture review, which is the correct first-line mechanism for catching duplication and integration risk. It is also disproportionate to a routine procurement decision.

Information Technology and Security

Tempting but wrong

Withdrawing entirely from holding customer payment data online is the best response to catastrophic breach risk.

Why it fails

Avoidance removes the threat but guts the core retail business, an overreaction when the catastrophic financial impact can instead be transferred to an insurer while controls keep likelihood low.

Risk Response and Reporting

Tempting but wrong

When strategy shifts to overseas expansion, freezing the existing risk register until the expansion is complete keeps the approach aligned.

Why it fails

Freezing the register feels cautious but lets the approach drift out of step with a strategy whose risk profile is shifting right now. The right response is to reassess appetite and tolerance against the new exposures immediately.

Governance

Tempting but wrong

A threat-vulnerability pairing is only a genuine exposure once the asset owner has formally accepted the vulnerability.

Why it fails

Formal acceptance is a treatment decision recorded after assessment. It does not determine whether the threat-vulnerability pair creates a real exposure in the first place; a capable threat acting on a real vulnerability affecting a valued asset is what defines exposure.

Risk Assessment

Tempting but wrong

A vendor will probably extend support for a database engine indefinitely because too many large customers still depend on it.

Why it fails

Assuming an indefinite extension is wishful and unsupported by the published announcement. Relying on it leaves the genuine end-of-support exposure, unpatched future vulnerabilities, unidentified and unmanaged. Risk must be assessed against the stated cut-off date, not a hoped-for reprieve.

Information Technology and Security

Key terms

Risk treatmentRisk acceptanceRisk transferRisk mitigationRisk treatment planAction planRisk ownerRemediation timelineRisk ownershipControl ownershipAccountabilityResidual risk acceptanceThird-party riskSupply chain riskFourth-party riskVendor management

Exam-day rules

  • Find the appetite and the owner first. Before judging the options, ask what the organisation's risk appetite is and who is accountable for this risk, because that pairing usually picks the answer.
  • Reject answers where the practitioner oversteps. If an option has you accepting risk, choosing a treatment unilaterally or quietly working around a conflict, it is almost always the trap; the owner decides and accepts, you advise and disclose.
  • Understand the risk before you treat it. When an option jumps to a control before the risk is assessed or scoped, prefer the answer that assesses or clarifies first; sequence matters on this exam.
  • Run the cost-benefit on every control. Never pick a safeguard that costs more each year than the largest plausible loss it prevents; the proportionate, lower-cost treatment is usually correct.
  • Match the report to its audience. Boards get exposure aggregated against appetite and the decisions they must make; operational owners get the detailed control and remediation status. The same data, shaped to the reader, is the right answer.

Revision schedule

  1. Day 1
    Map the blueprint and book a date
  2. Week 1
    Internalise the practitioner mindset
  3. Weeks 1 to 3
    Go deep on Response and Reporting, then Governance
  4. Weeks 3 to 4
    Lock risk assessment fundamentals
  5. Week 4
    Cover the technology and security knowledge

Practise CRISC free

Every question explains why the right answer is right and why each wrong one is rationale. No sign-up.

554 audited flashcards in this deck.

Practise CRISC free
Examworthy - Certified in Risk and Information Systems Control (CRISC) cheat sheet. Free to share.examworthy.com