ISACA Certified in Risk and Information Systems Control incl QAE
- Course Code CRISC
- Duration 4 days
Course Delivery
Jump to:
Course Delivery
This course is available in the following formats:
-
Company Event
Event at company
-
Public Classroom
Traditional Classroom Learning
-
Virtual Learning
Learning that is virtual
Request this course in a different delivery format.
Course Overview
TopPrepare the CRISC - Certified Risk and Information System Control certification
This CRISC training course, in association with ISACA, prepares IT professionals for real-world threats with relevant tools to assess, govern and mitigate risk, and is targeting certification preparation.
The CRISC - Certified Risk and Information System Control - certificate gives you international recognition (from ISACA) as a security professional. The CRISC extensive set of online practice questions (QAE) are included in the courseprice.
The CRISC designation will not only certify professionals who have knowledge and experience identifying and evaluating entity-specific risk, but also aid them in helping enterprises accomplish business objectives by designing, implementing, monitoring and maintaining risk-based, efficient and effective IS controls.
- Continuing Professional Education (CPE) : 31
- Practice questions (QAE = Questions, Answers and Explanations) : 6 month access
Updated 4/2026
Course Schedule
Top-
- Delivery Format: Virtual Learning
- Date: 06-09 September, 2026 | 9:00 AM to 5:00 PM
- Location: Virtual (Egypt Stan)
- Language: English
-
- Delivery Format: Virtual Learning
- Date: 25-28 October, 2026 | 9:00 AM to 5:00 PM
- Location: Virtual (Egypt Stan)
- Language: English
-
- Delivery Format: Public Classroom
- Date: 25-28 October, 2026 | 9:00 AM to 5:00 PM
- Location: Riyadh (Arab Stand)
- Language: English
-
- Delivery Format: Public Classroom
- Date: 09-12 November, 2026 | 9:00 AM to 5:00 PM
- Location: Cairo-Sheraton (Egypt Stan)
- Language: English
-
- Delivery Format: Virtual Learning
- Date: 09-12 November, 2026 | 9:00 AM to 5:00 PM
- Location: Virtual (Egypt Stan)
- Language: English
-
- Delivery Format: Virtual Learning
- Date: 08-11 December, 2026 | 7:00 AM to 3:00 PM
- Location: Virtual (Egypt Stan)
- Language: English
Target Audience
TopCRISC is designed for IT professionals, risk professionals, business analysts, and project manager and/or compliance professionals and anyone who has job responsibilities in the following areas: Risk identification, assessment, evaluation, risk response, monitoring and IS control design/monitoring and implementation/maintenance.
Course Objectives
TopAfter this course participants should be able to:
- Understand Master Governance Frameworks: Understand organizational structures, policies, and accountability principles required to govern enterprise IT risk.
- Assess IT Risk: Identify threats, vulnerabilities, and impacts on business objectives to evaluate risk scenarios and assign accurate ratings.
- Implement Risk Responses: Formulate and execute practical risk treatment plans (mitigate, transfer, avoid, or accept) and monitor their performance.
- Optimize Security Controls: Design, implement, and maintain effective information systems controls to safeguard modern enterprise assets.
- Align IT with Business Goals: Translate technical risk data into meaningful business metrics to help leadership make informed strategic decisions
Course Content
TopOrganizational Governance - A
- Organizational Strategy, Goals, and Objectives
- Organizational Structure, Roles, and Responsibilities
- Organizational Culture
- Policies and Standards
- Business Processes
- Organizational Assets
Risk Governance - B
- Enterprise Risk Management and Risk Management Framework
- Three Lines of Defense
- Risk Profile
- Risk Appetite and Risk Tolerance
- Legal, Regulatory, and Contractual Requirements
- Professional Ethics of Risk Management
IT Risk Identification - A
- Risk Events (e.g., contributing conditions, loss result)
- Threat Modelling and Threat Landscape
- Vulnerability and Control Deficiency Analysis (e.g., root cause analysis)
- Risk Scenario Development
IT Risk Analysis and Evaluation - B
- Risk Assessment Concepts, Standards, and Frameworks
- Risk Register
- Risk Analysis Methodologies
- Business Impact Analysis
- Inherent and Residual Risk
Risk Response - A
- Risk Treatment / Risk Response Options
- Risk and Control Ownership
- Third-Party Risk Management
- Issue, Finding, and Exception Management
- Management of Emerging Risk
Control Design and Implementation - B
- Control Types, Standards, and Frameworks
- Control Design, Selection, and Analysis
- Control Implementation
- Control Testing and Effectiveness Evaluation
Risk Monitoring and Reporting - C
- Risk Treatment Plans
- Data Collection, Aggregation, Analysis, and Validation
- Risk and Control Monitoring Techniques
- Risk and Control Reporting Techniques (heatmap, scorecards, dashboards)
- Key Performance Indicators
- Key Risk Indicators (KRIs)
- Key Control Indicators (KCIs)
Information Technology Principles - A
- Enterprise Architecture
- IT Operations Management (e.g., change management, IT assets, problems, incidents)
- Project Management
- Disaster Recovery Management (DRM)
- Data Lifecycle Management
- System Development Life Cycle (SDLC)
- Emerging Technologies
Information Security Principles - B
- Information Security Concepts, Frameworks, and Standards
- Information Security Awareness Training
- Business Continuity Management
- Data Privacy and Data Protection Principles
Course Prerequisites
TopThere is no prerequisite to take the CRISC exam; however, in order to apply for CRISC certification you must meet the necessary experience requirements as determined by ISACA (see below).
Test Certification
TopThe CRISC exam lasts 4 hours and consists of 150 English Multiple Choice questions.
- Governance (25%)
- IT Risk Assessment (20%)
- Risk Response and Reporting (32%)
- Information Technology and Security (22%)
NB: The examen voucher for the official CRISC exam is not included in the course price. However, the exam voucher can be purchased when attending the associated training"
The exam voucher is available only to Global Knowledge course attendees and cannot be purchased as a standalone product
The requirements for certification are:
- Pass the official CRISC exam
- Three (3) or more years of cumulative work experience performing the tasks of a CRISC professional across at least two (2) CRISC domains, of which one must be in Domain 1 or 2, is required for certification. There are no substitutions or experience waivers.
Follow on Courses
TopManagement & Governance Paths
- CISM (Certified Information Security Manager): Focuses on security program management, strategy, and incident management.
- CDPSE (Certified Data Privacy Solutions Engineer): Focuses on privacy governance, privacy by design, and technical privacy controls.
Audit & Compliance Paths
- CISA (Certified Information Systems Auditor): Focuses on evaluating IT controls, compliance, and safeguarding information assets.
- ISO 27001LI - ISO27001LA Lead Implementer / Auditor: Provides hands-on operational training for building and auditing information security management systems (ISMS).
Further Information
Top- QAE (Questions, Answers and Explanations) is online available, via a voucher which is part of the courseware
- Official course book provided to participants