CRISC cheat sheet

A one-page reference for the ISACA CRISC — Certified in Risk and Information Systems Control exam: the format, how the domains are weighted, and the glossary terms for this exam.

Exam at a glance

Vendor
ISACA
Level
Advanced
Questions
100
Time
180 min
Mock pass mark
70%
Domains
4
Practice Qs
150
Code
CRISC

Domain weightings

How much of the exam each domain covers. Spend your study time in proportion — the heavier the domain, the more questions you'll see.

Key terms

IT Risk
IT Risk is the business risk associated with the use, ownership, operation, and adoption of IT within an enterprise. CRISC is built around identifying, assessing, and responding to IT risk in business terms.
Risk Appetite
Risk Appetite is the amount of risk an organization is willing to accept in pursuit of its objectives. CRISC uses it, with risk tolerance and capacity, to decide which risks to accept, mitigate, transfer, or avoid.
Risk Tolerance
Risk Tolerance is the acceptable variation around the risk appetite for a specific objective or activity. CRISC distinguishes it from appetite to set concrete thresholds for individual risks.
Inherent Risk
Inherent Risk is the level of risk before any controls or mitigations are applied. CRISC contrasts it with residual risk to measure how much a control reduces exposure.
Residual Risk
Residual Risk is the risk that remains after controls and other responses have been applied. CRISC holds that management formally accepts residual risk once it falls within the risk appetite.
Risk Register
A Risk Register is the central record of identified risks, their analysis, ownership, and response status. CRISC uses it to track and report risk throughout the risk management lifecycle.
Risk Assessment
Risk Assessment is the process of identifying, analyzing, and evaluating risk using qualitative or quantitative methods. CRISC Domain 2 covers assessment concepts, frameworks, and business impact analysis.
Risk Response
Risk Response is the selection and implementation of a treatment — accept, mitigate, transfer, or avoid — for an identified risk. CRISC's largest domain covers choosing responses aligned to the risk appetite.
Control
A Control is a policy, procedure, or safeguard that modifies risk, classified as preventive, detective, or corrective. CRISC covers control design, ownership, and monitoring as the core of risk response.
KRI
A Key Risk Indicator (KRI) is a metric that provides an early warning of rising risk exposure. CRISC uses KRIs, distinct from performance-measuring KPIs, to trigger action before a risk materializes.
KPI
A Key Performance Indicator (KPI) measures how well an activity or control is achieving its objectives. CRISC pairs KPIs with KRIs so that performance and risk are monitored together.
Three Lines of Defense
The Three Lines of Defense is a governance model separating risk ownership (operations), risk oversight (risk and compliance functions), and independent assurance (audit). CRISC uses it to clarify risk roles and responsibilities.
Risk Governance
Risk Governance is the framework of structures, policies, and processes that directs and oversees enterprise risk management. CRISC Domain 1 aligns risk governance with organizational strategy and culture.
Business Impact Analysis
Business Impact Analysis (BIA) determines the effect of disruptions on business processes to prioritize risk and recovery. CRISC uses the BIA to inform risk assessment and response decisions.
Third-Party Risk
Third-Party Risk is the risk introduced by vendors, suppliers, and other external parties. CRISC covers assessing and monitoring it through due diligence, contracts, and ongoing oversight within risk response.