CRISC cheat sheet
A one-page reference for the ISACA CRISC — Certified in Risk and Information Systems Control exam: the format, how the domains are weighted, and the glossary terms for this exam.
Exam at a glance
Vendor
ISACA
Level
Advanced
Questions
100
Time
180 min
Mock pass mark
70%
Domains
4
Practice Qs
150
Code
CRISC
Domain weightings
How much of the exam each domain covers. Spend your study time in proportion — the heavier the domain, the more questions you'll see.
Key terms
- IT Risk
- IT Risk is the business risk associated with the use, ownership, operation, and adoption of IT within an enterprise. CRISC is built around identifying, assessing, and responding to IT risk in business terms.
- Risk Appetite
- Risk Appetite is the amount of risk an organization is willing to accept in pursuit of its objectives. CRISC uses it, with risk tolerance and capacity, to decide which risks to accept, mitigate, transfer, or avoid.
- Risk Tolerance
- Risk Tolerance is the acceptable variation around the risk appetite for a specific objective or activity. CRISC distinguishes it from appetite to set concrete thresholds for individual risks.
- Inherent Risk
- Inherent Risk is the level of risk before any controls or mitigations are applied. CRISC contrasts it with residual risk to measure how much a control reduces exposure.
- Residual Risk
- Residual Risk is the risk that remains after controls and other responses have been applied. CRISC holds that management formally accepts residual risk once it falls within the risk appetite.
- Risk Register
- A Risk Register is the central record of identified risks, their analysis, ownership, and response status. CRISC uses it to track and report risk throughout the risk management lifecycle.
- Risk Assessment
- Risk Assessment is the process of identifying, analyzing, and evaluating risk using qualitative or quantitative methods. CRISC Domain 2 covers assessment concepts, frameworks, and business impact analysis.
- Risk Response
- Risk Response is the selection and implementation of a treatment — accept, mitigate, transfer, or avoid — for an identified risk. CRISC's largest domain covers choosing responses aligned to the risk appetite.
- Control
- A Control is a policy, procedure, or safeguard that modifies risk, classified as preventive, detective, or corrective. CRISC covers control design, ownership, and monitoring as the core of risk response.
- KRI
- A Key Risk Indicator (KRI) is a metric that provides an early warning of rising risk exposure. CRISC uses KRIs, distinct from performance-measuring KPIs, to trigger action before a risk materializes.
- KPI
- A Key Performance Indicator (KPI) measures how well an activity or control is achieving its objectives. CRISC pairs KPIs with KRIs so that performance and risk are monitored together.
- Three Lines of Defense
- The Three Lines of Defense is a governance model separating risk ownership (operations), risk oversight (risk and compliance functions), and independent assurance (audit). CRISC uses it to clarify risk roles and responsibilities.
- Risk Governance
- Risk Governance is the framework of structures, policies, and processes that directs and oversees enterprise risk management. CRISC Domain 1 aligns risk governance with organizational strategy and culture.
- Business Impact Analysis
- Business Impact Analysis (BIA) determines the effect of disruptions on business processes to prioritize risk and recovery. CRISC uses the BIA to inform risk assessment and response decisions.
- Third-Party Risk
- Third-Party Risk is the risk introduced by vendors, suppliers, and other external parties. CRISC covers assessing and monitoring it through due diligence, contracts, and ongoing oversight within risk response.