CertGrid
Security Study Guide

ISACA CRISC (Certified in Risk and Information Systems Control) Study Guide

ISACA's CRISC (Certified in Risk and Information Systems Control) validates the ability to identify, assess, respond to, and monitor enterprise IT risk and to design and maintain information systems controls. It is aimed at risk practitioners, control professionals, and IT/business managers who own or oversee risk. The exam is scenario-heavy and spans four domains: Governance, IT Risk Assessment, Risk Response and Reporting, and Information Technology and Security.

Objective-mapped study guide, aligned to current exam objectives · Published Jul 2026 · Guide updated Sep 2026 · Question bank reviewed Aug 2026 · Independent practice platform.

Real exam: 150 qs · 240 min

Domain 1: Governance

Key concepts you must know · 218 practice questions

Domain 2: IT Risk Assessment

Key concepts you must know · 186 practice questions

Domain 3: Risk Response and Reporting

Key concepts you must know · 269 practice questions

Domain 4: Information Technology and Security

Key concepts you must know · 169 practice questions

CRISC: Risk and Information Systems Control exam tips

Study guide FAQ

How many questions is the CRISC exam and how long do I get?

The CRISC exam has 150 multiple-choice questions and you are given 4 hours (240 minutes) to complete it.

What score do I need to pass CRISC?

ISACA uses a scaled score from 200 to 800, and you need a 450 or higher to pass. The scaled score is not a simple percentage of questions correct.

What are the four CRISC domains and their weights?

The domains are Governance (26%), IT Risk Assessment (20%), Risk Response and Reporting (32%), and Information Technology and Security (22%). Risk Response and Reporting carries the most weight.

Does CRISC require work experience to become certified?

Yes. Passing the exam is separate from certification; ISACA requires a minimum of three years of cumulative relevant experience across at least two CRISC domains, and there are no substitutions or waivers for this requirement.

Official exam sources

The domain names and weightings on this page follow the published exam blueprint. Each source below records what it confirmed and when it was read, so the split can be checked rather than taken on trust.

Settled, and recorded here. Our mock weights for domains 2 and 4 were SWAPPED against ISACA's outline, and have been corrected: Risk Assessment is 22% and Technology and Security 20%, where our practice mocks drew 20% and 22%. The question bank was never wrong - 218 / 186 / 269 / 169 of 842 questions is 25.9 / 22.1 / 31.9 / 20.1, which is ISACA's split - so only the draw disagreed, pulling two points too few from Risk Assessment and two too many from Technology and Security. Separately, this guide says there are "no substitutions or waivers" for the CRISC experience requirement; ISACA's page does not say so either way, so that sentence is unverified.

Related Security resources

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Security. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.