Skip to content
CBT Nuggets
DemoBook a Demo

ISACA CRISC – Certified in Risk and Information Systems Control

This ISACA CRISC training is designed to help you earn your Certified in Risk and Information Systems Control credential. This course helps you learn to identify IT risks, build threat models, and align technology with business goals. Once you've completed this course, you'll know how to design effective control frameworks, manage vendor risk, and handle data lifecycles from start to finish. You'll also gain the skills to analyze risk appetite, report metrics through heatmaps and dashboards, and lead disaster recovery efforts.

Updated August 2021

15Skills
102Videos
1Practice Exam
14hTotal

Who This Course Is For

This CRISC training is considered professional-level ISACA training, which means it was designed for security managers and auditors with three to five years of experience with information systems controls.

Skills Your Team Will Gain

  • Decreasing the number of system vulnerabilities with effective incident identification
  • Writing and disseminating security governance models
  • Assessing the likelihood of security breaches and performing risk calculations
  • Performing cost-benefit analyses of risk reduction approaches
  • Incorporating information system controls installation costs to threat analysis

Course Curriculum

2 skills are free to watch — no signup needed. The other 13 premium skills unlock for your whole team with a CBT Nuggets plan.

Free skill preview

Organizational Governance

Bob SalmansDuration: 53m12 videos

Watch this complete skill free — the same trainer, videos, and labs your team gets with a plan.

Watch free skill
  • Organizational GovernanceFree53m · 12 videos
  • Premium skill.Security Program Resources54m · 16 videos
  • Premium skill.Risk Governance57m · 12 videos
  • Premium skill.Risk and Threat Identification1h 2m · 14 videos
  • Premium skill.Vulnerability Analysis and Risk Scenario Development1h 11m · 14 videos
  • Premium skill.IT Risk Analysis and Evaluation56m · 16 videos
  • Premium skill.Risk Response53m · 14 videos
  • Premium skill.Control Design and Implementation54m · 14 videos
  • Premium skill.Risk Monitoring and Reporting1h 19m · 18 videos
  • Premium skill.Network and Endpoint Security55m · 20 videos
  • Premium skill.Business Application Security55m · 18 videos
  • Information Systems OperationsFree58m · 22 videos
  • Premium skill.Data Classification and Encryption32m · 14 videos
  • Premium skill.Information Technology Principles1h · 14 videos
  • Premium skill.Information Security Principles52m · 16 videos
Want to browse the locked skills?
with no purchase required. Already have an account?

An account gets you the full catalog to browse, pre-assessments, quiz questions on free skills, and IT Trainerbot, with every answer citing its source video.

Certification

CRISC – Certified in Risk and Information Systems Control

The Certified in Risk and Information Systems Control (CRISC) certification validates an IT professional's ability to identify and manage risk, design and implement information system controls, and maintain ongoing monitoring and reporting of IT risk...

Exam CRISCLevel ProfessionalDifficulty AdvancedCost $575 for ISACA members, $760 for non-members
Risk IdentificationRisk AssessmentRisk Response and MitigationRisk and Control Monitoring and ReportingInformation Systems Control
Official certification page

Put this course to work for your team

Every plan includes this course plus the full library, virtual labs, and practice exams — or talk it through with sales.

For IT leaders

What IT leaders need to know before assigning this course

Enterprise IT risk becomes expensive when teams treat it reactively instead of tying governance, controls, monitoring, and reporting to business decisions. This professional-level ISACA CRISC training is a strong fit for IT Directors assigning security managers, auditors, risk professionals, and experienced IT Practitioners with roughly three to five years of information systems controls experience.

The course requires about 14 hours per learner and is best assigned to staff who influence risk response, control design, audit readiness, and security program decisions—not entry-level technicians. For change management, Training Managers can stage the course by domain: governance first, then risk identification and analysis, then controls, monitoring, and security operations.

Teams use this training to prepare for the CRISC certification while building a shared vocabulary for enterprise IT risk. CBT Nuggets Practice Exams can support exam readiness, and Team Reporting helps Training Managers track completion and identify learners who may need follow-up before certification or audit milestones.

Team Impact

How this training helps your team succeed

IT teams complete CRISC training to make risk management more consistent across governance, security, audit, and operations functions. The course connects enterprise risk concepts with practical control work, including risk scenarios, vulnerability analysis, response planning, monitoring, and reporting.

  • Improve audit and compliance readiness: Teams align risk governance, control implementation, and reporting so evidence is easier to explain and defend.
  • Reduce reactive security decisions: Security managers and auditors learn to identify threats, analyze vulnerabilities, evaluate IT risk, and select appropriate responses before issues become outages or incidents.
  • Strengthen control ownership: Team Leads can map controls to business applications, endpoints, networks, IS operations, data classification, and encryption responsibilities.
  • Standardize risk communication: Risk monitoring and reporting topics help practitioners present risk posture, control status, and response decisions in terms leaders can act on.

After completion

Capabilities your team walks away with

Knowledge

  • How organizational governance and risk governance shape IT risk decisions.
  • How to identify threats, vulnerabilities, and risk scenarios across enterprise systems.
  • How IT risk analysis and evaluation inform risk response choices.
  • How control design, implementation, monitoring, and reporting support risk management.
  • How network, endpoint, application, operations, data classification, and encryption concepts relate to information systems control.

Ability

  • Evaluate enterprise IT risks and connect them to governance and business priorities.
  • Contribute to risk response planning with a clearer understanding of control options.
  • Support implementation and maintenance of information systems controls.
  • Communicate risk and control status through monitoring and reporting practices.
  • Prepare more effectively for the ISACA CRISC certification exam.

Readiness check

Confirm prerequisite knowledge before training begins

A short placement assessment on the CBT Nuggets assessments platform measures whether a learner already has the foundation this course assumes. IT Directors use it to put the right people in the right training — and any learner can take it right now to make sure they'll get full value from day one.

  • Questions generated from this course's own video transcripts — what gets measured is exactly what gets taught
  • Instant, per-learner results that show whether the prerequisite foundation is in place
  • Results roll up into team readiness reporting, so training hours go where they change outcomes
Runs on assessments.cbtnuggets.com — sign in with an Adept account so results roll up into team readiness reporting. Need one?
.

If gaps show up, start here

ISACA Cybersecurity Fundamentals (ITCA)

This ITCA - Cybersecurity Fundamentals training covers how to perform the basic, professional tasks required of an entry-level IT professional in a cybersecurity capacity. Although earning the ITCA Cybersecurity Fundamentals certification is valuable...

~24h

This course is included with every subscription

Unlock this one course, or get one learner — or your whole team — access to all 287 courses, virtual labs, and practice exams.

Course Unlock

Just need this course?

$225one time

No subscription

One year of access to CRISC

  • Every skill in this course
  • Its virtual labs and practice exam
  • Ask IT Trainerbot about it — free

CBT Nuggets Individual

IT Trainerbot Pro

$49per month

Billed annually

Every course, for one learner

See Individual pricing
For IT teams

CBT Nuggets Teams

IT Trainerbot for Teams

$59per seat / mo

Billed annually

From 1 learner seat · unlimited admin seats

Checking your access

Need tenant hosting, reseller terms, or payment plans on a larger agreement? Book a Demo to discuss an Enterprise contract.

See plans and pricing for your team

Trusted by 23,000+ organizations

Frequently Asked Questions

What will you learn in this enterprise IT risk management training?

Learn how to balance all the factors that go into making enterprise networks as fast as possible but also secure. This course in enterprise IT risk management covers organization governance concerns, risk assessment strategies, risk response and reporting standards, and IT security – taken all together they constitute what a risk management expert needs to know.

Who should take this ISACA risk and information systems control course?

You can take this enterprise IT risk management and information systems control course at any time, and even use it to jump-start your security and auditing career, but it does deal with advanced risk management concepts. It's best for audit, risk and security professionals with a few years of experience already under their belt.

Is this training in enterprise IT risk management associated with any certifications?

Yes, everything you learn on this course about risk auditing and information systems control is directly related to the ISACA certification CRISC. CRISC, or Certified in Risk and Information Systems Control, is a mid-career certification that ISACA offers to risk and auditing professionals who've proven their abilities with continuous risk monitoring and reporting.

What certification should you consider after taking this course in risk and information systems control?

After you take this course in auditing, risk and security, you should aim to earn the Certified in Risk and Information Systems Control (CRISC) from ISACA. Before you can earn it, you will need to have at least three accumulated years of experience in at least two of the four domains on the exam.

Why should you take this ISACA risk and information systems control certification training?

This course isn't necessarily for every IT professional – not even every cybersecurity professional needs what this course teaches. However, if you want to position your career to take on organizational governance, continuous risk monitoring and reporting, information security and IT risk management, then you should take this course and earn CRISC.

Ready to upskill your team?

Talk to our sales team to find the right plan for your organization.