Definition

Certified in Risk and Information Systems Control (CRISC)

Certified in Risk and Information Systems Control (CRISC) is a certification program that recognizes knowledge and training in the field of risk management for IT. CRISC is one of many certifications available from Information Systems Audit and Control Association (ISACA) which is accredited by the American National Standards Institute (ANSI).

CRISC can provide IT security professionals with a visible marker of experience and knowledge in risk management for enterprise and financial sectors. The Certification is useful for independent consultants, as well as those working for enterprise directly in IT operations, security and other areas. CRISC provides a respected and recognized credential for experienced IT staff who have studied security and garnered the skills needed to understand and manage IT risk.

CRISC Areas of Risk Management

CRISC breaks down areas of risk management specialization into 4 domains:

  1. Identifying risks.
  2. Assessing risks.
  3. Responding to and mitigating risks.
  4. Controlling, monitoring and reporting about risks.

Within these domains, CRISC measures an individual’s ability to deal with risks in an enterprise business and to use information system controls.

Prerequisites for CRISC include three years’ experience in a risk management role with one year at least in domain 1 or 2. Candidates must agree to uphold the ISACA professional code of ethics and comply with the continued education policy. The certification has one requisite exam with 150 questions.

This was last updated in March 2018

Continue Reading About Certified in Risk and Information Systems Control (CRISC)