
CRISC — Certified in Risk and Information Systems Control · 2026 Edition
CRISC Study Guide — 2026 Edition
Edition noteWritten to ISACA's 2025 CRISC outline, effective November 3, 2025, at its new domain weights.
Written to ISACA's 2025 CRISC Exam Content Outline (effective November 3, 2025), 200 original questions with worked explanations, and a 150-question full-length practice exam at the new domain weights.
- 200 original CRISC practice questions, each with a worked explanation, in one PDF + EPUB you keep
PDF + EPUB · English · 143 pages · $24.99 one-time
This book is written in English.
Instant download after payment — no account needed, no subscription.
14-day money-back guarantee: not satisfied for any reason? Email support@preppass.org within 14 days of purchase for a full refund. Refund policy
Look inside the book
Three real pages, rendered straight from the PDF you download — a reference page, a teaching page, and a worked question, always in that order. Nothing here was redrawn to look better.
- Quick referenceChapter 1 — Governance · PDF page 17
A page you can turn back to: the numbers, deadlines or terms gathered in one place.
- How it's taughtChapter 1 — Governance · PDF page 13
An explanation page: the material taught in prose, in the order the exam tests it.
- A question, workedChapter 4 — Information Technology and Security · PDF page 73
A practice question with its answer and the reasoning behind it — not just a key.
About the CRISC exam
For IT risk, control, security and audit professionals preparing for ISACA's CRISC exam. This book teaches the four domains of the 2025 content outline from public primary sources and ends each chapter with a quiz, plus a full-length practice exam. It is an independent study guide, not affiliated with ISACA, and comes with no online practice.
Outline changes: In the 2025 outline, Domain 2 (IT Risk Assessment) rose from 20% to 22% and Domain 4 (Information Technology and Security) fell from 22% to 20%; Domains 1 and 3 stayed at 26% and 32%.
| Awarding body | ISACA |
|---|---|
| Questions | 150 multiple-choice questions |
| Time limit | 4 hours (240 minutes) |
| Passing rule | Candidates must receive a score of 450 or higher to pass the exam (200-800 scale). |
| Fees | Exam registration: ISACA member US$575; nonmember US$760 (nonrefundable and nontransferable). A US$50 application processing fee is paid when applying for certification after passing. |
| Delivery | Computer-based; administered at authorized PSI testing centers globally or as remotely proctored exams. |
| Eligibility | Certification requires three or more years of experience in IT risk management and IS control, with no experience waivers or substitutions, and an application within five years of passing the exam. Exam eligibility is established at registration and is good for six months; one six-month extension may be purchased for US$75. |
| Retakes | Four attempts within a rolling 12-month period; 30-day wait before the second attempt, 90 days before the third and fourth; full registration fee per attempt. |
| Languages | English, Spanish, Japanese |
| Content outline | CRISC Exam Content Outline, 2025 — effective November 3, 2025 |
| Domains and weights |
|
Questions buyers ask
- How many questions are on the CRISC exam, and how long is it?
- The CRISC exam has 150 multiple-choice questions, and candidates have 4 hours (240 minutes) to complete it. It is computer-based, taken at an authorized PSI testing center or as a remotely proctored exam.
- What score is needed to pass the CRISC exam?
- A scaled score of 450 or higher on ISACA's 200–800 scale is needed to pass. ISACA states the standard as a scaled score, not as a percentage or a number of questions answered correctly.
- What are the CRISC exam domains and their weights?
- The four domains are Governance (26%), IT Risk Assessment (22%), Risk Response and Reporting (32%), and Information Technology and Security (20%).
- Which CRISC content outline is current, and what changed?
- The current CRISC Exam Content Outline took effect for exams from 3 November 2025. Compared with the previous outline, IT Risk Assessment rose from 20% to 22% and Information Technology and Security fell from 22% to 20%.
- What experience do I need for CRISC certification?
- You need three or more years of experience in IT risk management and IS control, with no waivers or substitutions. You may sit the exam first and then apply for certification within five years of passing.
- How much does the CRISC exam cost, and how do retakes work?
- Registration costs US$575 for ISACA members and US$760 for nonmembers, and the full fee is paid for every attempt. Candidates have four attempts in a rolling 12-month period, waiting 30 days before the second attempt and 90 days before the third and fourth.
- How is this book organised?
- It has one chapter per CRISC domain, each ending with a quiz, and a 150-question practice exam weighted like the real exam: 200 questions in all, each with an explanation. It costs $24.99.
- Is a study guide enough for the CRISC — Certified in Risk and Information Systems Control exam, or do I need a course?
- Check eligibility first — per ISACA: certification requires three or more years of experience in IT risk management and IS control, with no experience waivers or substitutions, and an application within five years of passing the exam. Exam eligibility is established at registration and is good for six months; one six-month extension may be purchased for US$75. A book does not replace those requirements. For the exam content itself, this 143-page guide teaches the material chapter by chapter with 200 practice questions and explanations inside. A prep course adds live instruction and a set schedule; whether you need one beyond any required education is your call.
- Does the CRISC — Certified in Risk and Information Systems Control study guide come as a PDF?
- Yes — CRISC Study Guide — 2026 Edition downloads as PDF and EPUB, 143 pages. The download link is emailed the moment payment clears and does not expire.
- How much does the CRISC — Certified in Risk and Information Systems Control study guide cost?
- $24.99, once. There is no subscription and no account to create; the PDF and EPUB files are yours to keep.
- Can I read part of the CRISC — Certified in Risk and Information Systems Control study guide before buying?
- Yes. A full chapter is free to read on this page — not a summary of one, the chapter itself.
- Is this the official CRISC — Certified in Risk and Information Systems Control study guide?
- No. This is an independent study guide and is not affiliated with or endorsed by the exam's awarding body. It is written from ISACA's published CRISC Exam Content Outline (2025) and exam candidate information. Always confirm current requirements with the body that issues your licence.
What's included — and what isn't
Included
- Every domain and topic of ISACA's 2025 CRISC Exam Content Outline, each under its own heading
- A quiz closing each chapter, with worked explanations
- A 150-question practice exam at the 2025 domain weights (26/22/32/20)
- 200 original questions, each explained and cited to its source
- Cited to NIST SP 800-30, 800-39 and 800-53 and the IIA Three Lines Model
- PDF + EPUB you keep
Not included
- No printed copy is shipped — this is a file you download and can print yourself
- No video course, instructor, tutoring or online question bank comes with the book — everything is in the file
- Not your exam registration or the testing centre's fee, which you still pay to the official body
Contents
See 8 sections and the page each one starts on
- Chapter 1 — Governancep. 6
- Chapter 2 — IT Risk Assessmentp. 24
- Answer key & explanationsp. 35
- Chapter 3 — Risk Response and Reportingp. 37
- Chapter 4 — Information Technology and Securityp. 56
- Appendix A — The CRISC Exam at a Glance Fact Detailp. 134
- Appendix B — Terms ISACA Expects You to Use Preciselyp. 136
- Appendix C — Risk Decisions at a Glance Response selectionp. 139
Taken from the PDF you download, with the page each one starts on — not typed here.
Read a chapter free, in full
One complete chapter, exactly as it ships in the eBook. Scroll the window to read it right here; no download, no email.
Read chapter 3 here, without leaving the page
We didn't give you the easy intro — the free chapter opens on one of the hardest-working parts of the book, so you can judge the teaching where the exam gets difficult.
If Chapter 2 is about understanding risk, Chapter 3 is about doing something about it and proving it worked. The domain has three movements: choose responses (3A), build controls (3B), and monitor and report (3C). The exam tests this domain as a decision chain — response selection follows from residual risk versus tolerance, control selection follows from the response, and monitoring verifies the whole thing still holds. More than any other domain, the questions here punish answers that sound diligent but act on the wrong step: adding controls to a risk already within tolerance, monitoring without thresholds, or reporting activity instead of risk.
3A1 Risk Response Options
Risk response is the decision about what to do with each assessed risk, and NISTIR 8286A lays out the logic cleanly. The determined exposure is compared with risk tolerance. If exposure is within tolerance limits, the risk may be accepted — acceptance is a conscious decision by someone with the authority to make it, documented and periodically revisited, never the default of doing nothing. If exposure exceeds tolerance, the practitioner works through the other options.
Mitigation applies controls to reduce the likelihood or impact of a risk to a tolerable level — the most common response, and the subject of all of 3B. Risk transfer, also known as risk sharing, moves some of the exposure elsewhere: hiring an external organization to process sensitive transactions such as payment card transactions (reducing the likelihood that sensitive data is processed in-house), or buying cybersecurity insurance (reducing the economic impact if the event occurs). Transfer never transfers accountability — the organization still owns the risk and its consequences; it has only changed who bears part of the cost or the processing.
Avoidance means not doing the risky thing at all: declining the acquisition, discontinuing the product, redesigning the system so the exposure disappears. NISTIR 8286A is explicit that if an unacceptable risk cannot be adequately treated in a cost-effective manner, that risk must be avoided — and equally explicit that risk avoidance is not the same as ignoring a risk. Avoidance is a decision with consequences (lost opportunity, redesign cost), taken deliberately when no proportionate treatment exists.
Two principles govern response selection. First, responses are chosen on residual risk versus tolerance, not inherent risk — Chapter 2's rule, applied. Second, responses must be cost-effective and proportionate: a response that costs more than the exposure it removes destroys value. The practitioner also considers the response's own risk — every new control introduces complexity, and outsourcing introduces third-party risk (3A3).
3A2 Risk and Control Ownership
Every risk needs a named owner, and every control needs a named owner, and they are not always the same person. The risk owner is accountable for the risk — the business person who decides what to do about it, accepts the residual, and answers for the outcome. The control owner is responsible for the control's design, implementation, and operation — often a technical or operational role. The risk owner chooses the response; the control owner delivers the control that implements it.
Ownership fails in predictable ways the exam loves. Orphaned risks — assessed, registered, owned by "the team" — are unmanaged risks. Risk owners without authority — accountable in name but unable to fund the response or accept the residual — produce responses that never happen. And ownership that follows the org chart instead of the risk — the CISO "owning" all cyber risk while business units make the decisions that create it — separates accountability from the power to act. ISACA's supporting tasks make assignment explicit: the practitioner identifies risk owners and control owners and holds each to their distinct accountability.
3A3 Vendor/Supply Chain Risk Management
Third parties extend the enterprise's risk surface beyond its control boundary: suppliers, developers, system integrators, and external service providers all touch the organization's data, systems, or operations. NIST SP 800-161 defines Cybersecurity Supply Chain Risk Management (C-SCRM) as a systematic process for managing exposure to cybersecurity risks throughout the supply chain and developing appropriate response strategies, policies, processes, and procedures. The key word is systematic — not a questionnaire filed at onboarding, but a lifecycle.
The lifecycle runs: establish the C-SCRM frame (strategy, policy, risk tolerance for supply chain exposure), assess suppliers before and during the relationship (due diligence proportionate to criticality — the payroll processor gets more scrutiny than the office-supply vendor), flow security requirements into contracts (right to audit, breach notification timelines, subcontractor controls, data return and destruction), monitor continuously (performance, incidents, financial health, changes in ownership or subcontracting), and plan for exit (data retrieval, access revocation, transition of services).
The exam tests three pressure points. First, criticality drives rigor: assessment depth, contract terms, and monitoring intensity scale with the supplier's access to sensitive data and its importance to critical processes. Second, the organization retains accountability for risks its suppliers create — outsourcing the work never outsources the risk, and regulators and customers hold the enterprise responsible for its vendors' failures. Third, fourth parties matter: the supplier's own suppliers are part of the chain, and contracts should require visibility into material subcontracting. A vendor program that assesses the vendor but ignores its subcontractors has drawn the boundary in the wrong place.
3A4 Issues, Findings, Exceptions and Exemptions Management
Not everything goes according to plan. Issues are problems identified during risk management activities — a control that is not operating, a risk that has grown beyond tolerance, a response that is behind schedule. Findings are the output of assessments and audits — the specific gaps reported with evidence. Both need the same discipline: documented, assigned an owner, given a remediation date proportionate to the risk, tracked to closure, and verified — not merely marked complete when someone says the work is done.
Exceptions and exemptions are the formal way of handling the cases where the standard answer does not apply. An exception is a temporary, approved deviation from policy or control requirements — the legacy system that cannot support multi-factor authentication gets an exception with compensating controls and an expiration date. An exemption is a longer-term or permanent relief from a requirement, granted where the requirement does not fit the circumstances. NIST SP 800-161's rule for exceptions illustrates the discipline: when exceptions are made for compelling operational requirements, approval by the authorizing official should be contingent upon explicitly incorporating risk assessments into the broader assessment and implementing compensating controls to address the gaps. An exception approved by the person who wants it, rather than the risk owner, is self-dealing.
3B1 Control Frameworks, Types, and Standards
Controls are the safeguards that modify risk — the means of managing risk, including policies, procedures, practices, and organizational structures. Practitioners classify controls along several dimensions, and the exam tests all of them.
By function (ISACA's glossary taxonomy): preventive controls avoid undesirable events before they occur — access controls, input validation, segregation of duties, encryption, firewalls. Detective controls identify and report events that have occurred — log monitoring, reconciliations, exception reports, intrusion detection. Corrective controls fix the damage after detection — backups and restore procedures, incident response playbooks, rollback plans. Classify by primary purpose: a firewall that blocks an attack in real time is preventive even though it noticed the attack; a system that only reports it is detective. The exam's trap is the control that both detects and stops — the question asks what it primarily does.
By nature: administrative controls are the rules, procedures, and practices — policies, training, separation of duties. Technical (logical) controls are the system-enforced mechanisms — authentication, encryption, access control lists. Physical controls protect the tangible — locks, guards, fire suppression. A complete control set layers all three: the policy requires visitor logging (administrative), the badge system enforces it (technical), and the locked door makes it real (physical).
By relationship to the requirement: compensating controls are alternatives used when the primary control cannot be implemented — enhanced manual review where automated segregation is technically impossible, with the requirement that they actually reduce risk to an equivalent level and be supportable with evidence. Directive controls guide behavior toward the desired outcome — policies, standards, training. Deterrent controls discourage violations — warning banners, visible cameras.
Control frameworks organize all of this into implementable catalogs. NIST SP 800-53 is the federal control catalog — families of management, operational, and technical controls with baselines by impact level. The NIST Cybersecurity Framework 2.0 organizes outcomes by function (Govern, Identify, Protect, Detect, Respond, Recover). COBIT 2019 provides governance and management objectives. ISO/IEC 27001/27002 specifies the information security management system and its control guidance. The practitioner does not memorize catalogs; the practitioner selects controls from them proportionate to the risk, and the exam tests selection logic, not catalog contents.
3B2 Control Design, Selection, Implementation, and Analysis
Control selection follows the risk response: the response says mitigate, and the control set is how. Good control design starts from the risk scenario — which threat, exploiting which vulnerability, against which asset — and chooses controls that address the actual causal chain, not the generic checklist. A scenario about phishing-driven credential theft calls for MFA (preventive), email filtering (preventive), and monitoring of anomalous logins (detective); a scenario about database misconfiguration calls for configuration baselines and change control. Controls selected without reference to scenarios are decorations.
Design principles the exam tests: defense in depth — layered controls so no single failure is fatal; least privilege — every user, process, and system gets only the access it needs; separation of duties — no single person controls all stages of a critical process (the person who approves payments cannot also disburse them); and fail-secure — when a control fails, it fails closed, denying access rather than granting it.
Implementation turns design into operation: assign the control owner, document the procedure, configure and deploy, train the operators, and establish the evidence the control leaves behind — because a control without evidence cannot be tested (3B3) or monitored (3C4). Then comes analysis: is the control operating as designed, is it actually reducing the risk it was built for, and is it still cost-effective? Controls degrade — configurations drift, staff turn over, threats evolve — and analysis is what catches the decay. A control that was effective at implementation and is never re-analyzed is an assumption, not a safeguard.
Cost-effectiveness runs through all of it. The practitioner compares the control's total cost — implementation, operation, maintenance, and the friction it imposes on the business — against the risk reduction it delivers, measured as the change in exposure (Chapter 2's ALE arithmetic applies directly). A control that costs more than the risk it removes, or that the business bypasses because it is unusable, is a failed design regardless of its technical elegance.
3B3 Control Testing Methodologies
Testing answers two questions: is the control designed correctly, and does it operate effectively? Design testing (a walkthrough of the design against the risk scenario) comes first — there is no point testing the operation of a control that cannot work. Operating effectiveness testing then examines whether the control worked consistently over the period.
SP 800-53A's assessment methods are the tester's toolkit: examine (review documents, configurations, logs — the evidence the control leaves), interview (ask the operators and owners how the control works — and compare the answer to the evidence), and test (actively exercise the control — attempt the unauthorized access, submit the malformed input, trigger the alert). Strong testing combines all three; testing that relies on interviews alone tests the story, not the control.
Testing produces findings (3A4): control deficiencies — design gaps where the control cannot achieve its objective, and operating failures where a sound control was not followed. Deficiencies are rated by the risk they leave exposed, assigned owners, remediated, and retested. The exam's discipline point: testing is periodic and risk-based — critical controls over significant risks are tested more often and more deeply — and test results feed monitoring and reporting, closing the loop from 3C back to the risk register.
3C1 Risk Action Plans
A risk action plan is the documented program for executing the chosen risk responses: what will be done, by whom, by when, with what resources, and how completion will be verified. NISTIR 8286A points to the Plan of Action and Milestones (POA&M) as the instrument that records agreed-upon future risk activities. The plan turns the register's "mitigate" into accountable work — each action names an owner, carries a milestone date proportionate to the risk's severity, and defines the evidence that will demonstrate completion.
Action plans fail the way projects fail: vague actions ("improve security awareness") with no measurable outcome, owners without authority or resources, dates that slip without escalation, and completion declared on effort rather than evidence. The practitioner's discipline is to make every action specific, measurable, owned, and time-bound — and to escalate overdue actions on significant risks rather than quietly re-dating them. The plan is also where the response's cost-effectiveness is rechecked: if implementation costs have grown past the exposure they address, the plan — and the response — needs rethinking, not just more budget.
Before you buy
- How do I get it?
- Pay, and the download appears on this page straight away. The links are also emailed to you. No account is required.
- What if it isn't for me?
- Email us within 14 days for a full refund, no questions asked.
- Is there online practice for this exam too?
- No. PrepPass has no online question bank for this exam; the book is self-contained. Its chapter quizzes and full-length practice exam, each question with a worked explanation, are all in the PDF and EPUB.
- Can I read it on my phone?
- Yes — the EPUB is for phones and e-readers, the PDF is for printing and tabbing. You get both.
The details
Written to ISACA's 2025 CRISC Exam Content Outline (effective November 3, 2025), 200 original questions with worked explanations, and a 150-question full-length practice exam at the new domain weights.
- Format: PDF + EPUB download · 143 pages
- 200 practice questions in the book, with a full answer key
- $24.99 one-time — no subscription
- 14-day money-back guarantee · refund policy
- Cross-referenced against: ISACA's published CRISC Exam Content Outline (2025) and exam candidate information
- Last updated: September 2026
- Verified from the official source(ISACA's published CRISC Exam Content Outline (2025) and exam candidate information)
- Instant download, yours for life
A CRISC review course or boot camp runs $795–$3,999. This book teaches the same exam — same rules, verified to current standards — for a one-time $24.99 you keep for life.
What the book gives you
PrepPass has no online question bank for this exam, so the $24.99 book is complete in itself: the material taught in order, a quiz closing each chapter and a full-length practice exam, in a file you own.
- Systematic teaching — every exam section explained chapter by chapter, start to finish, not just questions
- Print it & tab it — a paper-ready PDF you can highlight, mark up, and bring to your study table
- Study anywhere, offline — EPUB on your phone or e-reader; no wifi, no browser tabs
- Everything in one place — the chapters and the practice questions in one file
- Yours for life — one-time $24.99, instant download, no subscription
And it's risk-free: 14-day money-back guarantee — not satisfied? Email us for a full refund, no questions asked. See the refund policy.
14-day money-back guarantee · full refund, no questions asked.
One-time purchase, lifetime access to the download. The eBook is the full CRISC — Certified in Risk and Information Systems Control study guide in PDF and EPUB. Educational summary, not professional or legal advice — always confirm the current rules with the official source. Last updated: September 2026.