Course ID: #N/A

CRISC Certified in Risk and Information Systems Control

Duration: 3 days Dates: 30 August 2027 14 June 2027 1 March 2027 30 November 2026

CRISC is the ISACA certification for managing IT risk and controls in information systems. The course follows the current Exam Content Outline (valid from 3 November 2025) with the four domains Governance, Risk Assessment, Risk Response and Reporting, and Technology and Security. The course prepares you for the CRISC exam (the «Certified in Risk and Information Systems Control» certification).

Domain 1: Governance

  • Organisational governance: strategy, goals and objectives, organisational structure, roles and responsibilities
  • Organisational culture and ethics, policies and standards
  • Business processes and resilience, management of enterprise assets
  • Risk governance: enterprise risk management (ERM), lines of defense, risk profile
  • Risk appetite and risk tolerance
  • Risk frameworks and legal, regulatory and contractual requirements

Domain 2: Risk Assessment

  • Risk identification: risk events, threat modelling and threat landscape
  • Vulnerability management
  • Developing and evaluating risk scenarios
  • Risk analysis: risk assessment concepts and standards, business impact analysis
  • Risk register and risk analysis methods
  • Inherent risk and residual risk

Domain 3: Risk Response and Reporting

  • Risk response options, ownership of risks and controls
  • Risk management for suppliers and supply chains
  • Handling issues, findings, exceptions and exception approvals
  • Control design and implementation: control frameworks, types and standards; selection, implementation and analysis of controls; control testing methods
  • Risk monitoring: risk action plans; data collection, aggregation, analysis and validation
  • Risk and control indicators, monitoring and reporting techniques
  • Monitoring and reporting on emerging risks

Domain 4: Technology and Security

  • Technology principles, technology roadmaps and enterprise architecture
  • IT operations management, system development life cycle and data lifecycle management
  • Portfolio and project management
  • Technological resilience, emergency response and disaster recovery
  • Emerging technologies
  • Information security: security concepts, frameworks and standards, security and risk awareness and training
  • Principles of data privacy and data security
Learning Solution

Blended Learning, Firmenseminar, Individualcoaching, Klassenraumtraining, Online Live Webinar

Language

Deutsch, Englisch, Französisch, Italienisch

Dates

2026/11/30, 2027/03/01, 2027/06/14, 2027/08/30, flexibel, auf Anfrage

IT and business professionals who identify and manage risk through appropriate controls in information systems: risk and compliance managers, IT risk managers, information security and internal control professionals, business analysts and project managers.

Practical experience in IT risk management or with controls in information systems, as well as basic knowledge of IT operations and information security, is required. For certification, ISACA requires at least three years of professional experience in at least two of the four CRISC domains after passing the exam.

After the course you will be able to:

  • embed IT risk management in the organisation’s governance and define risk appetite and risk tolerance
  • identify and analyse risks based on threats, vulnerabilities and scenarios, and document them in the risk register
  • select appropriate risk responses and design, implement and test controls
  • monitor risks and controls using key indicators and report on them to the relevant audience
  • classify risks arising from technology, supply chains, emerging technologies and data privacy
  • prepare specifically for the CRISC exam

CHF2'650 excl. VAT

Clear

SIGN UP

Newsletter

Receive news about new courses, offers and promotions by email.

← Back

Thank you for your response. ✨

Email Subscription
Amazon
VMware and Virtualisation