CRISC certification exam
Computer-based professional knowledge assessment
- Type
- Written
- Delivery
- Both
Passing score: 450 ISACA scaled score
Exam sections
Governance
At the center of “Governance” is objectives, responsible parties, risk significance, fitness of supporting information, sequence of action, and supportable conclusions. In this credential, candidates demonstrate whether they can determine who is responsible, how much support the judgment requires, and what should happen before later actions. It leads into “Risk Assessment” in the published outline.
Question notes
Knowing the heading “Governance” is not sufficient; a case may test whether the candidate gathers support before reaching or communicating a conclusion. The principal risk is evidence that cannot sustain the claim, misplaced ownership, early conclusions, or a response disconnected from the risk driving the case. The response should be supported by traceability from objective to risk, evidence, judgment, conclusion, and stakeholder communication. A provider-published percentage exists separately; no exact item distribution is derived from it.
Preparation tips
Turn “Governance” into a reviewable practice artifact. Exercise: Review a flawed conclusion, identify the missing or unreliable evidence, and rewrite it so the final judgment is supportable. Challenge condition: insufficient evidence, confused responsibility, premature judgment, or a response aimed at the visible symptom rather than the actual exposure. Completion evidence: traceability from objective to risk, evidence, judgment, conclusion, and stakeholder communication. Use the completed work to challenge a decision in “Risk Assessment”.
Risk Assessment
At the center of “Risk Assessment” is objectives, assigned accountability, risk significance, fitness of supporting information, sequence of action, and defensible conclusions. The assessable outcome is not recall, but an ability to determine who is responsible, how much support the judgment requires, and what should happen before later actions. In the published sequence, it follows “Governance” and precedes “Risk Response And Reporting”.
Question notes
Before acting on “Risk Assessment,” read the full scenario; the expected judgment should remain proportional to risk and consistent with governance responsibilities. Test the response for unverified inputs, unclear responsibility, judgment before analysis is complete, or an intervention focused on what is visible instead of the risk driving the case. Confirm the outcome with a documented link from objective into risk, evidence, judgment, conclusion, and stakeholder communication. Use the stored percentage for relative blueprint emphasis, not as a guarantee of exact assessment presentation.
Preparation tips
For “Risk Assessment,” use this drill: Review a flawed conclusion, identify the missing or unreliable evidence, and rewrite it so the final judgment is supportable. Negative test: insufficient evidence, confused responsibility, premature judgment, or an intervention focused on what is visible instead of the risk driving the case. Evidence to retain: an auditable connection between purpose and risk, evidence, judgment, conclusion, and stakeholder communication. Identify the evidence that would reveal this mistake when handling “Risk Response And Reporting”.
Risk Response And Reporting
“Risk Response And Reporting” tests whether a candidate understands objectives, assigned accountability, risk significance, reliability of support, sequence of action, and supportable conclusions. That understanding must support an ability to recognize the responsible party, judge what evidence is still missing, and select the defensible next response. In the published sequence, it follows “Risk Assessment” and precedes “Technology And Security”.
Question notes
For “Risk Response And Reporting,” the assessment context matters: the scenario can hinge on professional role, order of action, evidence quality, or stakeholder accountability. Failure mode to test: a weak factual basis, ambiguous accountability, unsupported conclusions, or action taken against a secondary issue rather than the risk driving the case. Verification should include a documented link from objective into risk, evidence, judgment, conclusion, and stakeholder communication. Section metadata carries the published emphasis; assessment composition can still vary within that boundary.
Preparation tips
Keep a short decision journal for “Risk Response And Reporting.” Complete this exercise: Review a flawed conclusion, identify the missing or unreliable evidence, and rewrite it so the final judgment is supportable. Record whether you detected or prevented a weak factual basis, ambiguous accountability, unsupported conclusions, or an intervention focused on what is visible instead of the risk driving the case. Attach a documented link from objective into risk, evidence, judgment, conclusion, and stakeholder communication. Challenge the handoff from the perspective of later work in “Technology And Security”.
Technology And Security
For “Technology And Security,” the relevant professional context is how least-privilege intent becomes actual behavior across security boundaries under realistic production conditions. The candidate is expected to tie the objective to access boundaries, accountable ownership, and evaluated controls, and observable access behavior, rather than answer from keyword familiarity alone. It draws on work established in “Risk Response And Reporting”.
Question notes
Prepare “Technology And Security” within the credential's wider flow, since several answers may sound reasonable until the responsible role and objective are identified. A defensible response accounts for an apparently correct configuration that meets the normal case while exposing excess privilege or an untested exception. Its support should include a policy-allowed case, a blocked authorization case, the policy evaluation path, and an audit record another reviewer can inspect. The structured record preserves domain weighting without inferring how many items will represent it.
Preparation tips
For “Technology And Security,” use an explain–perform–verify loop. Exercise: Build one policy-allowed case and one denied case, then trace the identity and policy path responsible for each result. Explain how this evidence confirms the “Technology And Security” result: a permitted case, a blocked authorization case, the policy evaluation path, and an audit record another reviewer can inspect. Also test for an apparently correct configuration that opens permissions beyond the stated need or ignores a bypass condition. Compare the result with the assumptions established during “Risk Response And Reporting”.
