logo-img
CRISC training - Certified in Risk and Information Systems Control

CRISC training - Certified in Risk and Information Systems Control

4 days + 365 days of online support via the MyTSTC learning platform Classroom MyTSTC

Sharpest price in just 2 steps

Requesting more information and/or the current price of this training is easy. We take into account any ongoing promotions, subsidies, or relationship discounts.

Description

The CRISC training prepares you strategically for the unique challenges of IT and enterprise risk management. You will learn everything about identifying and managing (business) risks through the development, implementation, and maintenance of controls appropriate to the information systems (IS) in an organization.

This training enables you to assess IT risks based on their threat to the organization, valuable or sensitive data, and the objectives pursued. You will then learn to create plans to mitigate these risks and avoid them where possible. In doing so, you will take into account conditions related to governance and compliance, efficiency, and the continuity of performance.

In preparation for the CRISC training, you will receive the official ISACA study material upon registration and one year of access to the accompanying MyTSTC learning platform. By doing a short self-study before the training, you will enter the classroom training better prepared and can ask more targeted questions to the experienced instructor based on the material covered. The result is a more interactive course with greater depth on the heavier topics and less variation in levels among participants.

Our CRISC training is classroom-based but can also be attended Live Online if desired. You will then follow the training live remotely with our own instructor, view the slides and notes on the whiteboard, and can ask questions to both the trainer and your fellow participants. Essentially, it is just like being present in the classroom training, but from your own location. If the Live Online training does not meet your expectations, you may attend the classroom training again free of charge within a year.

Working method

We deviate from the regular CRISC training by starting with a short, guided self-study period after registration. For this, you will receive the CRISC Review Manual by post and gain access to our exclusive MyTSTC learning platform prior to the classroom days. On the platform, you will take a short assessment test after which you will receive tailored material (including videos) based on your answers to prepare you for the intensive training. Furthermore, you will already read a limited number of pages from the Review Manual. With this approach, we reduce differences in levels among participants and spread the necessary self-study over a part before and after the training.

We advise you to practice with the included test questions from the ISACA CRISC Questions, Answers & Explanations database after the training before participating in the exam to get accustomed to the typical ISACA question format. If you need further guidance, you will receive it through MyTSTC. Finally, it is possible to attend the training again free of charge within a year (not applicable for in-company training). For example, if you unexpectedly fail, but also if you wish for extra help towards the exam.

This training is classroom-based but can also be attended Live Online if desired. You will then follow the training live remotely with our own instructor, view the slides and notes on the whiteboard, and can ask questions to both the trainer and your fellow participants. Essentially, it’s just like being present in the classroom training, but from your own location.

Certification

This training prepares you for the CRISC exam from ISACA. This exam can be taken throughout the year at various exam locations in the Netherlands, including at TSTC or from home under the supervision of your webcam. There are no admission requirements for exam participation. However, you must have sufficient relevant practical experience to hold the CRISC title upon successful completion. If you do not yet meet the requirement, it is possible to gain this experience after passing the exam. Students who unexpectedly fail the exam may participate in the classroom training again free of charge. Our support only ends when you succeed.

Training Requirements

  • (IT) Risk Managers
  • (IT) Risk Officers
  • (Chief) Compliance Officers
  • Chief Information Security Officers (CISO)
  • Chief Information Officers (CIO)
  • Security Managers
  • IT Managers
  • Audit Managers
  • IT Consultants
  • Professionals die een 27001 implementatie doen of begeleiden.

Training Content

De CRISC training en het examen bestaan uit onderstaande vier ‘job practice area’s’. ISACA toetst de invulling ervan continu aan de actualiteit zodat de training aan blijft sluiten op het hedendaagse profiel van de Risk Professional:

Organizational Governance A

Organizational Strategy, Goals and Objectives
Organizational Structure, Roles and Responsibilities
Organizational Culture
Policies and Standards
Business Processes
Organizational Assets
Risk Governance B

Enterprise Risk Management and Risk Management Framework
Three Lines of Defense
Risk Profile
Risk Appetite and Risk Tolerance
Legal, Regulatory and Contractual Requirements
Professional Ethics of Risk Management

IT Risk Identification A

Risk Events (e.g., contributing conditions, loss result)
Threat Modelling and Threat Landscape
Vulnerability and Control Deficiency Analysis (e.g., root cause analysis)
Risk Scenario Development
IT Risk Analysis and Evaluation B

Risk Assessment Concepts, Standards, and Frameworks
Risk Register
Risk Analysis Methodologies
Business Impact Analysis
Inherent and Residual Risk

Risk Response A

Risk Treatment / Risk Response Options
Risk and Control Ownership
Third-Party Risk Management
Issue, Finding and Exception Management
Management of Emerging Risk
Control Design and Implementation B

Control Types, Standards and Frameworks
Control Design, Selection and Analysis
Control Implementation
Control Testing and Effectiveness Evaluation
Risk Monitoring and Reporting C

Risk Treatment Plans
Data Collection, Aggregation, Analysis and Validation
Risk and Control Monitoring Techniques
Risk and Control Reporting Techniques (heatmap, scorecards, dashboards)
Key Performance Indicators
Key Risk Indicators (KRIs)
Key Control Indicators (KCIs)

Information Technology Principles A

Enterprise Architecture
IT Operations Management (e.g. change management, IT assets, problems, incidents)
Project Management
Disaster Recovery Management (DRM)
Data Lifecycle Management
System Development Life Cycle (SDLC)
Emerging Technologies
Information Security Principles B

Information Security Concepts, Frameworks and Standards
Information Security Awareness Training
Business Continuity Management
Data Privacy and Data Protection Principles

Description

The CRISC training prepares you strategically for the unique challenges of IT and enterprise risk management. You will learn everything about identifying and managing (business) risks through the development, implementation, and maintenance of controls appropriate to the information systems (IS) in an organization.

This training enables you to assess IT risks based on their threat to the organization, valuable or sensitive data, and the objectives pursued. You will then learn to create plans to mitigate these risks and avoid them where possible. In doing so, you will take into account conditions related to governance and compliance, efficiency, and the continuity of performance.

In preparation for the CRISC training, you will receive the official ISACA study material upon registration and one year of access to the accompanying MyTSTC learning platform. By doing a short self-study before the training, you will enter the classroom training better prepared and can ask more targeted questions to the experienced instructor based on the material covered. The result is a more interactive course with greater depth on the heavier topics and less variation in levels among participants.

Our CRISC training is classroom-based but can also be attended Live Online if desired. You will then follow the training live remotely with our own instructor, view the slides and notes on the whiteboard, and can ask questions to both the trainer and your fellow participants. Essentially, it is just like being present in the classroom training, but from your own location. If the Live Online training does not meet your expectations, you may attend the classroom training again free of charge within a year.

Working method

We deviate from the regular CRISC training by starting with a short, guided self-study period after registration. For this, you will receive the CRISC Review Manual by post and gain access to our exclusive MyTSTC learning platform prior to the classroom days. On the platform, you will take a short assessment test after which you will receive tailored material (including videos) based on your answers to prepare you for the intensive training. Furthermore, you will already read a limited number of pages from the Review Manual. With this approach, we reduce differences in levels among participants and spread the necessary self-study over a part before and after the training.

We advise you to practice with the included test questions from the ISACA CRISC Questions, Answers & Explanations database after the training before participating in the exam to get accustomed to the typical ISACA question format. If you need further guidance, you will receive it through MyTSTC. Finally, it is possible to attend the training again free of charge within a year (not applicable for in-company training). For example, if you unexpectedly fail, but also if you wish for extra help towards the exam.

This training is classroom-based but can also be attended Live Online if desired. You will then follow the training live remotely with our own instructor, view the slides and notes on the whiteboard, and can ask questions to both the trainer and your fellow participants. Essentially, it’s just like being present in the classroom training, but from your own location.

Certification

This training prepares you for the CRISC exam from ISACA. This exam can be taken throughout the year at various exam locations in the Netherlands, including at TSTC or from home under the supervision of your webcam. There are no admission requirements for exam participation. However, you must have sufficient relevant practical experience to hold the CRISC title upon successful completion. If you do not yet meet the requirement, it is possible to gain this experience after passing the exam. Students who unexpectedly fail the exam may participate in the classroom training again free of charge. Our support only ends when you succeed.

Training Requirements

  • (IT) Risk Managers
  • (IT) Risk Officers
  • (Chief) Compliance Officers
  • Chief Information Security Officers (CISO)
  • Chief Information Officers (CIO)
  • Security Managers
  • IT Managers
  • Audit Managers
  • IT Consultants
  • Professionals die een 27001 implementatie doen of begeleiden.

Training Content

De CRISC training en het examen bestaan uit onderstaande vier ‘job practice area’s’. ISACA toetst de invulling ervan continu aan de actualiteit zodat de training aan blijft sluiten op het hedendaagse profiel van de Risk Professional:

Organizational Governance A

Organizational Strategy, Goals and Objectives
Organizational Structure, Roles and Responsibilities
Organizational Culture
Policies and Standards
Business Processes
Organizational Assets
Risk Governance B

Enterprise Risk Management and Risk Management Framework
Three Lines of Defense
Risk Profile
Risk Appetite and Risk Tolerance
Legal, Regulatory and Contractual Requirements
Professional Ethics of Risk Management

IT Risk Identification A

Risk Events (e.g., contributing conditions, loss result)
Threat Modelling and Threat Landscape
Vulnerability and Control Deficiency Analysis (e.g., root cause analysis)
Risk Scenario Development
IT Risk Analysis and Evaluation B

Risk Assessment Concepts, Standards, and Frameworks
Risk Register
Risk Analysis Methodologies
Business Impact Analysis
Inherent and Residual Risk

Risk Response A

Risk Treatment / Risk Response Options
Risk and Control Ownership
Third-Party Risk Management
Issue, Finding and Exception Management
Management of Emerging Risk
Control Design and Implementation B

Control Types, Standards and Frameworks
Control Design, Selection and Analysis
Control Implementation
Control Testing and Effectiveness Evaluation
Risk Monitoring and Reporting C

Risk Treatment Plans
Data Collection, Aggregation, Analysis and Validation
Risk and Control Monitoring Techniques
Risk and Control Reporting Techniques (heatmap, scorecards, dashboards)
Key Performance Indicators
Key Risk Indicators (KRIs)
Key Control Indicators (KCIs)

Information Technology Principles A

Enterprise Architecture
IT Operations Management (e.g. change management, IT assets, problems, incidents)
Project Management
Disaster Recovery Management (DRM)
Data Lifecycle Management
System Development Life Cycle (SDLC)
Emerging Technologies
Information Security Principles B

Information Security Concepts, Frameworks and Standards
Information Security Awareness Training
Business Continuity Management
Data Privacy and Data Protection Principles

shape

I am taking this next step in my lifelong learning journey.

1

Applicant Information

2

Billing Information

What Can I Learn After The CRISC training - Certified in Risk and Information Systems Control?

  • Identifying relevant standards, frameworks, and methodologies
  • Identifying relevant stakeholders
  • Describe the key elements of a risk register.
  • Analyzing risk scenarios
  • Communicating the results of IT risk assessments to relevant stakeholders
  • Explaining how residual risk relates to inherent risk, risk appetite, and risk tolerance.
  • Explain the principles of risk ownership.
  • Distinguishing between Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs)
  • Describe various tools and techniques for testing and assessment.
  • Applying risk identification techniques
  • Discuss tools and techniques for developing risk scenarios.
  • Contributing to the creation of a risk awareness program
  • Identify the current status of measures.
  • Create a list of the different risk response options.
  • Discuss the necessity of conducting a cost-benefit analysis for determining a risk response.
  • Utilizing a good understanding of the System Development Life Cycle (SDLC) process to implement IS controls efficiently and effectively.
  • Describe tools and techniques for data extraction, aggregation, and analysis.
  • Distinguishing between threats and vulnerabilities
  • Explain the meaning of the key concepts for risk management, including risk appetite and risk tolerance.
  • Identifying and applying risk assessment techniques
  • Assessing gaps between the current and desired state of the IT risk environment
  • Define various parameters for risk-response selection.
  • Developing a risk action plan
  • Understanding the necessity of maintaining measures
  • Comparing different monitoring tools and techniques

Schedules

This training is scheduled as follows in the coming period. Missing a date? Feel free to contact us.

Date: 22 - 25 juni 2026

Location: TSTC Veenendaal - Klassikaal & Live Online

Date: 14 - 17 september 2026

Location: TSTC Veenendaal - Klassikaal & Live Online

Date: In overleg

Location:

1

Applicant Information

2

Billing Information

Learning paths

This training can also be taken as part of the below learning path(s). If you want to follow multiple titles from a learning path, please contact our advisors for a suitable bundle offer.

Shape

Frequently Asked Questions

CISM primarily addresses risk management from the security management perspective: how to set up a security program and how risks are incorporated into it. CRISC, on the other hand, delves much deeper into identifying, analyzing, and addressing IT risks. With just CISM, you primarily position yourself as a security manager. By adding CRISC, you demonstrate that you are also specialized in enterprise IT risk management and control design. CRISC goes into more detail on: ● Designing controls ● Evaluating control effectiveness ● Choosing risk responses (mitigating, accepting, transferring, avoiding). This provides a more practical risk perspective alongside the management focus of CISM and thus also helps in better executing your risk-related tasks as a security manager.

Although both trainings focus on risk management, they target different perspectives. CRISC focuses on enterprise IT risk management and addresses how IT risks are linked to business objectives and governance. The perspective of CRISC is therefore broader than just information security. The ISO 27005 Certified Risk Manager training specifically targets information security risks and follows the methodology from ISO/IEC 27005. This is often applied within an ISMS according to ISO/IEC 27001. Finally, CRISC pays more attention to governance and control frameworks, while ISO 27005 Certified Risk Manager mainly limits itself to more practical tasks such as risk assessment techniques, risk analyses, risk treatment within an ISMS, and thus the integration with ISO 27001.

I am taking this next step in my lifelong learning journey.

1

Applicant Information

2

Billing Information

Why experienced professionals choose TSTC for their studies

Train smarter, not harder. TSTC's unique approach guarantees the effective acquisition of skills and the greatest chance of success.

Learn more about TSTC
Toucan Rhino