---
title: CRISC mind map
source: https://credentialpress.com/guides/crisc-mind-map
tags: [crisc, mindmap]
---

# CRISC exam: 150 questions, four domains

## 1 Governance (26%)
- A Organizational governance: strategy, structure, culture, policies, assets
- B Risk governance: ERM, lines of defense, risk profile, appetite and tolerance

## 2 Risk Assessment (22%)
- A Risk identification: events, threats, vulnerabilities, scenarios
- B Risk analysis: BIA, risk register, methods, inherent and residual risk

## 3 Risk Response and Reporting (32%)
- A Risk response: options, ownership, third-party risk, exceptions
- B Control design, implementation and testing
- C Monitoring and reporting: action plans, metrics, emerging risk

## 4 Technology and Security (20%)
- A Technology: architecture, SDLC, data lifecycle, resilience, emerging tech
- B Information security principles, awareness, data privacy

## Mnemonic: Good Analysts Reduce Threats
- **G** Governance
- **A** Risk Assessment
- **R** Risk Response and Reporting
- **T** Technology and Security
