Credential type: certification examination · verified on the issuer's site September 20, 2026 issuer page
The Certified in Risk and Information Systems Control credential is an esteemed designation administered by ISACA. It evaluates professional competence across four distinct domains, covering governance, information technology risk assessment, risk response, reporting, and information technology security to support organizational operations and essential assets throughout their enterprise lifecycle and operations.
This credential suits risk management professionals, information security managers, system analysts, and internal auditors seeking to validate their ability to identify, assess, and manage enterprise-wide information technology risks.
Review ISACA study materials, official guides, and practice questions carefully to prepare for the assessment. Focus your study time on the four distinct domains, paying close attention to complex risk management frameworks and IT governance principles to ensure you master every single topic tested on the exam.
Covers baseline organizational governance principles, management activities, enterprise architecture, and the funding of information security programs to align sound risk management strategies directly with overarching business objectives and corporate goals.
Focuses heavily on identifying, estimating, and prioritizing risk to organizational operations, essential assets, individual stakeholders, and the wider community resulting directly from the use, deployment, and operation of modern information systems.
Deals with informing key decision makers and supporting effective risk responses by selecting appropriate mitigation strategies, designing action plans, and communicating vital risk assessment information across all levels of the organization.
Examines important information technology and security controls, security categorization processes, control implementation methodologies, and operational safeguards designed specifically to protect enterprise systems, networks, and sensitive data from threats.
Manage your 240 minutes carefully across 150 questions. Read each multiple-choice question carefully before selecting the best answer based on ISACA frameworks and standard risk management practices.
The certification exam consists of a total of 150 multiple-choice questions delivered in a linear format, requiring candidates to demonstrate their knowledge across all established domains within the designated time frame.
The exam uses a scaled score ranging from 200 to 800. You need to achieve a minimum scaled score of 450 or higher in order to successfully pass the certification exam.
You are given a total duration of 240 minutes to complete all questions on the test, so candidates must pace themselves appropriately to answer every single item before time expires.
The non-member registration price is $760, while the discounted ISACA member price is $575. You should always check directly with ISACA for the current certification path details.
Verified 2026-08-30
This detailed informational page was systematically built using official ISACA documentation, exam content outlines, and available standard references regarding risk assessment frameworks.