All certifications
ISACA
CRISCOfficial MoU PartnerProfessional

Certified in Risk and Information Systems Control

Build expertise in identifying, assessing, and managing enterprise IT risk.

40 instructional hoursArea: Risk3 Credit Course or Integrated

Which ISACA certification is right for you?

Key areas
Deployment and management of enterprise IT risk and controls.
Career stage
Mid-level IT professionals looking for career growth in IT risk.
Average salary (US$)
$167,145
Typical job titles
Risk and Security Manager, IS or Business Analyst, IS Manager, Operations Manager, Information Control Manager, Chief Information Security or Compliance Officer
Experience required
Three years of experience in IT risk and/or security and audit.
Exam required
Yes
Recommended pre-requisites
For early career: IT Risk Fundamentals certificate. CISA certification is a plus.
Hands-on labs
No — knowledge-based exam.
Career path advancement
Pursue CISM and/or CGEIT to develop a more strategic mindset.

CPE credit hours

Continuing Professional Education (CPE) is essential for maintaining ISACA certification status. Year 1 CPE hours are optional. Years 2+ require a minimum of 20 CPEs each year and 120 CPEs over three years, plus compliance with the ISACA Code of Professional Ethics. Full policies: isaca.org.