Loading Events

Training Calendar

หลักสูตรที่ได้รับการออกแบบเนื้อหาที่ครอบคลุม ทั้งทฤษฎี เทคนิค และสาระน่ารู้ที่ทันสมัยสอนโดยอาจารย์ผู้เชี่ยวชาญ และมีประสบการณ์ด้านความปลอดภัยของสารสนเทศโดยตรง

CRISC (Exam Prep.)

กำหนดการ
08/07/2026 - 10/07/2026
9:30 am - 4:30 pm

About this course

A Certified in Risk and Information Systems Control® (CRISC®) certification demonstrates your IT risk management expertise. By taking a proactive approach, you will learn how to enhance your organization’s business resilience, deliver stakeholder value and optimize risk management across the enterprise. As a CRISC, you will be ready to address emerging technology, including AI risk assessment and general best practices for risk management and mitigation related to AI data governance and ethics.

Course Benefits

The CRISC course offers students outstanding benefits, including:

  • Three full days of intense instruction with no outside distractions
  • In-person access to the top security experts in the industry
  • Lunch and snacks provided on each day of class
  • Worldwide recognition as a universally accepted information systems manager
  • Opportunity to build upon existing certifications/credentials already earned
  • Provides tangible evidence of career growth
  • Potential for a salary increase and/or promotion
  • Intense Courseware:
    • ISACA Authorized Courseware including:
      CRISC Review Manual
      CRISC Review Questions, Answers & Explanations Manual
  • Excellent Certification Preparation (Note that Students are responsible for registering for the exam and transportation to the exam; InfoSec Institute will not provide exam logistics or transportation support)

Module

DOMAIN 1 – GOVERNANCE

The governance domain interrogates your knowledge of information about an organization’s business and IT environments, organizational strategy, goals and objectives, and examines potential or realized impacts of IT risk to the organization’s business objectives and operations, including Enterprise Risk Management and Risk Management Framework.

A—ORGANIZATIONAL GOVERNANCE

  1. Strategy, Goals, and Objectives
  2. Organizational Structure, Roles, and Responsibilities
  3. Organizational Culture and Ethics
  4. Policies and Standards
  5. Business Processes and Resilience (e.g., DRP, BCP)
  6. Organizational Asset Management

B—RISK GOVERNANCE

  1. Enterprise Risk Management (ERM)
  2. Lines of Defense
  3. Risk Profile
  4. Risk Appetite and Risk Tolerance
  5. Risk Frameworks, Legal, Regulatory, and Contractual Requirements

DOMAIN 2 – RISK ASSESSMENT

This domain will certify your knowledge of threats and vulnerabilities to the organization’s people, processes and technology as well as the likelihood and impact of threats, vulnerabilities and risk scenarios.

A—RISK IDENTIFICATION

  1. Risk Events
  2. Threat Modeling and Threat Landscape
  3. Vulnerability Management
  4. Risk Scenario Development and Evaluation

B—RISK ANALYSIS

  1. Risk Assessment Concepts and Standards
  2. Business Impact Analysis (BIA)
  3. Risk Register
  4. Risk Analysis Methodologies
  5. Inherent and Residual Risk

DOMAIN 3 – RISK RESPONSE AND REPORTING

This domain deals with the development and management of risk treatment plans among key stakeholders, the evaluation of existing controls and improving effectiveness for IT risk mitigation, and the assessment of relevant risk and control information to applicable stakeholders.

A—RISK RESPONSE

  1. Risk Response Options
  2. Risk and Control Ownership
  3. Vendor/Supply Chain Risk Management
  4. Issues, Findings, Exceptions and Exemptions Management

B—CONTROL DESIGN AND IMPLEMENTATION

  1. Control Frameworks, Types, and Standards
  2. Control Design, Selection, Implementation, and Analysis
  3. Control Testing Methodologies

C—RISK MONITORING AND REPORTING

  1. Risk Action Plans
  2. Data Collection, Aggregation, Analysis, and Validation
  3. Risk and Control Metrics (e.g., KRIs, KCIs, KPIs)
  4. Risk and Control Monitoring Techniques
  5. Risk and Control Reporting Techniques (e.g., heatmap, scorecards, dashboards)
  6. Monitoring and Reporting of Emerging Risks

DOMAIN 4 – TECHNOLOGY AND SECURITY

In this domain we interrogate the alignment of business practices with Risk Management and Information Security frameworks and standards, as well as the development of a risk-aware culture and implementation of security awareness training.

A—Technology and Security

  1. Technology Principles
  2. Technology Roadmaps and Enterprise Architecture (EA)
  3. Operations Management (e.g., change management, assets, DevOps, problems, incidents)
  4. System Development Life Cycle (SDLC)
  5. Data Lifecycle Management
  6. Portfolio and Project Management (e.g. Agile)
  7. Technology Resilience and Disaster Response/Recovery
  8. Emerging Technologies

B—INFORMATION SECURITY PRINCIPLES

  1. Security Concepts, Frameworks, and Standards
  2. Security/Risk Awareness and Training
  3. Data Privacy and Data Protection Principles

Who should Attend?

01

IT professionals

02

Risk professionals

03

Business analysts

04

Project managers

05

Compliance professionals

06

Risk identification specialists

07

Risk assessment specialists

08

Risk evaluation specialists

09

Risk response specialists

10

Risk monitoring specialists

11

IS control designers

12

IS control monitoring specialists

13

IS control implementation specialists/maintenance specialists

Certification and Accreditation

CRISC course extensively prepares students for the CRISC exam, which consists of 200 multiple-choice questions that cover the five information systems auditing areas. These areas have been created from a CRISC job practice analysis and reflect the work performed by information systems auditors.

Examination

Our CRISC exam preparation course assists IT professionals to accomplish the following business objectives in their enterprise:

* Designing, implementing, monitoring & maintaining risk-based, effective IS controls
* Compliance with regulatory requirements

Also covered are the 5 domains as required by ISACA:

1. Risk Identification Assessment and Evaluation (RI)
2. Risk Response (RR)
3. Risk Monitoring (RM)
4. IS Control Design and Implementation (CD)
5. IS Control Monitoring and Maintenance (MM)

  • Computer-based examination
  • 4 hours
  • 150 multiple-choice question exam
  • ISACA uses a 200 – 800 point scale with 450 as the passing mark for the exams

Training Info

Date : 

08/07/2026 - 10/07/2026

Time : 

9:30 am - 4:30 pm

Duration:  3 Days
Venue: Grande Centre Point Lumphini 16th Floor,1188 Rama IV Road,
Thungmahamek, Sathon, Bangkok 10120
Training price: 34,000 Baht (Ex.Vat)

02 670 8980-4 ext. 321, 322, 323

Bookings

Bookings are closed for this event.

ติดต่อเรา
เพื่อรับคำปรึกษาข้อมูลเพิ่มเติม
ACinfotec พร้อมเป็นพาร์ทเนอร์เคียงข้างคุณ ตั้งแต่ก้าวแรก… จนถึงการรับรอง