Overview
Since its introduction in 2010, more than 24,000 professionals have obtained ISACA®’s Certified in Risk and Information Systems Control® (CRISC®) certification. The designation demonstrates to employers that the holder is able to identify, evaluate and manage information systems and technology risk, and help enterprises achieve their business objectives.
Private in-house training
Apart from public, instructor-led classes, we also offer private in-house trainings for organizations based on their needs. Call us at +852 2116 3328 or email us at [email protected] for more details.
Why Choose KORNERSTONE
- KORNERSTONE is the Only ISACA® Accredited Training Organization in HK
- ALL Official ISACA Material included
- Practical, scenario-based learning – focus on application, not just theory
- Over 85% Passing rate in ISACA program
- Pass Guaranteed (80% over attendance)
- Exclusive Offer on purchasing Exam Voucher
Skills Covered
- Pinpoint and evaluate technology-related risks across enterprise systems
- Formulate risk treatment plans and communicate findings to decision-makers
- Connect IT risk management with broader organizational governance structures
- Deploy security measures that address both current and emerging threats
- Track and report risk exposure levels to support informed business choices
Course Curriculum
- Domain 1 — Governance (26%)
- Domain 2 — Risk Assessment (20%)
- Domain 3 — Risk Response and Reporting (32%)
- Domain 4 — Information Technology and Security (22%)
Dates & Locations

Exam & Certification
- Successful completion of the CRISC examination
- A minimum of at least three (3) years of cumulative work experience performing the tasks of a CRISC professional across at least two (2) of the four (4) CRISC domains is required for certification. Of these two (2) required domains, one (1) must be in either Domain 1 or 2. There are no substitutions or experience waivers.
- Maintenance fees and a minimum of 20 contact hours of CPE are required annually. In addition, a minimum of 120 contact hours is required during a fixed 3-year period.
Trainer for this course
Mr. R Shiflet
MSc.
- CISSP®, PMP®, CRISC®, Prince2, ITIL Intermediate
- 30+ years solid experience in IT, System Security, Projects and Consultation
- Trained up thousands of IT professionals and project leaders in various industries
- Guest lecturer in different Universities, including University of Manchester, for over 10 years








