CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingA practical CRISC exam preparation plan — resources, a domain-weighted study sequence, practice question strategy and a readiness checklist before you book.

Preparing for the Certified in Risk and Information Systems Control (CRISC) exam comes down to three things: learn ISACA's risk vocabulary and lifecycle until its way of thinking feels natural, weight your study time to match the four domain percentages, and drill scenario-style practice questions until you can consistently pick the best answer among four defensible ones. This article gives you a complete preparation system — the resources worth buying, a phased study sequence, a practice-question strategy and a readiness checklist — and assumes you already know what the certification is. If you don't, start with the CRISC certification guide and come back.
One orientation point before the plan. The CRISC exam is 150 multiple-choice questions in four hours, scored on a 200–800 scale with 450 needed to pass. As of 2026 it costs US$575 for ISACA members and US$760 for non-members (confirm current fees on isaca.org), and it tests the 2021 exam content outline across four domains: Governance (26%), Risk Assessment (22%), Risk Response and Reporting (32%), and Technology and Security (20%). Those weights are the skeleton of everything below.
ISACA publishes no official study-hours figure, and anyone quoting one as a guarantee is guessing. Prep literature commonly suggests two to four months of part-time study, and where you fall in that range depends almost entirely on how much of your day job already looks like the exam.
A useful way to place yourself:
One scheduling fact shapes your timeline: when you register, ISACA gives you a six-month eligibility window in which to sit the exam, and you can schedule as soon as 48 hours after payment. A sensible pattern is to study for three to five weeks first, then register once you're confident, which puts a real deadline on the calendar without risking a forfeited fee.
CRISC does not require a tall stack of books. It rewards depth in a few resources over breadth across many.
ISACA also sells an online review course, and instructor-led courses exist through training partners. These help most if you learn poorly from books or want structure imposed from outside. They are accelerants, not substitutes — no course removes the need to drill questions.
A note on ISACA membership: members pay US$185 less for the exam and get discounts on official materials, so price the bundle before you buy anything at non-member rates. Verify current membership dues on isaca.org, as they vary by chapter.
Rather than prescribing rigid weeks — your calendar is yours — this plan works in phases with clear exit criteria. Move on when you meet the criterion, not when the calendar says so.
Read the Review Manual's coverage of Domain 1 (Governance) and the risk-lifecycle concepts that thread through the whole exam: how risk appetite and tolerance are set, who owns risk, how the three lines of accountability work, and how IT risk connects to enterprise objectives. Don't take notes by transcription; instead, after each section, write two or three sentences answering "what decision does this concept support, and who makes it?" CRISC is an exam about decisions.
Exit criterion: you can explain the difference between risk appetite and risk tolerance, and between a risk owner and a control owner, to a colleague without notes.
Domains 2 and 3 — Risk Assessment (22%) and Risk Response and Reporting (32%) — together carry over half the exam, and Domain 3 is the single heaviest domain. Study them as one connected pipeline: identify and analyse risk, evaluate it against appetite, choose a response (accept, mitigate, transfer, avoid), design and implement controls, then monitor with key risk indicators and report upward.
Two study techniques earn their keep here:
Exit criterion: you can take an unfamiliar risk scenario and state, in ISACA's terms, the appropriate response type and how you would monitor and report it.
Domain 4 (20%) covers the technology and security concepts a risk practitioner needs — architecture, controls, resilience. If you come from security or infrastructure, much of this is revision; read it anyway, because the exam frames technology through a risk lens rather than an engineering one. The question is rarely "how does this control work?" and almost always "what does this control do to the risk position?"
End this phase with your first full-length timed practice test. Score it by domain, not just overall, and let the per-domain results dictate what you re-read.
Exit criterion: a completed 150-question timed test with a per-domain breakdown in hand.
Now the balance shifts from reading to answering. A daily rhythm that works: a block of 25–40 questions, then a slower review pass that matters more than the answering did. For every question you got wrong — and every one you got right by guessing — write down which domain it came from and why the credited answer beats your choice. Patterns will surface fast: perhaps you keep choosing the technically strongest control when the question asked what to do first, or you keep escalating when the scenario wanted analysis.
Take at least two more full-length, strictly timed simulations in this phase, ideally at the same time of day as your booked exam. Four hours for 150 questions is generous — over 90 seconds per question — but only if you don't burn twenty minutes agonising over five early scenarios. Practise flagging and moving on.
Avoid the one trap that quietly ruins this phase: memorising answers. If you can recognise a question and recall its letter without reading it, that question has stopped teaching you anything, and it has started giving you a falsely inflated score. Rotate question sources, and re-attempt old questions only after enough time has passed that you're reasoning, not remembering.
CRISC questions are mostly scenarios with four defensible answers, asking for the BEST, FIRST, or MOST important one. (For a fuller look at why this style trips people up, see how hard the CRISC exam is — one sentence of it here: the difficulty is judgement, not memorisation.) Three reasoning habits convert to marks:
Book your slot with confidence when you can tick all of these:
If two or more boxes stay unticked, delay a few weeks rather than gamble — a retake means paying the full fee again and waiting 30 days after a first failed attempt.
Taper rather than cram. In the final week, drop new material entirely; run one last timed simulation early in the week, then spend the remaining days on light review of your error log and flashcard-level definitions. The night before, stop early.
On the day, arrive (or log in) about 30 minutes early. During the exam you may take up to two breaks of ten minutes or less with the proctor's permission — plan roughly where you'll take one, because a two-minute reset around question 75 buys back more accuracy than it costs in time. You'll see a preliminary pass/fail result on screen immediately, with official scores following within ten working days. After a pass, you have five years to apply for certification, which carries a US$50 application processing fee.
Yes — there are no prerequisites to sit the exam, and the plan above works for career-changers; expect the longer end of the study range. Experience matters afterwards: certification requires three years of relevant experience with no waivers, and you have five years from passing to accumulate and apply.
Third-party courses and question banks are valuable for volume and variety, but the exam is written in the Review Manual's vocabulary and logic. Preparing entirely without official materials means guessing at the very definitions the exam turns on. The pragmatic combination is official manual + official QAE + one third-party question source.
Run the arithmetic: members save US$185 on the exam fee alone, plus discounts on the manual and QAE database. For most candidates buying official materials, membership costs less than the discounts it unlocks — but confirm current dues for your chapter on isaca.org before deciding.
You can retake after a 30-day wait (90 days after second and third attempts), up to four attempts in a rolling twelve-month period, paying the full registration fee each time. Treat your score report's domain breakdown as a targeted study plan for the retake.
Preparation systems only work once started, so make this week's actions small and concrete: download the exam content outline from isaca.org, decide on membership, order the Review Manual, and attempt a set of free CRISC sample questions cold. That cold baseline — taken before you've studied anything — is the most honest measure you'll ever get of the gap between your current experience and the exam, and everything in the plan above exists to close it. If you're still weighing CRISC against ISACA's security-management track before committing, settle that first with CRISC vs CISM; whether the investment pays off for your situation is covered in Is CRISC worth it?.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading