Reference

Frameworks & Standards

These are the reference models the CRISC exam tests against — the frameworks named in the official job practice. You're not asked to recite them cover to cover; you're asked to know what each one is for, where it fits the risk lifecycle, and how its vocabulary shapes a well-formed answer.

Every summary is pinned to a current published version. Free for every tier — look one up whenever you need it.

Which framework applies where

● = primary CRISC-domain relevance · tap a name to jump

FrameworkD1GovernanceD2IT Risk AssessmentD3Risk Response & ReportingD4IT & Security
COSO ERM2017 (Integrating with Strategy and Performance)

COSO Enterprise Risk Management

D1 · GovernanceD3 · Risk Response & Reporting

An enterprise-wide framework for integrating risk management with strategy-setting and performance, owned at the top of the organisation.

Why it matters in CRISC

COSO ERM is the reference model for how risk connects to strategy and governance — appetite set at the top, risk considered when objectives are chosen, not bolted on after. A risk practitioner is expected to know that ERM is a governance discipline, not a control checklist.

Key elements

ElementWhat it is
Governance & CultureEstablishes oversight responsibilities and the risk culture — board oversight, operating structures, and the desired behaviours that set the tone for everything else.
Strategy & Objective-SettingIntegrates ERM into strategic planning: defining risk appetite and evaluating alternative strategies against it before objectives are locked in.
PerformanceIdentifies, assesses and prioritises risks that affect the achievement of objectives, then selects risk responses across the portfolio.
Review & RevisionReviews how the entity is performing and whether the ERM components are still working as intended, revising them as circumstances change.
Information, Communication & ReportingUses relevant information from internal and external sources to support ERM, and reports on risk, culture and performance to stakeholders.

💡 How it shows in the exam

Expect stems that test the sequence appetite → strategy → objectives (COSO's core insight that risk appetite shapes strategy selection), and questions distinguishing enterprise-level ERM governance from operational control activities.

COBITCOBIT 2019

Control Objectives for Information and Related Technologies

D1 · GovernanceD4 · IT & Security

ISACA's framework for the governance and management of enterprise IT, separating who directs (governance) from who runs (management).

Why it matters in CRISC

COBIT is ISACA's own governance framework, so its language shapes how CRISC frames IT governance: a clear split between governance (evaluate, direct, monitor) and management, with risk handled as a specific management objective (APO12, Managed Risk). Knowing this separation is core to Domain 1.

Key elements

ElementWhat it is
EDM — Evaluate, Direct & MonitorThe governance domain: the board evaluates options, directs management, and monitors outcomes. The one domain that is governance, not management.
APO — Align, Plan & OrganizeManagement domain covering strategy, architecture and — via APO12 — the managed-risk objective that a risk practitioner lives in.
BAI — Build, Acquire & ImplementManagement domain for acquiring and implementing solutions, including change, project and requirements management.
DSS — Deliver, Service & SupportManagement domain for operational delivery: service operations, security services, incidents and continuity.
MEA — Monitor, Evaluate & AssessManagement domain for performance monitoring, internal control assessment, and compliance with external requirements.

💡 How it shows in the exam

Questions lean on the governance-vs-management distinction (EDM is governance; APO/BAI/DSS/MEA are management) and on placing risk management as a defined objective within a governance system rather than an ad-hoc activity.

ISO 31000ISO 31000:2018

ISO 31000 — Risk Management Guidelines

D1 · GovernanceD2 · IT Risk AssessmentD3 · Risk Response & Reporting

A generic, sector-agnostic set of guidelines for managing any kind of risk, built on principles, a framework, and a repeatable process.

Why it matters in CRISC

ISO 31000 defines the risk-management process CRISC assumes you follow — assess, then treat, wrapped in continuous communication and monitoring. Its vocabulary (risk criteria, risk treatment, residual risk) is the neutral language the exam uses when it isn't naming a specific control framework.

Key elements

ElementWhat it is
Communication & consultationRuns throughout the process — engaging stakeholders so risk decisions reflect the full range of views, not just the risk team's.
Scope, context & criteriaDefines the boundaries of the assessment and the risk criteria (including appetite/tolerance) against which risk will be evaluated.
Risk assessmentThe three-step core: risk identification, risk analysis (likelihood × consequence), and risk evaluation against the criteria.
Risk treatmentSelecting and implementing options to modify risk (avoid, reduce, share/transfer, retain), then re-assessing the residual risk.
Monitoring & reviewOngoing checking that controls remain effective and that the risk picture hasn't shifted.
Recording & reportingDocumenting the process and outcomes to support decisions and demonstrate the risk process was actually followed.

💡 How it shows in the exam

The sequence is the trap: identification before analysis before evaluation before treatment. Stems often reward picking the earliest correct step (e.g. establishing context/criteria) over jumping straight to a control.

ISO/IEC 27001ISO/IEC 27001:2022

ISO/IEC 27001 — Information Security Management Systems

D2 · IT Risk AssessmentD3 · Risk Response & ReportingD4 · IT & Security

The certifiable standard specifying the requirements for an information security management system (ISMS) — a managed, risk-driven system for protecting information.

Why it matters in CRISC

27001 is where information-security risk assessment and treatment become a formal, auditable management system. It ties Domain 2 (assessment) and Domain 3 (treatment, via the Statement of Applicability) to Domain 4's security controls — the 2022 revision's Annex A lists 93 controls across four themes (organisational, people, physical, technological).

Key elements

ElementWhat it is
Context of the organisation (cl. 4)Determining internal/external issues, interested parties, and the ISMS scope — what the system is actually protecting.
Leadership (cl. 5)Top-management commitment, an information security policy, and assigned roles and responsibilities.
Planning (cl. 6)The risk engine: information security risk assessment and risk treatment, plus the Statement of Applicability justifying included/excluded Annex A controls.
Support & Operation (cl. 7–8)Resources, competence, awareness and documented information; then operating the risk assessment and treatment plans.
Performance evaluation (cl. 9)Monitoring, measurement, internal audit and management review — evidence the ISMS actually works.
Improvement (cl. 10)Handling nonconformities with corrective action and continually improving the ISMS.

💡 How it shows in the exam

Questions frame the Statement of Applicability and the risk-treatment plan as the link between a risk assessment and the controls chosen, and test that certification covers a managed system — not that every Annex A control is mandatory.

NIST CSFCSF 2.0 (2024)

NIST Cybersecurity Framework

D1 · GovernanceD2 · IT Risk AssessmentD4 · IT & Security

A voluntary framework of cybersecurity outcomes organised into core Functions, usable by any organisation to describe and improve its security posture.

Why it matters in CRISC

CSF gives a common vocabulary for cybersecurity outcomes that maps cleanly onto the risk lifecycle. The 2.0 revision (2024) added a sixth Function, Govern, elevating cybersecurity governance and risk-management strategy alongside the original five — a point the exam can test as a currency check.

Key elements

ElementWhat it is
Govern (GV)Added in CSF 2.0: establishes and monitors the organisation's cybersecurity risk-management strategy, expectations and policy — the governance wrapper around the other five.
Identify (ID)Understanding assets, the business context and cybersecurity risks — the asset and risk-assessment foundation.
Protect (PR)Safeguards to limit or contain the impact of a potential event — access control, awareness, data security, maintenance.
Detect (DE)Activities to identify the occurrence of a cybersecurity event in a timely way — monitoring and detection processes.
Respond (RS)Actions taken once an incident is detected — response planning, communications, analysis and mitigation.
Recover (RC)Restoring capabilities or services impaired by an incident, and improving from lessons learned.

💡 How it shows in the exam

The high-value fact is that CSF 2.0 has six Functions (Govern added), not five. Scenarios also use the Functions as a way to classify where a given control or activity sits in the lifecycle (e.g. monitoring is Detect, not Protect).

NIST RMFSP 800-37 Rev. 2

NIST Risk Management Framework

D2 · IT Risk AssessmentD4 · IT & Security

A structured, seven-step process for managing information-system security and privacy risk across the system life cycle, from preparation through continuous monitoring.

Why it matters in CRISC

RMF is the disciplined, control-centric complement to ISO 31000's generic process: it walks a specific system from categorisation through authorisation to ongoing monitoring. Revision 2 added the Prepare step at the front, making seven steps — a currency detail the exam can probe.

Key elements

ElementWhat it is
PrepareAdded in Rev. 2: essential activities to ready the organisation and system to manage security and privacy risk before categorisation begins.
CategorizeCategorise the system and the information it processes based on an impact analysis (confidentiality, integrity, availability).
SelectSelect an appropriate baseline of controls and tailor them to the system's specific risk.
ImplementImplement the selected controls and document how they are deployed.
AssessAssess whether the controls are implemented correctly, operating as intended and producing the desired outcome.
AuthorizeA senior official makes a risk-based decision to authorise the system to operate, accepting the residual risk.
MonitorContinuously monitor controls and the system's risk posture, feeding changes back into the process.

💡 How it shows in the exam

Questions test the ordering (Categorize precedes Select — you can't choose controls before you know the impact level) and the concept of a senior official formally accepting residual risk at the Authorize step.

CRISC is a trademark of ISACA. Lucid Mastery is an independent study aid and is not affiliated with, endorsed by, or sponsored by ISACA. All framework summaries are original and describe publicly published standards.