CISSP Domain 1: Security and Risk Management

The governance domain, and the largest in the exam outline: how an organisation decides what to protect, how much risk it will carry, which laws and standards bind it, and how it proves it acted with due care. Everything else in the CISSP sits inside decisions made here.

16% OF THE EXAM · 7 ARTICLES · 21 TERMS

What the exam outline covers

The ISC2 CISSP exam outline lists these areas for Domain 1 and gives the domain a weighting of 16%. The wording below is a plain-English paraphrase; the outline itself is the source.

  1. Professional ethics and the ISC2 Code
  2. Security concepts: confidentiality, integrity, availability, authenticity and non-repudiation
  3. Security governance principles and alignment with business goals
  4. Legal, regulatory and compliance requirements
  5. Investigation types and requirements
  6. Security policy, standards, procedures and guidelines
  7. Business continuity requirements and the business impact analysis
  8. Personnel security policies and procedures
  9. Risk management concepts: assessment, treatment, controls and monitoring
  10. Threat modelling concepts and methods
  11. Supply chain risk management
  12. Security awareness, education and training

Articles

Key terms

The expected yearly cost of a risk: Single Loss Expectancy multiplied by Annualized Rate of Occurrence (ALE = SLE x ARO), the figure that justifies control spending in quantitative analysis.

The monetary loss from one occurrence of a risk event: asset value multiplied by exposure factor (SLE = AV x EF), the per-incident building block of quantitative risk analysis.

The amount and type of risk leadership is willing to accept in pursuit of organisational objectives, set at board level and cascaded down as the boundary for every risk decision.

The decision on how to respond to an identified risk using one of four options: avoid it, transfer it, mitigate it, or accept it. Every identified risk gets exactly one deliberate response.

The risk that remains after controls are applied. It can never reach zero, so leadership must formally accept whatever remains within the organisation's risk appetite.

The classification of security controls by the function they perform: preventive, detective, corrective, deterrent, recovery, and directive. One control can serve several functions at once.

An alternative control adopted when the primary control is impractical or too costly. It must meet the intent and rigour of the original requirement, not merely gesture at it.

The top of the governance document hierarchy: a mandatory, high-level statement of management intent, implemented through standards and procedures and advised by guidelines.

Doing what a reasonable, prudent person would do to protect the organisation's interests. The ongoing act of implementing and maintaining reasonable safeguards. The do part.

The investigation and ongoing assessment that informs prudent decisions: researching risks, vetting vendors, verifying controls. The homework that precedes due care's action.

The binary decision about whether a baseline control applies to your environment at all. A control for a technology you do not run is scoped out. Applicability, not customisation.

Customising how the controls that apply to your environment are implemented: adjusting parameters, adding compensating controls, or refining assumptions to fit organisational reality.

Systematic identification and rating of the threats a system faces, performed during design so weaknesses are engineered out before deployment rather than discovered in production.

Microsoft's threat categorisation model: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege, each violating one security property.

Microsoft's threat-scoring model: Damage, Reproducibility, Exploitability, Affected users, Discoverability, rated on an agreed scale to rank threats a framework such as STRIDE has already found.

Identifying and reducing the risks inherited from suppliers, vendors, and service providers: tampered hardware, counterfeit components, malicious implants, and compromised updates.

The organisation-wide plan for keeping critical business functions running during and after a disruption. The umbrella programme that disaster recovery sits underneath.

The process that identifies critical business functions and the impact of their disruption over time, producing the recovery metrics (RTO, RPO, MTD) that drive continuity planning.

Splitting a critical process across multiple people so no individual can complete it alone, forcing collusion to commit fraud. A core control in Clark-Wilson and Domain 1 alike.

A control that requires two or more people to act together, at the same moment, to complete a single sensitive operation, so that no individual can perform it alone.

Layering physical, technical, and administrative controls so no single control failure exposes an asset; every layer assumes the layer in front of it can be breached.

Reading is half of it. Scenario questions in this domain tend to turn on the distinctions above, and the quickest way to find out which ones you hold is to answer some. The CISSP practice tests cover all eight domains with an explanation for every answer, and the free assessment gives you a baseline first.