Security and Risk Management
Domain 1 is the governance layer of the CISSP: ethics, the core security properties, how security serves the business, the legal and privacy landscape, continuity planning, personnel security and risk management. Items here usually ask what a risk advisor or security leader should do, not how a tool works.
Ethics and core security concepts
Every CISSP is bound by the ISC2 Code of Ethics, whose four mandatory canons cover duties to society, to honest and legal conduct, to principals, and to the profession. The outline widens the classic confidentiality-integrity-availability triad to five pillars by adding authenticity and nonrepudiation. Expect scenarios that ask which property a control or a failure touches.
Governance, frameworks and the law
Security exists to support the mission, so governance starts from business objectives and risk tolerance, not from products. NIST CSF 2.0 made this explicit with a new Govern Function alongside Identify, Protect, Detect, Respond and Recover. The legal side spans cybercrime, intellectual property, import/export controls and privacy regimes such as the GDPR, which reach across borders.
Business continuity and personnel security
Business continuity requirements come from a business impact analysis that ranks processes, sets tolerances and exposes dependencies, including external suppliers. Personnel security covers the whole employment life cycle, from screening to termination, and extends to contractors and vendors through agreements.
Risk management, threat modeling and supply chain
Risk management identifies threats and vulnerabilities, estimates likelihood and impact, and chooses a response within the organization's tolerance. Threat modeling applies the same thinking to a design before it is built. Supply chain risk management extends it to what you buy, using tools such as SBOMs and independent assessments.
Keep going: the full CISSP — Certified Information Systems Security Professional guide covers every section of the exam. CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.