Chapter 1 of 816% of exam

Security and Risk Management

Domain 1 is the governance layer of the CISSP: ethics, the core security properties, how security serves the business, the legal and privacy landscape, continuity planning, personnel security and risk management. Items here usually ask what a risk advisor or security leader should do, not how a tool works.

Ethics and core security concepts

Every CISSP is bound by the ISC2 Code of Ethics, whose four mandatory canons cover duties to society, to honest and legal conduct, to principals, and to the profession. The outline widens the classic confidentiality-integrity-availability triad to five pillars by adding authenticity and nonrepudiation. Expect scenarios that ask which property a control or a failure touches.

Four canons
Protect society, the common good, necessary public trust and confidence, and the infrastructure; act honorably, honestly, justly, responsibly and legally; provide diligent and competent service to principals; advance and protect the profession.
ISC2 Code of Ethics
Duty to report
Members who observe another member breaching the Code are obligated to follow the ethics complaint procedure; failing to do so may itself breach Canon IV.
ISC2 Code of Ethics
Standing to complain
Anyone may complain about Canons I or II, only principals (employer/contractor relationship) about Canon III, and only other ethics-bound professionals about Canon IV.
ISC2 Ethical Complaint Procedures
Nonrepudiation
A service that gives evidence of origin (or receipt) so a party cannot falsely deny having sent (or received) data.
RFC 4949 Internet Security Glossary

Governance, frameworks and the law

Security exists to support the mission, so governance starts from business objectives and risk tolerance, not from products. NIST CSF 2.0 made this explicit with a new Govern Function alongside Identify, Protect, Detect, Respond and Recover. The legal side spans cybercrime, intellectual property, import/export controls and privacy regimes such as the GDPR, which reach across borders.

Mission first
Understanding the organizational mission is the first Organizational Context outcome and informs cybersecurity risk management.
NIST CSF 2.0 GV.OC-01
GDPR breach notice
A controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless the breach is unlikely to result in a risk to individuals.
GDPR Art. 33(1)
Transborder transfers
A transfer to a country covered by a Commission adequacy decision needs no specific authorisation; otherwise safeguards such as standard clauses or binding corporate rules apply.
GDPR Art. 45–46
Idea versus expression
Copyright protects the expression of a work, never the underlying idea, procedure, process or method of operation.
17 U.S.C. §102(b)

Business continuity and personnel security

Business continuity requirements come from a business impact analysis that ranks processes, sets tolerances and exposes dependencies, including external suppliers. Personnel security covers the whole employment life cycle, from screening to termination, and extends to contractors and vendors through agreements.

MTD, RTO, RPO
MTD is how long a process can be disrupted before impact is unacceptable; RTO is how long a supporting system may be down; RPO is the point in time to which data must be recoverable.
NIST SP 800-34 Rev. 1 §3.2
External dependencies
The BIA should capture the suppliers and services a process relies on, because their recovery capability limits yours.
ISC2 CISSP Exam Outline 1.7
Termination
On termination, disable system access within a defined period, revoke credentials, conduct an exit interview and retrieve organizational property.
NIST SP 800-53 Rev. 5 PS-4
External personnel
Security requirements for contractors and service providers are established and documented, typically in contracts.
NIST SP 800-53 Rev. 5 PS-7

Risk management, threat modeling and supply chain

Risk management identifies threats and vulnerabilities, estimates likelihood and impact, and chooses a response within the organization's tolerance. Threat modeling applies the same thinking to a design before it is built. Supply chain risk management extends it to what you buy, using tools such as SBOMs and independent assessments.

Four responses
Organizations can accept, avoid, mitigate, or share/transfer risk, or combine them.
NIST SP 800-39 Task 3-1
Transfer is not reduction
Transferring risk (e.g., insurance) shifts liability but reduces neither the likelihood of harm nor its consequences.
NIST SP 800-39 Task 3-1
Accept within tolerance
Acceptance is appropriate when the risk is within organizational risk tolerance; avoidance when it exceeds tolerance and no practical safeguard exists.
NIST SP 800-39 Task 3-1
Model threats at design
Use threat modeling or attack-surface mapping during design to assess security risk in software.
NIST SP 800-218 PW.1.1
SBOM
A formal record of the components, and their supply chain relationships, used to build software.
NIST SP 800-161r1 glossary (from E.O. 14028)

Keep going: the full CISSP — Certified Information Systems Security Professional guide covers every section of the exam. CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Studying in order?

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.

Get the book — $24.99
Report