Đội ngũ PrepPass · Đối chiếu với ISC2's CISSP Certification Exam Outline (effective 15 April 2024), with NIST, IETF and U.S. federal primary sources · Quy trình kiểm tra
ĐỌC THỬ MIỄN PHÍ · ĐỌC TRỰC TUYẾNChương 1

Security and Risk Management

Đây là Chương 1 của CISSP Study Guide — 2026 Edition — trọn vẹn một chương, đọc miễn phí ngay tại đây; không cần tải, không cần email. Cùng nội dung với eBook. Khi đọc đến cuối, trọn bộ hướng dẫn chỉ cách một cú nhấp.

Domain 1 carries the heaviest weight on the exam at 16%[1], and it sets the tone for everything after it: governance before technology, risk before controls, and the manager's view before the technician's. Read it as the person who will have to defend the program to executives, auditors, and regulators.

1.1 Professional ethics

ISC2's Code of Ethics has four mandatory canons: protect society, the common good, public trust, and the infrastructure[2]; act honorably, honestly, justly, responsibly, and legally[2]; provide diligent and competent service to principals[2]; and advance and protect the profession[2]. On the exam, when an ethics scenario pits loyalty to an employer against one of these duties, the canons outrank the employer's instructions — the first canon, protecting society, outranks them all.

1.2 Security concepts

The CIA triad — confidentiality, integrity, availability — is the vocabulary of the whole field, and FIPS 199 states the three objectives in the words of federal law: confidentiality means "preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information"; integrity means "guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity"; and availability means "ensuring timely and reliable access to and use of information"[3, 4]. Related concepts the outline names here include threats, vulnerabilities, and risk: NIST defines risk as a function of the adverse impacts of an event and the likelihood it occurs[5]. Controls are the safeguards you select against that risk, and they come in families — NIST organizes its controls into 20 families[6].

1.3 Security governance principles

Governance is the system by which the organization's security is directed and controlled. NIST's Cybersecurity Framework puts a GOVERN function at the center: the organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored[7]. In practice this means policies (management's high-level intent), standards (mandatory rules), procedures (step-by-step instructions), and guidelines (recommended practices) — and a board and executive team that own risk rather than delegating it away.

1.4 Legal, regulatory, and compliance issues

Several regimes appear repeatedly. The EU General Data Protection Regulation requires breach notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of a personal data breach[8], and its top tier of administrative fines reaches 20 million euros or 4% of worldwide annual turnover, whichever is higher[8]. In U.S. health care, the HIPAA Security Rule sets forth the administrative, physical, and technical safeguards that covered entities and business associates must put in place to secure electronic protected health information[9]. For payment cards, PCI DSS provides a baseline of technical and operational requirements designed to protect payment account data[10], applying to entities that store, process, or transmit cardholder data[10]. For software, copyright subsists in original works of authorship fixed in any tangible medium of expression[11], while fair use — for purposes such as criticism, comment, news reporting, teaching, scholarship, or research — is not infringement[12], judged on four factors including the purpose and character of the use and its effect on the market[12].

1.5 Investigation types

Administrative investigations address policy violations and support HR action; criminal investigations support prosecution and demand the strictest evidence handling; civil investigations support lawsuits between parties. The key exam distinction is the standard of handling: criminal matters require preserving chain of custody and involving law enforcement, because mishandled evidence is inadmissible. Never let an internal investigation contaminate a potential criminal case.

1.6 Security policy, standards, procedures, and guidelines

Policy states management's intent and assigns responsibility; standards set the mandatory rules that implement policy; procedures give the step-by-step instructions; guidelines offer recommended practices for situations where judgment applies. NIST's contingency planning guidance makes the same point about authority: a formal policy provides the authority and guidance necessary to develop an effective plan[13]. Write policies short, get executive sign-off, and review them on a schedule — an unsigned, unreviewed policy is decoration.

1.7 Business continuity requirements

Business continuity is about keeping the mission alive through disruption. The analysis that drives it is the business impact analysis: the BIA helps identify and prioritize information systems and components critical to supporting the organization's mission and business processes[13]. From the BIA come the recovery targets — how long you can be down and how much data you can afford to lose — and the strategies to meet them. Continuity planning starts with policy and the BIA before any technology is chosen.

1.8 Personnel security policies and procedures

People are part of the control set: background checks before hiring, least privilege from day one, mandatory vacations and job rotation to expose fraud, and a termination procedure that revokes access the same day. Personnel controls also include nondisclosure and noncompete agreements where lawful. The exam treats separation of duties and least privilege as personnel controls first and technical controls second.

1.9 Risk management concepts

Risk management is a cycle: assess, treat, monitor. NIST defines risk assessment as the process of identifying, estimating, and prioritizing information security risks[5], and risk itself as a function of adverse impact and likelihood[5]. Treatment options are the classic four: avoid, transfer, mitigate, or accept the risk. The Risk Management Framework gives this a formal seven-step shape — a preparatory step plus six main steps, all essential[14] — beginning with preparing to execute the RMF by establishing context and priorities[14] and categorizing each system based on the impact of loss[14]. Senior management formally accepts the leftover risk; that acceptance is what makes the program legitimate.

1.10 Threat modeling concepts and methodologies

Threat modeling is structured brainstorming about what can go wrong, done early enough to influence design. Methodologies decompose the system (data flows, trust boundaries, entry points), enumerate threats against each element, and rank them so design effort goes to the worst first. The output feeds directly into control selection: you don't buy controls and then look for threats, you model threats and then select controls.

1.11 Supply chain risk management

Modern systems are assembled from other people's components, so the supply chain is part of your attack surface. SCRM means vetting suppliers, demanding evidence of their secure development practices — NIST's SSDF gives acquirers a common vocabulary for exactly these conversations with suppliers[15] — and planning for supplier failure or compromise. Counterfeit components, tampered updates, and a vendor's breach becoming your breach are the scenarios to plan for.

1.12 Security awareness, education, and training

Awareness changes behavior across the whole workforce; education builds deeper understanding for those who need it; training builds job-specific skill. The program must be established and maintained — one annual slide deck is not a program — with role-based training for privileged users and developers, and metrics (such as phishing-simulation click rates) that show whether behavior is actually changing.

Key numbers

  • Exam: 3 hours, 100–150 items, pass at 700/1000[1]
  • Breach notification under GDPR: 72 hours to the supervisory authority[8]
  • Top GDPR fines: 20 million euros or 4% of worldwide annual turnover[8]
  • RMF: seven steps (one preparatory plus six main)[14]
  • NIST controls: 20 families[6]

Key takeaways

  • Domain 1 is the manager's domain: governance, risk, law, and ethics before technology.
  • The four ethics canons outrank any employer's instruction; protecting society comes first.
  • Risk is impact times likelihood; assessment identifies, estimates, and prioritizes.
  • The BIA identifies and prioritizes what the mission cannot lose, and it comes before recovery strategies.
  • When in doubt on the exam, choose the answer that manages risk at the program level rather than fixing one technical symptom.

Chapter 1 quiz — 16 questions

Answer each question, then check the key that follows.

1. A security manager discovers the company is quietly selling customer location data in a way that endangers domestic-violence victims. The CEO orders the manager to stay silent. What should guide the manager's decision first?

  • A. The duty to protect society and the common good
  • B. The manager's personal employment contract terms
  • C. The company's public privacy policy statements
  • D. The CEO's direct order, as the highest internal authority

2. Which definition best matches how NIST describes information security risk?

  • A. The difference between threats and vulnerabilities
  • B. A function of adverse impacts and likelihood of occurrence
  • C. The number of vulnerabilities found in the last assessment
  • D. The annual cost of all security controls in the program

3. The board asks what governance of cybersecurity actually requires of them. Which answer is most accurate?

  • A. Setting and monitoring risk strategy and policy
  • B. Reviewing penetration test reports line by line
  • C. Approving every firewall rule change personally
  • D. Delegating all security decisions to the IT department

4. A company discovers a breach of EU residents' personal data on Monday morning. By when must it notify the supervisory authority, where feasible?

  • A. Within 30 days of completing the investigation
  • B. Only after notifying affected individuals first
  • C. Within 24 hours of discovery
  • D. Within 72 hours of becoming aware

5. Under the GDPR's highest tier, administrative fines can reach which maximum?

  • A. 10 million euros or 2% of worldwide annual turnover
  • B. 1 million euros or 1% of worldwide annual turnover
  • C. 20 million euros or 4% of turnover
  • D. 50 million euros with no turnover alternative

6. A U.S. hospital is documenting its safeguards for patient records systems. Which rule's framework of administrative, physical, and technical safeguards applies?

  • A. The GDPR's data protection principles
  • B. The FedRAMP authorization baseline
  • C. The PCI Data Security Standard
  • D. The HIPAA Security Rule

7. A retailer that stores and processes payment card numbers wants the baseline of technical and operational requirements for protecting that data. Which standard provides it?

  • A. The CISSP exam outline
  • B. PCI DSS
  • C. NIST SP 800-53
  • D. ISO/IEC 27001

8. A developer copies a competitor's proprietary program into a new product. Under U.S. copyright law, what determines whether the program is protected?

  • A. Whether the program was registered before publication
  • B. Whether the program contains more than 1,000 lines of code
  • C. Whether it is an original work in a tangible medium
  • D. Whether the competitor sells the program commercially

9. A trainer wants to quote short passages of a copyrighted article in a security awareness course. Which factor is part of the fair-use analysis?

  • A. The number of students enrolled in the course
  • B. The trainer's job title and seniority
  • C. Effect on the work's potential market
  • D. Whether the article was published in the last year

10. An employee is suspected of stealing trade secrets, and prosecution is possible. What is the most important handling requirement for the evidence?

  • A. Preserving chain of custody so the evidence stays admissible
  • B. Confronting the employee immediately to get a confession
  • C. Deleting the employee's accounts before collecting anything
  • D. Publishing findings internally as a deterrent

11. Which document should state management's high-level intent for information security and assign responsibility for it?

  • A. A guideline
  • B. A procedure
  • C. A standard
  • D. A policy

12. Before buying backup infrastructure, a company wants to know which systems the mission cannot survive without and for how long each can be down. What should it conduct first?

  • A. A vulnerability scan of the data center
  • B. A business impact analysis
  • C. A penetration test of the backup systems
  • D. A code review of the recovery scripts

13. According to NIST, risk assessment is best described as which activity?

  • A. Installing controls to reduce all risks to zero
  • B. Identifying, estimating, and prioritizing information security risks
  • C. Documenting accepted risks for the auditors
  • D. Transferring risk to an insurance provider

14. An organization adopts the NIST Risk Management Framework. How many steps does it include?

  • A. Seven steps: a preparatory step plus six main steps
  • B. Four steps, one per risk treatment option
  • C. Twelve steps, one per control family
  • D. Five steps matching the CSF functions

15. A company buys most of its product's components from outside vendors. Which practice best addresses the resulting supply chain risk?

  • A. Buying only from the lowest-cost supplier in each category
  • B. Testing finished products once a year for defects
  • C. Keeping the supplier list secret from internal auditors
  • D. Requiring vendors to demonstrate secure development practices during acquisition

16. A phishing simulation shows 30% of staff clicking malicious links. What does a mature awareness program do next?

  • A. Block all external email to eliminate the threat
  • B. Punish the staff who clicked with formal warnings
  • C. Treat it as a metric and deliver targeted training
  • D. Run the same simulation monthly without any training

Answer key & explanations

1. A. The first canon requires protecting society, the common good, public trust, and the infrastructure[2] — that duty is what the manager's decision must serve first. The remaining canons then require acting honorably, honestly, justly, responsibly, and legally[2], providing diligent and competent service to principals[2], and advancing and protecting the profession itself[2].

2. B. NIST defines risk as a measure of the extent to which an entity is threatened by a potential circumstance or event, typically a function of the adverse impacts that would arise and the likelihood of occurrence[5]. Cost of controls, vulnerability counts, and threat-vulnerability arithmetic are not the definition. Risk assessment is the separate process of identifying, estimating, and prioritizing information security risks[5] — the mechanism that produces the likelihood-and-impact judgments the definition calls for.

3. A. The GOVERN function is defined as establishing, communicating, and monitoring the organization's cybersecurity risk management strategy, expectations, and policy[7]. Boards govern through strategy and oversight, not by approving individual technical changes or reviewing raw test output. The CSF organizes all cybersecurity outcomes at their highest level into six Core Functions — GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER[7] — with GOVERN setting the strategy that the other five execute.

4. D. GDPR Article 33 requires notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach[8]. Waiting for the investigation to finish or notifying individuals first does not satisfy the deadline. Breaches at this scale also expose the company to the top fine tier — up to 20 million euros or 4% of worldwide annual turnover[8] — which is why the clock starts at awareness, not at the end of the investigation.

5. C. The top tier of GDPR administrative fines is up to 20 million euros or, for an undertaking, up to 4% of total worldwide annual turnover of the preceding financial year, whichever is higher[8]. The lower 10 million / 2% tier applies to a different set of infringements. The same regulation separately imposes the 72-hour breach notification duty[8], framing all of this as protecting a fundamental right — the protection of natural persons in relation to the processing of personal data[8].

6. D. The HIPAA Security Rule sets forth the administrative, physical, and technical safeguards that covered entities and business associates must put in place to secure electronic protected health information[9]. PCI DSS covers payment cards, not patient records. The rule's protected object is electronic protected health information — PHI maintained in or transmitted by electronic media[9] — so the first scoping question is always whether the system handles ePHI at all.

7. B. PCI DSS provides a baseline of technical and operational requirements designed to protect payment account data[10], and its intended audience is entities that store, process, or transmit cardholder data[10]. ISO 27001 and SP 800-53 are general control frameworks, not the card-data baseline. The distractors name real frameworks, but neither is scoped to cardholder data: ISO 27001 is a general ISMS standard and SP 800-53 a federal control catalog, while PCI DSS exists specifically for the payment-card baseline.

8. C. Copyright protection subsists in original works of authorship fixed in any tangible medium of expression[11]. Registration, length, and commercial sale are not the test for whether protection exists. The owner's exclusive rights include reproduction of the work[16], so copying the program infringes regardless of registration; fair use remains only a limited defense, judged by factors including the purpose and character of the use[12].

9. C. The four fair-use factors include the effect of the use upon the potential market for or value of the work, alongside the purpose and character of the use, the nature of the work, and the amount used[12]. Job title, publication recency, and class size are not factors. Protection itself subsists in original works fixed in a tangible medium[11], and the owner's exclusive rights include reproduction[16] — fair use is the limited exception to those rights, not the default.

10. A. Criminal investigations support prosecution, so evidence must survive legal challenge: NIST's incident handling guidance says evidence should be accounted for at all times, with chain of custody forms detailing every transfer[17]. Confronting the suspect, deleting accounts, or publicizing findings all risk contaminating the case the prosecution depends on. The response lifecycle itself runs preparation, detection and analysis, containment, eradication and recovery, and post-incident activity[17] — evidence discipline sits inside that structure, which is why improvising outside it destroys the case.

11. D. A security policy is "a definite goal, course, or method of action to guide and determine present and future decisions concerning security in a system"[18] — management's high-level intent, which is why it is the document that assigns responsibility. A standard is the tempting wrong answer: it sets mandatory specifics (an approved algorithm, a baseline) that implement the policy, not the intent itself. Procedures give the steps and guidelines advise; NIST's contingency guidance makes the same point about authority, noting that a formal policy "provides the authority and guidance" for the plans beneath it[13].

Sources cited in this excerpt

  1. ISC2 CISSP Certification Exam Outline. https://www.isc2.org/certifications/cissp
  2. ISC2 Code of Ethics. https://www.isc2.org/ethics
  3. FIPS 199, Standards for Security Categorization of Federal Information and Information Systems. NIST. https://csrc.nist.gov/pubs/fips/199/final
  4. FIPS 199, Standards for Security Categorization of Federal Information and Information Systems. NIST. https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf
  5. NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments. https://csrc.nist.gov/pubs/sp/800/30/r1/final
  6. NIST SP 800-53 Rev. 5, Security and Privacy Controls. https://csrc.nist.gov/pubs/sp/800/53/r5/final
  7. NIST Cybersecurity Framework (CSF) 2.0. https://www.nist.gov/cyberframework
  8. Regulation (EU) 2016/679 (GDPR), official text, EUR-Lex. Publications Office of the European Union. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
  9. 45 CFR Part 164, Subpart C — Security Standards for the Protection of Electronic Protected Health Information (eCFR). U.S. HHS / eCFR. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C
  10. PCI Security Standards Council — PCI DSS. https://www.pcisecuritystandards.org/standards/pci-dss/
  11. 17 U.S.C. § 102, U.S. Copyright Office, Title 17 Chapter 1. https://www.copyright.gov/title17/92chap1.html
  12. 17 U.S.C. § 107, U.S. Copyright Office, Title 17 Chapter 1. https://www.copyright.gov/title17/92chap1.html
  13. NIST SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems. https://csrc.nist.gov/pubs/sp/800/34/r1/final
  14. NIST SP 800-37 Rev. 2, Risk Management Framework. https://csrc.nist.gov/pubs/sp/800/37/r2/final
  15. NIST SP 800-218, Secure Software Development Framework (SSDF). https://csrc.nist.gov/pubs/sp/800/218/final
  16. 17 U.S.C. § 106, Exclusive rights in copyrighted works. https://www.copyright.gov/title17/92chap1.html
  17. NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide. https://csrc.nist.gov/pubs/sp/800/61/r2/final
  18. RFC 4949, Internet Security Glossary, Version 2. Internet Engineering Task Force (IETF), 2007-08. https://www.rfc-editor.org/rfc/rfc4949.txt
Bạn đã đọc xong chương miễn phí

Nhận trọn bộ hướng dẫn

Đó là Chương 1 trong 8 chương — trọn vẹn một chương, đúng như bản chính thức. Các chương còn lại cũng sâu như vậy qua mọi phần của kỳ thi, kèm câu hỏi luyện tập có giải thích — ở dạng PDF và EPUB gọn gàng bạn giữ mãi mãi.

Cùng một kỳ thi, chỉ một phần nhỏ chi phí
$3,695–$4,399→$24.99

Một CISSP boot camp có giá $3,695–$4,399. Cuốn sách này dạy cùng một kỳ thi — với độ sâu bạn vừa đọc — chỉ với $24.99 trả một lần, thuộc về bạn trọn đời.

  • Eight chapters, one per domain of the ISC2 CISSP outline (effective 15 April 2024)
  • A quiz closing each chapter, with worked explanations
  • A 150-question practice exam at the published domain weights
  • 250 original questions, each explained and cited to its source
  • Sourced from NIST FIPS and SP publications, IETF RFCs and the ISC2 Code
  • PDF + EPUB you keep

Sở hữu trọn cuốn sách — PDF + EPUB

Câu hỏi luyện tập và thi thử tính giờ vẫn miễn phí. Cuốn sách là nửa "học":

  • Dạy theo từng chương — mọi phần thi được giảng theo trình tự, không chỉ là câu hỏi
  • In ra & dán tab — một tài liệu giấy để tô đậm và ghi chú
  • Dùng ngoại tuyến — PDF để in, EPUB cho điện thoại hoặc máy đọc sách
  • Tất cả trong một tệp — mọi chương ở cùng một chỗ, tìm kiếm và in được

Sách này được viết bằng tiếng Anh — tệp PDF và EPUB bạn tải về đều bằng tiếng Anh.

$24.99trả một lần · tải trọn đời · không thuê bao

Đảm bảo hoàn tiền trong 14 ngày — không hài lòng? Email cho chúng tôi để được hoàn tiền đầy đủ, không cần lý do. Chính sách hoàn tiền

Có một chương đọc thử miễn phí trên trang này — đọc trước khi mua. Một lần trả mở khóa trọn cuốn sách dưới dạng PDF + EPUB bạn giữ mãi.

Trả một lần $24.99 · PDF + EPUB · của bạn mãi mãi · xem toàn bộ nội dung.

Đọc thử miễn phí — trọn vẹn một chương của bộ hướng dẫn ôn CISSP — Certified Information Systems Security Professional. Bản tóm tắt mang tính giáo dục, không phải tư vấn chuyên môn hay pháp lý — luôn xác nhận quy định hiện hành với nguồn chính thức. Cập nhật lần cuối: August 2026.

Báo lỗi