Doc CC-06Rev 2026-10Class study materialRead ~8 min
CISSP Domain 1: Security and Risk Management (16%) — what’s tested and the traps
Domain 1 of the ISC2 CISSP (Certified Information Systems Security Professional) exam is Security and Risk Management: 16% of the current outline (effective April 2024), the heaviest of the eight domains. It tests judgment from a manager’s chair — ethics, governance, law, continuity, personnel and risk.
Exam readout
- Format
- CAT, every language
- Items
- 100–150
- Time
- 3 hours
- Pass mark
- 700 / 1000 scaled
- Outline
- 8 domains · Apr 2024
Domain 1 at a glance
Weight
16%
Largest slice of the outline; 15% in the 2021 version.
Point of view
Manager
Advise, align, escalate. Fix it yourself: rarely.
Arithmetic
Light
Two risk formulas and one downtime inequality. That is the whole budget.
Practice here
12 items
Every option explained.
What Domain 1 is really testing
Domain 1 reads like a governance syllabus, but the questions are not recall drills. An item hands you a scenario — a merger, a breach, a regulator, a vendor with a worrying contract — and asks what to do first or what is best. All four options will be defensible; the item writers are thorough like that.
The winning option is what a security advisor reporting to senior management would do. Management owns risk and is the only party that accepts it; the security function measures and recommends. Quietly accepting a risk on the company’s behalf, or patching before anyone with authority knows, is a distractor in a hero costume.
The mindset carries into the other seven domains, so Domain 1 belongs early in a study plan. The format itself lives on the CISSP exam page.
The order a Domain 1 answer usually follows
When two options both look right, rank them against this sequence. It breaks most ties.
Step 01
People’s safety
Human life before data, systems and schedules. An evacuation beats a backup every time.
Step 02
Law and the business mission
Legal and regulatory obligations, then the organization’s objectives.
Step 03
Policy and the risk owner
Check what policy says, then inform or escalate to the owner. Senior management makes the acceptance call.
Step 04
Analysis before action
Assess, run the business impact analysis, gather facts. Buying a tool before you know the risk is a favorite wrong answer.
Step 05
The technical control
The fix ranks last — not because it matters less, but because someone else has to approve it.
The Domain 1 map
| Ref | Topic | The question asks you to | The usual trap |
|---|---|---|---|
| R-01 | Professional ethics | Resolve a conflict with the ISC2 Code of Ethics | Treating the canons as equal — the earlier one wins |
| R-02 | Security concepts | Name the property a control protects: CIA, authenticity, non-repudiation | Confusing integrity with authenticity |
| R-03 | Governance and roles | Match a duty to management, owner, custodian or security | Letting the security team accept risk |
| R-04 | Due care and diligence | Label an activity as investigating or acting | Swapping the two |
| R-05 | Law, regulation, privacy | Recognize law types, IP protections, privacy roles, export rules | Calling a trade secret a patent |
| R-06 | Investigations | Pick the type and its standard of proof | The criminal standard for an internal policy breach |
| R-07 | Policy hierarchy | Place a document in the hierarchy | Reading a guideline as mandatory |
| R-08 | Business continuity | Run the BIA, derive RTO, RPO and MTD | Treating RPO as a downtime target |
| R-09 | Personnel security | Choose the hiring, transfer or termination control | Revoking access after the exit meeting |
| R-10 | Risk management | Calculate ALE, choose a response, classify a control | Weighing a safeguard against SLE, not ALE |
| R-11 | Threat modeling | Apply a method such as STRIDE | Modeling after deployment |
| R-12 | Supply chain risk | Assess a supplier, set contract requirements | Thinking outsourcing moves accountability |
| R-13 | Awareness and training | Tell awareness, training and education apart | Counting attendance as behavior change |
Due care vs due diligence
The pair the exam returns to most, worded least consistently across study sources. Pick one definition and hold it.
- Due diligence
- The knowing part: investigating, assessing and verifying — a supplier assessment, a risk analysis, an audit of a control. Mnemonic:
do detect
. - Due care
- The doing part: acting as a prudent person would by implementing and maintaining protections. Mnemonic:
do correct
.
The ISC2 Code of Ethics: four canons and a tie-breaker
Ethics items are short and unforgiving. The Code has a preamble and four canons, and the favorite move is a conflict between two of them. The canons carry an order of priority — when two pull apart, the earlier one decides:
- Protect society, the common good, public trust and the infrastructure.
- Act honorably, honestly, justly, responsibly and legally.
- Give diligent, competent service to principals — your employer or client.
- Advance and protect the profession.
A duty to the public outranks a duty to your employer, and the profession comes last. Read each scenario for whose interest is at stake: hiding a flaw to keep a client contract versus disclosing it to protect the public is not close under this ordering.
Policy, standard, baseline, procedure, guideline
| Document | Mandatory? | What it says | Example |
|---|---|---|---|
| Policy | Yes | Senior management’s intent, high level | Data at rest is encrypted |
| Standard | Yes | A specific, uniform requirement | AES with 256-bit keys on every laptop |
| Baseline | Yes | Minimum configuration for a system type | The hardened build every server starts from |
| Procedure | Yes | Step-by-step instructions | How to enroll a laptop in disk encryption |
| Guideline | No | Recommended practice | Suggested passphrase style |
Only the guideline is optional. The other four are requirements written at different altitudes.
Law, investigations and privacy
Domain 1 stays at manager level: which kind of law applies, who investigates, and how much proof each path needs. Nobody asks you to cite statutes.
Four investigation types
- Criminal — brought by the state; beyond a reasonable doubt.
- Civil — between parties, usually over money; preponderance of the evidence.
- Administrative — internal policy breaches; the lowest bar.
- Regulatory — the standard set by the regulator or industry rule.
Intellectual property and privacy
Copyright protects expression such as code, trademarks protect names and logos, patents protect inventions in exchange for public disclosure, and trade secrets stay valuable only while secret — file a patent on one and it stops being a secret. On privacy, expect GDPR roles (the controller decides why and how data is processed; the processor acts on its behalf), transborder data flow, licensing and export controls on cryptography. Data handling itself belongs to Domain 2.
The risk arithmetic
Quantitative risk analysis on the exam is multiplication with acronyms. Learn the names cold; the numbers tend to be friendly.
Single loss expectancy
SLE = AV × EFAsset value times exposure factor, the share one incident destroys.
Annualized loss expectancy
ALE = SLE × AROARO is the yearly rate: once in ten years is 0.1.
Safeguard value
ALE before − ALE after − annual safeguard costPositive means the control pays for itself. Forgetting the last term is the classic slip.
Downtime ceiling
MTD ≥ RTO + WRTRestore time plus work recovery time must fit inside maximum tolerable downtime.
Risk work beyond the arithmetic
A worked case: a warehouse system worth $400,000 loses 25% of its value in a flood, so SLE is $100,000. Floods come once in 20 years (ARO 0.05), so ALE is $5,000. A barrier cuts ARO to 0.01 and ALE to $1,000, but costs $6,000 a year: $5,000 − $1,000 − $6,000 = −$2,000. It loses money; pick another response.
Qualitative analysis ranks risks with ratings, scenarios and expert judgment; the Delphi technique keeps opinions anonymous so the most senior voice does not set the score. The exam usually asks which method a scenario describes.
Four responses and one non-answer
- Mitigate — controls that lower likelihood or impact.
- Transfer or share — insurance or contract moves the financial impact.
- Avoid — stop the risky activity.
- Accept — a documented management decision for residual risk within appetite.
Ignoring a risk is never on the list, however often it happens in practice.
Control types and categories
Types say what a control does: preventive, detective, corrective, deterrent, recovery, compensating, directive. Categories say what it is made of: administrative, technical or physical. A guard dog deters and detects at once. A compensating control stands in for one you cannot implement; a corrective control repairs damage after the event.
Business continuity: BIA, RTO, RPO, MTD
Continuity planning starts with the business impact analysis: critical processes, their dependencies, and how long each can be down before the damage is unacceptable. Every recovery number on the exam comes from the BIA, not from what IT thinks it can manage.
- MTD — the longest a process can be unavailable.
- RTO — the target time to restore the system.
- WRT — time to verify data and resume work once the system is back.
- RPO — tolerable data loss measured in time; it sets backup frequency, not downtime.
The BCP keeps critical business functions running and is strategic; the disaster recovery plan restores IT and facilities and is one tactical part of it. An option calling the DRP the broader plan is wrong. Recovery sites and DR tests belong to Domain 7 — the study guide maps where each topic sits.
Twelve Domain 1 scenarios
Original practice items for this domain, with a note on every option once you answer. They show where your reasoning holds; they do not estimate a score. Mixed domains are on the practice test.
Domain drill
Item 01 / 12
Answer, then read why each option is right or wrong. Keys 1–4 pick, N goes next.
A critical application experiences an outage once every five years. The typical disruption lasts for 4,320 minutes before services are restored. The business impact analysis determines that downtime costs $500 per hour. Management is evaluating several continuity strategies to improve resilience. Which strategy is financially justified?
Rationale
Pick an answer. The reasoning for every option lands here — including why the wrong ones looked right.
The smaller objectives that still cost points
Personnel security
Background checks before hiring, NDAs at onboarding, separation of duties, job rotation and mandatory vacation to surface fraud, and access removal at termination — while the exit interview is happening, not the following Monday. Contractors fall under the same controls through their contracts.
Threat modeling
STRIDE sorts threats into spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege; PASTA is a risk-centric process in seven stages. The exam tests timing: model threats at design, while changes are cheap.
Supply chain risk management
Suppliers extend your attack surface through tampered hardware, compromised updates and weak service providers. Expect assessment before signing, security requirements and audit rights in the contract, and monitoring afterwards. Third-party components return in Domain 3.
Awareness, training and education
Awareness changes attention, training builds a job skill, education builds understanding over a career. A sound program is role-based, refreshed on a schedule and measured by behavior, not by clicks on complete
.
Questions people ask
Q01What is Domain 1 of CISSP?
Security and Risk Management, the heaviest of the eight domains at 16% of the outline effective April 2024: ethics, security concepts, governance, law and privacy, investigations, policies, continuity, personnel, risk, threat modeling, supply chain and awareness. The authoritative list is the ISC2 exam outline.
Q02What is the difference between due care and due diligence?
Due diligence is investigating and verifying — assessments, audits, risk analysis. Due care is acting on it as a prudent person would — implementing and maintaining controls. Diligence finds out; care follows through.
Q03How many Domain 1 questions are on the CISSP exam?
ISC2 publishes weights, not a per-domain count. The adaptive exam runs 100–150 items, so the number varies; 16% means Domain 1 is the largest share on average.
Q04Does Domain 1 overlap with CISM?
In governance and risk, yes. CISM goes deeper on security management; CISSP adds seven more domains. See CISSP vs CISM.
Debrief · key takeaways
- Domain 1 is 16% of the current outline, the largest single domain.
- Answer from the advisor’s chair; the technical fix comes last.
- Due diligence investigates; due care implements.
- Only the guideline is optional in the policy hierarchy.
- ALE = SLE × ARO; a safeguard must cut ALE by more than it costs per year.
- RPO drives backup frequency; RTO plus WRT must fit inside MTD.
Where to go next
Field kit
Take the Domain 1 scenarios with you
More practice by domain on your phone, with the reasoning behind every option.