🇺🇸 Certified Information Systems Security Professional (CISSP) · subject
Certified Information Systems Security Professional (CISSP) Security and Risk Management Syllabus
Every chapter and topic of Security and Risk Management examined in Certified Information Systems Security Professional (CISSP) — 5 chapters, 17 topics and 57 sub-topics, plus 72 flashcards written against it.
Security and Risk Management syllabus — full chapter and topic list
Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Security and Risk Management in Certified Information Systems Security Professional (CISSP), not a summary of it.
-
Security Governance and Foundational Principles
3 topics- The CIA Triad and Supporting Concepts
- Confidentiality, integrity, and availability defined
- Authenticity, non-repudiation, and accountability
- The DAD triad and opposing threats
- Balancing security objectives against business needs
- Security Governance Principles
- Aligning security function to business strategy and goals
- Organizational roles: senior management, data owner, custodian, user
- Security control frameworks (COBIT, ISO/IEC 27001, NIST CSF)
- Due care versus due diligence
- Security Policies, Standards, Procedures, and Guidelines
- Hierarchy of governance documents
- Acceptable use and baselines
- Policy lifecycle and review cadence
- The CIA Triad and Supporting Concepts
-
Compliance, Legal, and Regulatory Requirements
4 topics- Legal Systems and Categories of Law
- Civil, criminal, and administrative law
- Common law versus civil law systems
- Liability and prudent person rule
- Intellectual Property and Cybercrime
- Patents, trademarks, copyrights, trade secrets
- Licensing models and software piracy
- Computer Fraud and Abuse Act and related statutes
- Privacy and Data Protection Regulations
- GDPR principles and cross-border transfers
- HIPAA, GLBA, and sector-specific U.S. laws
- PCI DSS contractual obligations
- Transborder data flow and data localization
- Investigations and Evidence
- Investigation types: criminal, civil, regulatory, administrative
- Chain of custody and evidence admissibility
- eDiscovery obligations
- Legal Systems and Categories of Law
-
Professional Ethics and Security Awareness
3 topics- ISC2 Code of Professional Ethics
- The four mandatory canons
- Order of precedence among canons
- Organizational code of ethics (RFC 1087)
- Security Awareness, Training, and Education
- Awareness vs training vs education distinctions
- Role-based training programs
- Measuring program effectiveness
- Social engineering and phishing simulations
- Personnel Security Policies
- Candidate screening, onboarding, and offboarding
- Employment agreements and NDAs
- Separation of duties and job rotation
- ISC2 Code of Professional Ethics
-
Risk Management Concepts
4 topics- Risk Identification and Analysis
- Assets, threats, vulnerabilities, and exposure
- Qualitative risk analysis
- Quantitative risk analysis: AV, EF, SLE, ARO, ALE
- Total cost of ownership and risk appetite
- Risk Treatment and Response
- Mitigation, transfer, acceptance, and avoidance
- Residual risk and risk tolerance
- Control selection and cost-benefit analysis
- Control Categories and Functions
- Administrative, technical, and physical controls
- Preventive, detective, corrective, deterrent, compensating
- Control assessment and continuous monitoring
- Threat Modeling and Supply Chain Risk
- STRIDE, PASTA, and DREAD methodologies
- Attack trees and reduction analysis
- Supply chain risk management and third-party assessments
- Minimum security and service-level requirements
- Risk Identification and Analysis
-
Business Continuity Planning
3 topics- Business Impact Analysis
- Identifying critical functions and dependencies
- RTO, RPO, MTD, and WRT metrics
- Impact valuation and prioritization
- Continuity Strategy and Governance
- Scope, project initiation, and management buy-in
- Roles, responsibilities, and resource planning
- Documentation and plan maintenance
- Continuity Testing and Validation
- Tabletop and walkthrough exercises
- Simulation and parallel testing
- Lessons learned and plan revision
- Business Impact Analysis
Security and Risk Management flashcards for Certified Information Systems Security Professional (CISSP)
19 of 72 cards from the Security and Risk Management deck — real questions with worked answers.
What are the three core components of the CIA Triad?
Confidentiality (preventing unauthorized disclosure), Integrity (preventing unauthorized or improper modification), and Availability (ensuring authorized access when needed).
Which CIA Triad concept is the opposite of confidentiality, integrity, and availability respectively (the DAD triad)?
Disclosure (opposes confidentiality), Alteration (opposes integrity), and Destruction/Denial (opposes availability).
Define the security concepts of authenticity and non-repudiation.
Authenticity verifies that data/communication is genuine and from the claimed source; non-repudiation ensures a party cannot deny having performed an action (e.g., sending a message or making a transaction).
What does the AAA model in security stand for?
Authentication, Authorization, and Accounting (sometimes Auditing) — verifying identity, granting appropriate access, and tracking actions.
What is the difference between a vulnerability, a threat, and a risk?
A vulnerability is a weakness; a threat is a potential danger that could exploit a vulnerability; risk is the likelihood and impact of a threat exploiting a vulnerability.
What is 'due care' versus 'due diligence' in security governance?
Due diligence is researching and understanding risks/obligations (knowing what to do); due care is acting prudently to address them (doing the right thing). Diligence = planning, care = action.
What is security governance and how does it differ from security management?
Security governance is the set of practices by which senior leadership directs and controls the organization's security to align with business goals; management executes the day-to-day operations within that governance framework.
Name the recommended order of priority among Top-down vs. Bottom-up security program approaches, and why.
Top-down is preferred: it is initiated and supported by senior management, ensuring proper authority, funding, and alignment. Bottom-up (IT-driven) often lacks executive support and strategic alignment.
Define the four document types in a security documentation hierarchy: policy, standard, procedure, and guideline.
Policy = high-level mandatory management intent; Standard = mandatory specific requirements (e.g., technologies/configs); Procedure = mandatory step-by-step instructions; Guideline = recommended, non-mandatory advice.
Which security documents are mandatory and which are discretionary: policies, standards, procedures, guidelines, baselines?
Mandatory: policies, standards, procedures, and baselines. Discretionary (recommended only): guidelines.
What is a security baseline?
A baseline is a mandatory minimum level of security/configuration that a system or component must meet (a uniform starting reference for protection).
Distinguish a regulatory policy, an advisory policy, and an informative policy.
Regulatory = required by law/regulation; Advisory = strongly recommended behaviors with consequences (most common org policies); Informative = provides knowledge/education only, no enforcement.
What are the four main categories/sources of law commonly compared in CISSP: criminal, civil, administrative, and which is based on judicial precedent?
Criminal law (crimes/punishment), Civil/tort law (disputes/damages), Administrative/regulatory law (agency rules), and Common law which is based on judicial precedent.
Compare the burden of proof in criminal vs. civil law.
Criminal: 'beyond a reasonable doubt' (highest standard). Civil: 'preponderance of the evidence' (more likely than not). Administrative: 'substantial evidence.'
What are the three main categories of intellectual property protection and what does each protect?
Patent (protects inventions, ~20 years), Trademark (protects brand identity/logos/names), and Copyright (protects original creative/authored works). Trade secrets protect confidential business info.
How long does copyright protection generally last in the U.S. for a work created by an individual?
The life of the author plus 70 years.
What protection covers a trade secret, and what is its key requirement?
A trade secret protects confidential proprietary business information (e.g., formulas, processes) and requires the owner to take reasonable steps to keep it secret; it has no expiration as long as secrecy is maintained.
What U.S. law addresses computer crime including unauthorized access to federal/protected computers?
The Computer Fraud and Abuse Act (CFAA).
What is the difference between licensing models: contractual, shrink-wrap, click-through, and cloud services (browse-wrap) agreements?
Contractual = signed written agreement; Shrink-wrap = terms accepted by opening packaging; Click-through (click-wrap) = accept by clicking during install; Browse-wrap = terms binding by using a website/service.
Planning Security and Risk Management for Certified Information Systems Security Professional (CISSP)
Security and Risk Management is about 17% of the Certified Information Systems Security Professional (CISSP) syllabus by topic count — 17 of 102 topics, spread over 5 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 25 hours.
The heaviest chapters are Compliance, Legal, and Regulatory Requirements (4 topics), Risk Management Concepts (4 topics), Security Governance and Foundational Principles (3 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.
Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.
Security and Risk Management (Certified Information Systems Security Professional (CISSP)) FAQ
What is in the Certified Information Systems Security Professional (CISSP) Security and Risk Management syllabus?
Security and Risk Management is split into 5 chapters — Security Governance and Foundational Principles, Compliance, Legal, and Regulatory Requirements, Professional Ethics and Security Awareness, Risk Management Concepts and Business Continuity Planning, containing 17 topics and 57 sub-topics in total.
How is Security and Risk Management structured in the Certified Information Systems Security Professional (CISSP) syllabus?
5 chapters. Security and Risk Management accounts for about 17% of the topics in the whole Certified Information Systems Security Professional (CISSP) syllabus (17 of 102).
How long should I spend on Security and Risk Management for Certified Information Systems Security Professional (CISSP)?
Budget around 25 hours for a first pass through Security and Risk Management — about 45 minutes per topic plus 12 minutes per sub-topic across its 17 topics. Add revision cycles on top.
Are there flashcards for Certified Information Systems Security Professional (CISSP) Security and Risk Management?
Yes — a 72-card Security and Risk Management deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.