CISSP Resources · Domain 1 — 16% of the exam
CISSP Domain 1 Guide: Security and Risk Management
Domain 1 is the largest domain at 16% and the lens through which every other domain is graded. If you learn nothing else properly, learn this: the CISSP wants risk-based, management-level answers, and Domain 1 is where that vocabulary is defined.
What Domain 1 covers
- Confidentiality, integrity and availability, and the trade-offs between them
- Security governance: strategy, policies, standards, procedures, guidelines and baselines
- Legal and regulatory systems, intellectual property, privacy and cross-border data transfer
- The ISC2 Code of Professional Ethics
- Risk management: identification, analysis, treatment, and monitoring
- Business continuity: business impact analysis, recovery objectives, and continuity strategy
- Personnel security, third-party risk, and security awareness training
Risk management: the maths you must know
| Term | Meaning | Formula |
|---|---|---|
| AV | Asset value | — |
| EF | Exposure factor — proportion of asset lost | — |
| SLE | Single loss expectancy | AV × EF |
| ARO | Annualised rate of occurrence | — |
| ALE | Annualised loss expectancy | SLE × ARO |
| Control value | Whether a control is worth buying | ALE before − ALE after − annual control cost |
If the control costs more than the risk it removes, the correct answer is not to buy it. That is the exam testing whether you think in business terms.
Risk treatment options
- Mitigate / reduce — apply a control.
- Transfer / share — insurance or contract. Note: you transfer financial impact, never accountability.
- Avoid — stop doing the activity.
- Accept — a formal decision by the risk owner, documented. Ignoring a risk is not acceptance.
Governance documents in order
| Document | Nature | Example |
|---|---|---|
| Policy | Mandatory, high level, states intent | 'All data must be classified.' |
| Standard | Mandatory, specific | 'Use AES-256 for data at rest.' |
| Procedure | Mandatory, step by step | 'How to encrypt a new database.' |
| Guideline | Discretionary, recommended | 'Consider quarterly key rotation.' |
| Baseline | Mandatory minimum configuration | 'Server hardening baseline.' |
Business continuity essentials
- BIA comes first. You cannot plan recovery before knowing what matters and how quickly it must return.
- RTO — how long a process can be down. RPO — how much data loss is acceptable. MTD — the maximum tolerable downtime; RTO must be shorter.
- Senior management support is the critical success factor for any BCP question.
Exam traps in Domain 1
- 'What should be done FIRST?' in a governance scenario is almost always obtain senior management support or perform a risk assessment.
- Insurance transfers impact, not responsibility. Accountability never leaves the organisation.
- Due care is doing the right thing; due diligence is investigating and continuing to verify.
- Qualitative analysis uses ratings and judgement; quantitative uses monetary values. Most real programmes use both.
- The ISC2 Code of Ethics canons apply in order — protect society first, act honourably second.
Study checklist
- Be able to calculate SLE, ARO and ALE without notes and decide whether a control is justified.
- Recite the four risk treatment options and what each means for accountability.
- Order the governance document hierarchy and give an example of each.
- Explain BIA, RTO, RPO and MTD and how they relate.
- List the four ethics canons in order.
Frequently asked questions
Why is Domain 1 the most important CISSP domain?
It is the largest at 16%, and its risk and governance vocabulary is used to judge the correct answer in every other domain.
Do I need to memorise risk formulas for the CISSP?
Yes — SLE = AV × EF and ALE = SLE × ARO come up regularly, usually to test whether a control is cost-justified.
Drill Domain 1 with scenario questions
Governance and risk questions on Domain Eight are written in the same best-answer style as the exam, with the managerial reasoning explained for every option.
Related guides
- Domain 2: Asset SecurityClassification, ownership roles, data lifecycle, retention and secure disposal.
- Domain 3: Security Architecture and EngineeringSecure design principles, models, cryptography, and physical security. The heaviest technical domain.
- Domain 4: Communication and Network SecurityOSI and TCP/IP, segmentation, secure protocols, wireless and remote access.
- Domain 5: Identity and Access ManagementIdentification, authentication, authorisation models, federation and provisioning lifecycle.
More CISSP study material from Domain Eight: browse all resources.
