CISSP Resources · Domain 1 — 16% of the exam

CISSP Domain 1 Guide: Security and Risk Management

Domain 1 is the largest domain at 16% and the lens through which every other domain is graded. If you learn nothing else properly, learn this: the CISSP wants risk-based, management-level answers, and Domain 1 is where that vocabulary is defined.

What Domain 1 covers

  • Confidentiality, integrity and availability, and the trade-offs between them
  • Security governance: strategy, policies, standards, procedures, guidelines and baselines
  • Legal and regulatory systems, intellectual property, privacy and cross-border data transfer
  • The ISC2 Code of Professional Ethics
  • Risk management: identification, analysis, treatment, and monitoring
  • Business continuity: business impact analysis, recovery objectives, and continuity strategy
  • Personnel security, third-party risk, and security awareness training

Risk management: the maths you must know

TermMeaningFormula
AVAsset value
EFExposure factor — proportion of asset lost
SLESingle loss expectancyAV × EF
AROAnnualised rate of occurrence
ALEAnnualised loss expectancySLE × ARO
Control valueWhether a control is worth buyingALE before − ALE after − annual control cost

If the control costs more than the risk it removes, the correct answer is not to buy it. That is the exam testing whether you think in business terms.

Risk treatment options

  • Mitigate / reduce — apply a control.
  • Transfer / share — insurance or contract. Note: you transfer financial impact, never accountability.
  • Avoid — stop doing the activity.
  • Accept — a formal decision by the risk owner, documented. Ignoring a risk is not acceptance.

Governance documents in order

DocumentNatureExample
PolicyMandatory, high level, states intent'All data must be classified.'
StandardMandatory, specific'Use AES-256 for data at rest.'
ProcedureMandatory, step by step'How to encrypt a new database.'
GuidelineDiscretionary, recommended'Consider quarterly key rotation.'
BaselineMandatory minimum configuration'Server hardening baseline.'

Business continuity essentials

  • BIA comes first. You cannot plan recovery before knowing what matters and how quickly it must return.
  • RTO — how long a process can be down. RPO — how much data loss is acceptable. MTD — the maximum tolerable downtime; RTO must be shorter.
  • Senior management support is the critical success factor for any BCP question.

Exam traps in Domain 1

  • 'What should be done FIRST?' in a governance scenario is almost always obtain senior management support or perform a risk assessment.
  • Insurance transfers impact, not responsibility. Accountability never leaves the organisation.
  • Due care is doing the right thing; due diligence is investigating and continuing to verify.
  • Qualitative analysis uses ratings and judgement; quantitative uses monetary values. Most real programmes use both.
  • The ISC2 Code of Ethics canons apply in order — protect society first, act honourably second.

Study checklist

  1. Be able to calculate SLE, ARO and ALE without notes and decide whether a control is justified.
  2. Recite the four risk treatment options and what each means for accountability.
  3. Order the governance document hierarchy and give an example of each.
  4. Explain BIA, RTO, RPO and MTD and how they relate.
  5. List the four ethics canons in order.

Frequently asked questions

Why is Domain 1 the most important CISSP domain?

It is the largest at 16%, and its risk and governance vocabulary is used to judge the correct answer in every other domain.

Do I need to memorise risk formulas for the CISSP?

Yes — SLE = AV × EF and ALE = SLE × ARO come up regularly, usually to test whether a control is cost-justified.

Drill Domain 1 with scenario questions

Governance and risk questions on Domain Eight are written in the same best-answer style as the exam, with the managerial reasoning explained for every option.

Related guides

More CISSP study material from Domain Eight: browse all resources.