by MTC Group, LLC
CISSP D1: Security and Risk Management
Domain 1 carries the highest weight on the CISSP exam (16%). It covers the governance, legal, and risk-management foundation that every other domain sits on top of: confidentiality/integrity/availability, security governance principles, compliance and legal/regulatory requirements, professional ethics, business continuity concepts, personnel security policies, and risk management.
Because it's foundational rather than technical, in our view this domain is deceptively hard to study for. A useful habit is to practice judgment calls ("what should the CISO do first") instead of only memorizing terms: in our experience, candidates who treat it as a vocabulary list tend to underperform relative to candidates who understand the reasoning behind each framework.
CIA Triad
Confidentiality, Integrity, Availability: the three security objectives FISMA defines for information and information systems. A loss of each is, in turn, unauthorized disclosure, unauthorized modification or destruction, and disruption of access to or use of information. Practice deciding which property a scenario puts most at risk, not just defining the terms.
Due care vs. due diligence
Due care is the level of care expected from a reasonable person of similar competency under similar conditions (how you act). Due diligence is performing the prudent, responsible, and necessary actions to conduct a thorough and objective investigation, review, or analysis (how you find out before and while you act).
Risk management lifecycle
NIST SP 800-39 describes four components: frame, assess, respond, and monitor. Responses are acceptance, avoidance, mitigation, sharing, or transfer (or a combination). Know that risk can never be completely eliminated, only reduced to a residual level that falls within the organization's risk tolerance.
Quantitative vs. qualitative risk analysis
Quantitative assessments use numbers and most effectively support cost-benefit analysis of alternative risk responses; qualitative assessments use nonnumerical categories or levels (very low to very high). Quantitative impact can be expressed as the loss for each occurrence (single loss expectancy, SLE) or as the total loss over an annual period (annualized loss expectancy, ALE). Frequency matters: a moderate-impact event that occurs weekly may, over time, represent a higher risk than a major event that occurs infrequently.
Security governance frameworks
COBIT, ISO/IEC 27001, and NIST CSF: know what each is for, not just that they exist. COBIT is a framework for the governance and management of enterprise information and technology; ISO/IEC 27001 specifies the requirements for an information security management system (ISMS), the standard organizations claim conformity to; NIST CSF 2.0 is guidance for managing cybersecurity risks.
Third-party governance
SLAs, a risk assessment before acquiring or outsourcing security services, and ongoing monitoring of the provider's control compliance: the responsibility for managing risks from using external system services remains with the organization's authorizing officials. SLAs define expected control performance, measurable outcomes, and remedies for noncompliance.
Policy vs. standard vs. procedure vs. guideline
Policy is written at a broad level. Standards specify uniform use of specific technologies, parameters, or procedures and are normally compulsory. Procedures are the detailed steps to accomplish a particular task. Guidelines help ensure specific measures are not overlooked, and they can be implemented, correctly, in more than one way. Practice ordering them from most general (policy) to most specific (procedure).
Risk acceptance vs. risk transference
Accepting risk is the appropriate response when the risk is within the organization's risk tolerance: no further action is taken to reduce it, though it is still monitored like any other risk. Transferring risk (e.g., insurance) shifts responsibility or liability to another party, but it reduces neither the likelihood of the harmful event nor its operational consequences.
Due care vs. due professional care vs. due diligence
They sound alike but mean different things: due care is the level of care expected from a reasonable person of similar competency under similar conditions; due professional care is the diligence a person with a special skill would exercise under a given set of circumstances; due diligence is performing the actions regarded as prudent, responsible, and necessary to conduct a thorough and objective investigation, review, or analysis.
- [1]
- [2]
- [3]
- [4]
- [5]
- [6]
- [7]
- [8]
- [9]
- [10]
- [11]
- [12]
- [13]
- [14]
- [15]
- [16]
- [17]
Practice D1 questions with instant feedback, free to start, no card required.
Start Free© 2026 MTC Group, LLC. All rights reserved. InfoSec ExamPrep™ and the InfoSec ExamPrep logo are trademarks of MTC Group, LLC.
For personal exam preparation only. Printed from examprep.mtcgroupllc.com.