title: "CISSP Decision Cheat Sheet" summary: "A compact management-oriented framework for risk, assets, architecture, networking, identity, testing, operations, and software security decisions."
CISSP decision sequence
- Read the role, authority, scope, and “first/best/most” qualifier.
- Protect life safety and comply with mandatory legal or contractual duties.
- Identify the business, asset, data, risk, and process owner.
- Prefer policy, assessment, authorization, and evidence before unauthorized implementation.
- Choose the action that addresses the complete risk with appropriate governance.
- Preserve evidence, reversibility, communication, continuity, and follow-up.
- Reject technically attractive answers that are premature or outside the role.
The current live ISC2 page states 100–150 items, while its linked April 2024 outline PDF states 125–150. Keep that discrepancy visible. Baitaphish practice is fixed-length and non-adaptive; raw percentages do not reproduce ISC2 CAT selection or scaled scoring.
Use each matrix from the need or condition column. Explain the owner and evidence for every choice. If the answer contains only a technology and no governance, lifecycle, or validation, it is probably incomplete.