CISSP · D7 · 13%

Security Operations

Operate investigations, monitoring, configuration, change, incidents, vulnerability management, recovery, continuity, physical security, and personnel safety.

Provider facts checked 2026-08-03

Objective coverage

Objective 7.1 · high

Investigations

Support evidence collection, handling, reporting, forensics, eDiscovery, and investigation requirements with appropriate authority.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s08
Objective 7.2 · high

Logging and monitoring

Design and operate logging, event management, threat intelligence, behavior analytics, ingress/egress monitoring, and continuous control monitoring.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s08
Objective 7.3 · normal

Configuration management

Establish baselines, inventories, hardening, versioning, drift control, approved exceptions, and configuration evidence.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s08
Objective 7.4 · foundation

Security operations concepts

Apply need-to-know, least privilege, separation, job rotation, service levels, privileged operations, and resource lifecycle controls.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s08
Objective 7.5 · normal

Resource protection

Protect media, systems, facilities, data, keys, credentials, hardware, and operational resources through their lifecycle.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s08
Objective 7.6 · high

Incident management

Prepare, detect, respond, mitigate, report, recover, remediate, learn, and coordinate communications for incidents.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s08
Objective 7.7 · normal

Detective and preventive measures

Operate firewalls, intrusion systems, whitelisting/blacklisting, sandboxing, antimalware, machine learning, and related controls.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s08
Objective 7.8 · high

Patch and vulnerability management

Discover, assess, prioritize, test, remediate, verify, accept, and monitor vulnerabilities and patches based on risk.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s08
Objective 7.9 · high

Change management

Assess, authorize, test, schedule, communicate, implement, validate, document, and roll back operational changes.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s08
Objective 7.10 · high

Recovery strategies

Select alternate sites, backups, resilience, restoration, communications, suppliers, and recovery approaches from business requirements.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s09
Objective 7.11 · high

Disaster recovery processes

Execute response, personnel, communications, assessment, restoration, salvage, failback, and return-to-normal activities.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s09
Objective 7.12 · high

Disaster recovery testing

Use tabletop, walkthrough, simulation, parallel, and full-interruption methods with safe objectives and corrective action.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s09
Objective 7.13 · high

Business continuity planning and exercises

Maintain business continuity plans, dependencies, alternate processes, communication, exercises, measures, and improvement.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s02
Objective 7.14 · normal

Physical security

Operate facility access, monitoring, environmental, visitor, asset, restricted-area, and emergency physical controls.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s09
Objective 7.15 · high

Personnel safety

Protect people through travel, lone-worker, duress, emergency, evacuation, communications, and safety procedures.

Lesson
d7-lesson
Practice pool
d7-questions
Application
cissp-s09

Decision frame

Operations turns policy and architecture into controlled daily behavior. The senior-practitioner mindset is authority and safety first, preserve evidence, stabilize business impact, use reversible action, restore trusted operation, then remove root cause and improve.

Operational controls need owners, runbooks, service objectives, access, tools, evidence, exceptions, exercises, and feedback. A control that is configured but not monitored, tested, or maintained will decay.

Objective map

ObjectivesDecision focus
7.1–7.2 Investigations, logging, and monitoringCollect and protect evidence under appropriate authority; turn logs, intelligence, analytics, and monitoring into owned decisions
7.3–7.5 Configuration, operations concepts, resource protectionMaintain inventories, baselines, least privilege, separation, service levels, and lifecycle protection
7.6–7.9 Incidents, controls, vulnerability/patch, changePrepare, detect, contain, recover, prevent, prioritize, authorize, test, deploy, verify, and roll back
7.10–7.13 Recovery, disaster recovery, testing, continuityTranslate business impact into strategies, plans, exercises, communications, restoration, and improvement
7.14–7.15 Physical security and personnel safetyOperate facility and emergency controls with protection of people as the first priority

Investigations and evidence

Determine investigation type, authority, privacy limits, legal or regulatory involvement, and evidence requirements before collection. Preserve original evidence and work from controlled copies. Record collector, source, time, method, integrity, transfers, storage, and access. Coordinate with legal, HR, law enforcement, regulators, insurers, or suppliers through approved processes.

For digital forensics, consider volatility and order of collection, but do not perform an unsafe or unauthorized action to follow a generic order. Time synchronization, system state, memory, processes, network connections, logs, storage, cloud control-plane records, snapshots, backups, identity events, and external providers may contribute. Cloud and SaaS evidence depends on service capabilities and shared responsibility.

eDiscovery concerns identification, preservation, collection, processing, review, and production under legal authority. A litigation hold can suspend normal deletion. Security teams support preservation and technical collection; counsel directs legal decisions.

Logging, monitoring, and intelligence

Define events from response questions. Collect identity, endpoint, network, DNS, application, cloud, data, physical, and control-plane evidence as needed. Protect integrity, access, time, retention, and privacy. Normalize carefully while retaining original records or durable references. Correlate principal, asset, action, data, time, and outcome.

Security information and event management can aggregate and correlate; orchestration and automation can route or act; behavior analytics can identify deviations; threat intelligence can add context. None eliminates validation and ownership. Evaluate intelligence source, timeliness, relevance, confidence, and permitted use. Indicators expire; behaviors and adversary methods can provide more durable hypotheses.

Tune detections with false-positive and false-negative analysis. Suppression needs owner and expiry. Measure coverage, delivery, alert quality, time to triage, time to contain, and recurring blind spots. Avoid logging secrets and sensitive content without purpose and controls.

Configuration and controlled operations

Maintain hardware, software, cloud, network, data, identity, certificate, key, supplier, and owner inventories. Establish secure baselines, version configuration, detect drift, authorize exceptions, and reconcile actual state. Hardening includes removing defaults, disabling unnecessary services, least privilege, patching, secure protocols, logging, backup, and support status.

Apply need to know, least privilege, separation of duties, job rotation where appropriate, mandatory leave for certain fraud risks, two-person control for high-impact action, and service-level agreements. Protect privileged operations and maintenance tools. Track media, keys, devices, spare parts, licenses, and end-of-life resources.

Job scheduling, batch processing, backups, and automation need identity, input validation, dependencies, failure handling, evidence, and ownership. Protect scripts and pipelines as production code. Capacity, quotas, certificates, and support expiry are operational risks.

Incident management

Prepare roles, communications, access, evidence, playbooks, suppliers, exercises, and recovery. Detect and analyze to validate event, scope assets and identities, assess business impact, and prioritize. Contain with the least destructive effective action. Eradicate persistence and enabling weaknesses. Recover from known-good state, validate integrity and monitoring, obtain business acceptance, and track lessons.

Communication must be accurate, authorized, audience-appropriate, and timely. Maintain one decision log and distinguish confirmed facts, hypotheses, and unknowns. Legal and executive owners decide external notification under applicable requirements.

Preventive and detective technologies—firewalls, IDS/IPS, allow/deny lists, endpoint protection, sandboxing, antimalware, analytics, and machine learning—have scope and failure modes. Layer them with identity, configuration, patching, awareness, monitoring, and response.

Vulnerability, patch, and change management

Discover assets and vulnerabilities, validate exposure, prioritize from exploitability, asset criticality, data, access path, threat activity, compensating controls, and business impact. Select remediation, mitigation, acceptance, or removal. Test changes, schedule by risk and operations, deploy, verify, and monitor. Exceptions need owner, rationale, compensating control, expiry, and review.

Patch management is a controlled change process, not merely installation. Address dependencies, backups, compatibility, rollback, emergency approval, and verification. A patch can fail to deploy, fail to remove exposure, or create new business impact.

Change management records request, impact, risk, affected configuration, security review, test, approval, schedule, communication, implementation, validation, rollback, and documentation. Standard changes are pre-authorized within defined conditions. Emergency change accelerates process but still requires authority, evidence, validation, and retrospective review. Detect unauthorized change.

Recovery and continuity

Business continuity sustains critical products and processes. Disaster recovery restores technology and facilities that support them. Use BIA-derived priorities, RTO, RPO, maximum tolerable disruption, dependencies, people, suppliers, alternate work methods, and communications.

Recovery options include backups, alternate sites, redundancy, replication, spare equipment, manual processes, cloud capacity, reciprocal arrangements where credible, and third-party services. Hot, warm, and cold site labels describe readiness and cost but do not prove objectives. Protect recovery data and credentials from the same incident as production.

During disaster response, protect people, declare through authority, communicate, assess damage, activate strategies, restore in business priority, validate, operate in contingency, salvage safely, fail back deliberately, and return to normal. Test through checklist, tabletop, walkthrough, simulation, parallel processing, or full interruption as risk permits. Every exercise needs objectives, safety, evidence, corrective action, owner, and retest.

Physical security and safety

Operate layered facility access, visitor management, surveillance, alarms, guards, locks, barriers, lighting, power, cooling, fire detection and suppression, water protection, emergency power, equipment protection, and restricted areas. Keep logs and test emergency systems. Coordinate cyber and physical monitoring.

Personnel safety overrides asset protection. Plan evacuation, shelter, emergency communication, duress, lone work, travel, medical response, muster, and responder access. Do not require an employee to preserve equipment or evidence at unreasonable personal risk.

Decision patterns

  • Safety before evidence: protect people and emergency operations before preserving equipment or collecting volatile data.
  • Authority before action: confirm investigative, legal, privacy, change, and communications authority before high-impact operational steps.
  • Reversible containment before destructive remediation: limit impact while evidence, scope, dependencies, and recovery options are still being established.
  • Business priority before restoration convenience: recover processes in BIA order and validate the service, data, identity, monitoring, and owner acceptance together.
  • Verified outcome before closure: prove that a patch, restore, configuration change, or corrective action worked and did not introduce unacceptable risk.
  • Learning before repetition: assign every material lesson an owner, due date, verification method, and retest.

Scenario drill

A privileged account behaves anomalously during a production change while a regional storm threatens the primary facility.

  1. Protect personnel and activate emergency and continuity authority.
  2. Validate identity and change evidence; separate approved activity from suspected compromise.
  3. Preserve logs and system state while applying reversible containment that does not block safety operations.
  4. Coordinate incident, facilities, continuity, legal, communications, and workload owners.
  5. Restore critical services by business priority at the approved alternate capability.
  6. Remove the identity or change root cause, validate recovery, fail back deliberately, and track corrective actions.

Common traps

  • Destroying evidence before confirming authority and scope.
  • Collecting every log without retention, privacy, detection, or owner.
  • Treating patch installation as verified remediation.
  • Allowing emergency change to bypass documentation and later review.
  • Assuming replication protects against corruption or malicious deletion.
  • Selecting recovery technology before completing business impact analysis.
  • Protecting equipment before people.

Self-check

  1. Distinguish containment, eradication, recovery, and closure.
  2. Build a vulnerability priority using threat, exposure, asset, and business evidence.
  3. Compare standard, normal, and emergency change.
  4. Map a business process to RTO, RPO, dependencies, and recovery exercise.
  5. Name the evidence required to prove a failed patch or backup was corrected.

Primary references