CISSP · D1 · 16%

Security and Risk Management

Make ethical, governance, legal, business-continuity, personnel, risk, threat-model, supply-chain, and awareness decisions from an organizational perspective.

Provider facts checked 2026-08-03

Objective coverage

Objective 1.1 · high

Professional ethics

Apply and promote the ISC2 Code of Ethics and organizational ethics when duties, stakeholders, or incentives conflict.

Lesson
d1-lesson
Practice pool
d1-questions
Application
cissp-s01
Objective 1.2 · foundation

Security concepts

Apply confidentiality, integrity, availability, authenticity, and nonrepudiation to business and system decisions.

Lesson
d1-lesson
Practice pool
d1-questions
Application
cissp-s01
Objective 1.3 · high

Security governance

Align security roles, accountability, strategy, frameworks, due care, due diligence, and oversight with organizational goals.

Lesson
d1-lesson
Practice pool
d1-questions
Application
cissp-s01
Objective 1.4 · high

Legal, regulatory, and compliance issues

Recognize legal systems, privacy, intellectual property, transborder data, contractual, regulatory, and industry obligations.

Lesson
d1-lesson
Practice pool
d1-questions
Application
cissp-s01
Objective 1.5 · normal

Investigation requirements

Distinguish administrative, criminal, civil, regulatory, and industry investigations and their evidence requirements.

Lesson
d1-lesson
Practice pool
d1-questions
Application
cissp-s08
Objective 1.6 · foundation

Policies, standards, procedures, and guidelines

Develop and distinguish governing policy, mandatory standards, repeatable procedures, and recommended guidelines.

Lesson
d1-lesson
Practice pool
d1-questions
Application
cissp-s01
Objective 1.7 · high

Business continuity requirements

Use business impact analysis, dependencies, priorities, and management approval to establish continuity requirements.

Lesson
d1-lesson
Practice pool
d1-questions
Application
cissp-s02
Objective 1.8 · normal

Personnel security

Apply screening, agreements, onboarding, transfer, termination, third-party, and role-change controls.

Lesson
d1-lesson
Practice pool
d1-questions
Application
cissp-s01
Objective 1.9 · high

Risk management

Identify, analyze, assess, prioritize, treat, monitor, communicate, and improve organizational risk.

Lesson
d1-lesson
Practice pool
d1-questions
Application
cissp-s01
Objective 1.10 · high

Threat modeling

Use repeatable threat-modeling concepts to identify trust boundaries, threats, abuse paths, controls, and validation.

Lesson
d1-lesson
Practice pool
d1-questions
Application
cissp-s04
Objective 1.11 · high

Supply-chain risk management

Address supplier, component, service, provenance, tampering, concentration, contractual, assessment, and monitoring risk.

Lesson
d1-lesson
Practice pool
d1-questions
Application
cissp-s10
Objective 1.12 · normal

Security awareness, education, and training

Design role-aware programs, delivery methods, current content, behavioral measures, and program-effectiveness evaluation.

Lesson
d1-lesson
Practice pool
d1-questions
Application
cissp-s01

title: "Security and Risk Management" summary: "Management-centered reasoning for governance, ethics, compliance, risk treatment, policy, awareness, and supply-chain assurance."

Use the management perspective

CISSP decisions begin with ethics, authority, business objectives, legal and contractual duties, asset ownership, risk ownership, policy, and evidence. A technically effective action can still be wrong if it exceeds authority, destroys evidence, endangers people, violates an obligation, or bypasses the accountable owner.

Distinguish governance from management and implementation. Governance sets direction and accountability. Management allocates resources and accepts risk within authority. Security professionals assess, advise, design, operate, and report but do not silently become the business risk owner.

Risk work identifies assets, threats, vulnerabilities, likelihood, impact, existing controls, uncertainty, treatment, residual risk, owner, monitoring, and communication. Acceptance cannot waive law or contract. Business continuity priorities come from business impact and dependencies, not system preference.

Threat modeling examines assets, trust boundaries, actors, abuse paths, controls, and validation. Supply-chain risk includes provenance, tampering, concentration, contracts, assessment, monitoring, components, service dependencies, and exit. Awareness programs must be role-aware, current, measured, and improved.

Self-check

When a senior executive asks security to accept a regulatory risk, identify the ethical duty, authoritative owner, mandatory obligation, decision record, residual risk, and escalation path.