Professional ethics
Apply and promote the ISC2 Code of Ethics and organizational ethics when duties, stakeholders, or incentives conflict.
- Lesson
- d1-lesson
- Practice pool
- d1-questions
- Application
- cissp-s01
Make ethical, governance, legal, business-continuity, personnel, risk, threat-model, supply-chain, and awareness decisions from an organizational perspective.
Apply and promote the ISC2 Code of Ethics and organizational ethics when duties, stakeholders, or incentives conflict.
Apply confidentiality, integrity, availability, authenticity, and nonrepudiation to business and system decisions.
Align security roles, accountability, strategy, frameworks, due care, due diligence, and oversight with organizational goals.
Recognize legal systems, privacy, intellectual property, transborder data, contractual, regulatory, and industry obligations.
Distinguish administrative, criminal, civil, regulatory, and industry investigations and their evidence requirements.
Develop and distinguish governing policy, mandatory standards, repeatable procedures, and recommended guidelines.
Use business impact analysis, dependencies, priorities, and management approval to establish continuity requirements.
Apply screening, agreements, onboarding, transfer, termination, third-party, and role-change controls.
Identify, analyze, assess, prioritize, treat, monitor, communicate, and improve organizational risk.
Use repeatable threat-modeling concepts to identify trust boundaries, threats, abuse paths, controls, and validation.
Address supplier, component, service, provenance, tampering, concentration, contractual, assessment, and monitoring risk.
Design role-aware programs, delivery methods, current content, behavioral measures, and program-effectiveness evaluation.
CISSP decisions begin with ethics, authority, business objectives, legal and contractual duties, asset ownership, risk ownership, policy, and evidence. A technically effective action can still be wrong if it exceeds authority, destroys evidence, endangers people, violates an obligation, or bypasses the accountable owner.
Distinguish governance from management and implementation. Governance sets direction and accountability. Management allocates resources and accepts risk within authority. Security professionals assess, advise, design, operate, and report but do not silently become the business risk owner.
Risk work identifies assets, threats, vulnerabilities, likelihood, impact, existing controls, uncertainty, treatment, residual risk, owner, monitoring, and communication. Acceptance cannot waive law or contract. Business continuity priorities come from business impact and dependencies, not system preference.
Threat modeling examines assets, trust boundaries, actors, abuse paths, controls, and validation. Supply-chain risk includes provenance, tampering, concentration, contracts, assessment, monitoring, components, service dependencies, and exit. Awareness programs must be role-aware, current, measured, and improved.
When a senior executive asks security to accept a regulatory risk, identify the ethical duty, authoritative owner, mandatory obligation, decision record, residual risk, and escalation path.