Professional ethics
Apply and promote the ISC2 Code of Ethics and organizational ethics when duties, stakeholders, or incentives conflict.
- Lesson
- d1-lesson
- Practice pool
- d1-questions
- Application
- cissp-s01
Make ethical, governance, legal, business-continuity, personnel, risk, threat-model, supply-chain, and awareness decisions from an organizational perspective.
Apply and promote the ISC2 Code of Ethics and organizational ethics when duties, stakeholders, or incentives conflict.
Apply confidentiality, integrity, availability, authenticity, and nonrepudiation to business and system decisions.
Align security roles, accountability, strategy, frameworks, due care, due diligence, and oversight with organizational goals.
Recognize legal systems, privacy, intellectual property, transborder data, contractual, regulatory, and industry obligations.
Distinguish administrative, criminal, civil, regulatory, and industry investigations and their evidence requirements.
Develop and distinguish governing policy, mandatory standards, repeatable procedures, and recommended guidelines.
Use business impact analysis, dependencies, priorities, and management approval to establish continuity requirements.
Apply screening, agreements, onboarding, transfer, termination, third-party, and role-change controls.
Identify, analyze, assess, prioritize, treat, monitor, communicate, and improve organizational risk.
Use repeatable threat-modeling concepts to identify trust boundaries, threats, abuse paths, controls, and validation.
Address supplier, component, service, provenance, tampering, concentration, contractual, assessment, and monitoring risk.
Design role-aware programs, delivery methods, current content, behavioral measures, and program-effectiveness evaluation.
Security exists to support organizational objectives within acceptable risk and binding obligations. Senior security professionals advise, design, monitor, and escalate; accountable business leaders own business risk. When an exam scenario offers a tempting technical fix, first identify authority, safety, legal or contractual duties, affected assets, business impact, and the decision owner.
Use this sequence: understand context → identify obligations and assets → assess risk → select treatment and controls → obtain authorization → implement → measure → improve.
| Objectives | Decision focus |
|---|---|
| 1.1–1.3 Ethics, security concepts, governance | Act ethically; connect confidentiality, integrity, availability, authenticity, and nonrepudiation to strategy, roles, due care, and oversight |
| 1.4–1.6 Legal/compliance, investigations, policy hierarchy | Determine applicable authority and evidence needs; distinguish policy, standard, procedure, and guideline |
| 1.7–1.8 Continuity and personnel | Derive continuity priorities from business impact and govern people through screening, onboarding, change, and termination |
| 1.9–1.10 Risk and threat modeling | Identify, analyze, treat, monitor, and communicate risk; map trust boundaries and abuse paths to testable controls |
| 1.11–1.12 Supply chain and learning | Govern suppliers and components across their lifecycle; build role-aware education measured by behavior and outcomes |
Apply the ISC2 Code of Ethics and organizational ethics when duties conflict. Protect society and the common good, act honorably and legally, provide diligent service, and advance the profession. In a scenario involving concealment, unsafe action, or pressure to ignore a duty, escalate through authorized channels and preserve facts. Do not exceed authority in the name of security.
Translate security principles into business consequences. Confidentiality limits unauthorized disclosure. Integrity protects correctness and authorized change. Availability ensures timely, reliable access. Authenticity supports confidence in identity or origin. Nonrepudiation provides evidence that can resist a party's denial under the relevant process. Controls may support several properties, but state the primary requirement before choosing one.
Governance establishes direction and accountability. The board and executives set risk appetite and oversight. Management assigns owners and resources. Data and system owners make classification and access decisions. Custodians operate controls. Security advises, monitors, and reports. Internal audit provides independent assurance. Clear separation matters: the person implementing a control should not be the only person deciding whether it is effective.
Due care is the conduct reasonably expected to protect interests; due diligence is the ongoing investigation, verification, and monitoring used to sustain that care. Policies and evidence help demonstrate both, but the exact legal meaning depends on jurisdiction and facts.
Identify applicable law, regulation, contract, industry rule, privacy duty, intellectual-property requirement, and data-transfer restriction before designing controls. Requirements can conflict across jurisdictions. Security professionals should identify and escalate the conflict to qualified legal and business authority, not improvise legal advice.
Investigation type changes authority and evidence procedure. Criminal, civil, regulatory, administrative, internal, insurance, and incident investigations can have different standards, privacy limits, discovery obligations, and reporting paths. Preserve evidence integrity, document collection and transfer, use approved tools, and involve legal or human-resources teams when required. Technical access does not automatically create investigative authority.
Policy expresses management intent and mandatory direction. Standards define required controls or measures. Procedures define repeatable steps. Guidelines provide recommended discretion. Baselines establish an approved minimum configuration. Keep documents approved, communicated, versioned, exception-aware, reviewed, and connected to enforcement and evidence.
Business continuity begins with business impact analysis, not technology inventory. Identify critical products and processes, people, facilities, data, suppliers, applications, dependencies, maximum tolerable disruption, recovery time, and recovery point. Management approves priorities because simultaneous recovery of everything is unrealistic. Security and resilience teams design strategies that meet those priorities and exercise them.
Personnel security spans role definition, screening proportional to risk and law, agreements, awareness, onboarding, access provisioning, transfers, leave, performance issues, termination, contractors, and third parties. Trigger access change from authoritative lifecycle events. Remove or adjust access promptly, recover assets, preserve records, and separate hostile-termination handling from routine offboarding.
Define scope and assets, identify threats and vulnerabilities, analyze likelihood and impact, compare to appetite and tolerance, select treatment, assign ownership, implement controls, and monitor residual risk. Qualitative methods support relative decisions; quantitative methods estimate financial values but depend on uncertain inputs. Single loss expectancy, annualized rate of occurrence, and annualized loss expectancy can structure estimates, but false precision is dangerous.
Treatment choices are avoid, mitigate, transfer/share, or accept. Insurance can transfer some financial impact but rarely transfers accountability, legal duty, reputation, or operational disruption. Risk acceptance requires an authorized owner, defined residual risk, rationale, duration, monitoring, and review. Security cannot accept business risk simply because it found the issue.
Controls may be administrative, technical, or physical and may deter, prevent, detect, correct, recover, or compensate. Select from threat, asset value, requirement, feasibility, assurance, lifecycle, cost, and human impact. Defense in depth should create independent barriers and evidence, not duplicate the same failure mode.
Threat modeling identifies assets, trust boundaries, actors, entry points, threats, abuse paths, and assumptions. Prioritize credible paths, map controls to them, and define validation. Keep the model current as architecture and suppliers change. A list of threats without ownership and tests is incomplete.
Supply-chain risk covers vendors, cloud services, software, hardware, components, data, personnel, concentration, provenance, tampering, support, and exit. Perform due diligence before selection; establish security, incident, audit, notification, vulnerability, data, subcontractor, continuity, return/destruction, and termination requirements in contracts. Monitor performance and changes. A certification report is useful evidence, not a guarantee for the customer's use case.
Awareness builds broad recognition and expected behavior. Training develops job skills. Education builds deeper understanding and judgment. Tailor by role and risk, use current scenarios, reinforce behavior, and measure reporting, secure practice, simulation outcomes, incidents, and control use rather than completion alone.
| Scenario | Best first perspective | Weak response |
|---|---|---|
| Unapproved high risk | Identify authorized risk owner and options | Security accepts it silently |
| Conflicting jurisdictional duties | Escalate to qualified legal and business authority | Choose the stricter rule without analysis |
| Critical system outage | Protect people, invoke authorized continuity process, follow business priorities | Recover the most technically interesting server |
| Supplier with weak evidence | Assess use-case risk, contract, compensating controls, monitoring, and exit | Accept a badge as complete assurance |
| Repeated unsafe employee action | Review process, incentives, role training, and controls | Repeat generic annual awareness only |
A supplier supporting a critical service reports a breach but cannot yet confirm customer-data impact. Operations wants silence until facts are complete; legal duties and contract notification periods may apply.