All domains

Domain 1 · 16% of the exam

Security and Risk Management

Security professionals need to develop a comprehensive understanding of the principles, concepts, and best practices related to information security management. This includes not only technical skills but also an understanding of ethics, legal and regulatory requirements, risk management, and security governance.

Learning objectives

  • Define and explain the importance of an organizational code of ethics.
  • Explain the ethical standards every professional security professional is expected to uphold.
  • Specify the standards of behavior and performance expected of ISC2 members.
  • Explain confidentiality, integrity, availability, authenticity, non-repudiation, privacy, and safety.
  • Relate security governance to organizational business strategies, goals, missions, and objectives.
  • Relate concepts and principles to due care and due diligence.
  • Describe contractual, legal, and industry standards, as well as regulatory requirements for information security.
  • Explain the relationship of privacy protection to organizational information security risk management.
  • Explain how cybercrimes and data breaches apply to privacy.
  • Explain how licensing and intellectual property (IP) requirements apply to privacy.
  • Explain how import and export controls apply to data protection.
  • Explain how transborder data flow applies to privacy.
  • Understand requirements for investigation types an organization may conduct in the case of a cyber incident.
  • Link various privacy, cybersecurity, and risk frameworks as compliance requirements to their role in operational processes.
  • Compare and contrast different frameworks from an operational security perspective.
  • Explain the overall organizational business continuity practice.
  • Describe the importance of the business impact analysis (BIA) to the planning process.
  • Identify the key steps and resources necessary to support the BIA.
  • Advocate for security considerations in personnel practices.
  • Apply basic risk management theory to information security risks.
  • Identify various threat modeling concepts and methodologies and their applications.
  • Apply risk management practices to an example business area.
  • Identify standards associated with supply chain risk management (SCRM).
  • Describe service-level agreements (SLAs) to support contractual relationships.
  • Demonstrate the readiness of the human component of organizational information security.

Key topics

  • Professional Ethics
  • Legal, Regulatory, and Compliance Concerns
  • Standards, Procedures, and Guidelines
  • Risk Management Concepts
  • Security Concepts
  • Investigation Types
  • Business Continuity Requirements
  • Threat Modeling Concepts and Methodologies
  • Security Awareness, Education, and Training Programs
  • Security Governance Principles
  • Security Policy
  • Personnel Security Policies and Procedures
  • Supply Chain Risk Management Concepts

Lessons

Ordered the way the course presents them. Work top to bottom, or jump to whatever you need.

  1. 01Organizational Roles and ResponsibilitiesRoles and responsibilities in cybersecurity define who is accountable for securing systems and data, helping prevent vulnerabilities and ensuring effective threat response and compliance.5 slides · 3 min read
  2. 02Applicable Types of Controls and Control CategoriesEffective risk management involves applying technical, physical, and administrative controls, including directive, deterrent, preventive, and compensating measures tailored to specific threats.7 slides · 4 min read
  3. 03Privacy TermsYou should be familiar with these general concepts.4 slides · 3 min read
  4. 04Select Appropriate Business Continuity StandardsAn organization that wishes to implement a Business Continuity Plan (BCP) can either build the plan independently or use wellknown industry standards either as a reference or adopt the standard in its entirety.3 slides · 1 min read
  5. 05Risk Assessment and Treatment DecisionsAn important use of risk assessments is to inform a cost-benefits decision about how to deal with a particular risk or a set of related risks.8 slides · 5 min read
  6. 06Types of InvestigationsCivil Investigation14 slides · 8 min read
  7. 07Industry StandardsThere are many industry standards for investigations of all sorts, including IT security and data investigations; applicable standards for a given organization depend on a host of variables, such as geographic region/jurisdiction, the nature of the data in…4 slides · 1 min read
  8. 08Implement Candidate Screening and HiringThere are several measures and tools that can be implemented for screening and hiring such as the following:4 slides · 2 min read
  9. 09Candidate Screening and HiringEffective candidate screening and hiring practices help reduce insider threats by identifying risk factors before granting access to sensitive systems and data.8 slides · 3 min read
  10. 10Non-Disclosure AgreementNon-disclosure agreements are formal agreements that restrict the sharing of information disclosed between two parties to any third party without prior consent.4 slides · 2 min read
  11. 11Vendor, Consultant, and Contractor Agreements and ControlsExternal parties such as vendors, consultants, and contractors from outside the organization might also have access to the organization's IT environment and internal information.4 slides · 1 min read
  12. 12Employment Agreements and PoliciesOnce the organization has decided which candidate should fill a position, additional tools are available to enhance or support the trustworthiness and security of employees and staff.2 slides · 1 min read
  13. 13Periodic Content ReviewsAs we know, the security threat landscape is ever changing, and if we want our security training to be effective, we must ensure that our training and awareness materials are updated and relevant. Pertinent security aspects that should be included in the…2 slides · 1 min read
  14. 14Cybersecurity FrameworkJust like in the case of privacy frameworks, there are various frameworks in the cybersecurity world that can help guide an organization on how cybersecurity is governed.6 slides · 4 min read
  15. 15Risk FrameworksSimilar to (and, in some cases, overlapping with) the security control frameworks, the security professional may also make use of risk frameworks to optimize the organization's response to risk. In many mature organizations, this effort defines the…4 slides · 2 min read
  16. 16Security Control FrameworksIn marked contrast with many of the frameworks just reviewed, security control frameworks (SCFs) provide the framework publishers' minimum acceptable practices for implementation and operation of security controls within their span of activities.2 slides · 1 min read
  17. 17National and Regional FrameworksAt its heart, GDPR consists of rules, regulations and penalties that provide European citizens more control over their own personal data.4 slides · 2 min read
  18. 18Is Privacy Shield DeadAs the GDPR was being published, the United States developed concepts known as Safe Harbor and the Privacy Shield, which were voluntary for U.S. organizations wishing to do business with EU persons or organizations. In essence it provided an early on-ramp…2 slides · 1 min read
  19. 19GDPR Privacy PrinciplesThe GDPR codifies these concepts of privacy (in its Article 5) into six broad principles regarding the use of personal data.3 slides · 1 min read
  20. 20Cybercrimes and Data BreachesData breaches happen all the time. Some breaches are caused by the negligence of internal users, while other breaches are realized due to malicious activities and cybercrime. Some data breaches have dire repercussions. And unfortunately, jurisdiction by…5 slides · 2 min read
  21. 21Definitions Related to RiskFor purposes of this module, let's use the following definitions for some key risk terms.3 slides · 1 min read
  22. 22When to Use Which Risk Assessment TechniqueUse qualitative methods for general, subjective analysis, and use quantitative methods when precise data allows for detailed measurement and analysis of financial impact. For most of the last 50 years, the choice of when to use which assessment technique…3 slides · 2 min read
  23. 23Monitoring and MeasurementSelecting, installing, and making good operational use out of all security controls - including those focused on safety, privacy, and all other aspects of information security - are part of fulfilling the organization's due care responsibilities.3 slides · 2 min read
  24. 24Risks Associated with Hardware, Software, and ServicesOrganizations cannot operate solely alone; there are many dependencies and interconnections that organizations have with their entire supply chain, which includes suppliers, vendors, contractors and customers.2 slides · 1 min read
  25. 25Planning Factors for Business Continuity and Disaster RecoveryCreating a business continuity and disaster recovery plan involves identifying critical operations, assessing risks, defining recovery strategies, and establishing procedures to maintain or quickly resume essential services.5 slides · 4 min read
  26. 26Threat ModelingIn some threat models used for specific targets (systems/applications, instead of the overall organization), other elements can be used (mostly in addition to, not in lieu of, the abstract); incorporating those same threat modeling techniques into the…6 slides · 2 min read
  27. 27Privacy Concepts Continually and Rapidly EvolvePrivacy regulations and expectations shift frequently, driven by technological advances, legal challenges, and changing views on how personal data should be handled and safeguarded.5 slides · 3 min read
  28. 28Identify and Prioritize Business Continuity RequirementsBusiness continuity requirements are the essential tasks and systems an organization needs to keep running or restore quickly to minimize disruption during and after an unexpected incident.3 slides · 2 min read
  29. 29Four Perspectives What is at RiskRisk management should be approached by evaluating assets, anticipating outcomes, analyzing processes, and understanding vulnerabilities and threats that could impact security objectives.4 slides · 3 min read
  30. 30Continuous Improvement (Risk Maturity Modeling)Continuous improvement and risk maturity models help organizations strengthen risk management practices by identifying gaps, tracking progress, and guiding measurable enhancements over time.3 slides · 2 min read
  31. 31Third-Party Assessments and MonitoringIt is imperative that an organization apply the same risk-management methodologies and perspectives to its supply chain as the organization did for its own internal operations.3 slides · 2 min read
  32. 32Compliance Policy RequirementsOrganizations should use acceptable use policies (AUPS) for all personnel.4 slides · 1 min read
  33. 33Control Selection (Security and Privacy)When selecting security and privacy controls, an organization can use various frameworks. According to NIST SP 800-37, Revision 2, the Select Step of the Risk Management Framework, there are two approaches that can be used for the initial selection of…4 slides · 1 min read
  34. 34Service-Level RequirementsClients define service-level requirements by specifying the performance and quality standards a service must meet, forming the basis for service-level agreements.5 slides · 2 min read
  35. 35Privacy FrameworksAn organization might implement a privacy framework to be used by the organization. It is a set of privacy principles, standards, and or guidelines.4 slides · 2 min read
  36. 36Minimum Security RequirementsMeeting minimum security requirements at every level demands consistent enforcement of policies, controls, and protections across systems, applications, data, and organizational processes.3 slides · 1 min read
  37. 37The Right to Be ForgottenThe right to be forgotten is part of the EU's General Data Protection Regulation, allowing individuals to request deletion of their personal data.4 slides · 2 min read
  38. 38Data LocalizationLocal data protection laws govern how organizations collect, use, and share personal data, often requiring transparency, consent, security measures, and individual rights.4 slides · 2 min read
  39. 39National and Regional Framework ExamplesOrganizations handling and processing user data must comply with regional data privacy laws protecting data against inappropriate use.5 slides · 4 min read
  40. 40Data PortabilityData portability is a critical capability in modern IT environments, enabling seamless data movement across platforms and supporting technical operations and regulatory compliance.2 slides · 1 min read
  41. 41Privacy ProtectionPrivacy protection for data is guided by OECD privacy principles, which focus on user consent, transparency, and ensuring secure handling of personal information, particularly during cross-border transfers.3 slides · 1 min read
  42. 42Privacy Policy RequirementsPrivacy policies must clearly outline data collection, use, sharing, and retention practices while aligning with legal requirements and supporting controls that protect personal information throughout its life cycle.3 slides · 1 min read
  43. 43Program Effectiveness EvaluationDue care requires us to provide effective education, training, and awareness to employees; due diligence requires us to evaluate the effectiveness of that training.5 slides · 2 min read
  44. 44Import and Export ControlsImport and export controls require navigating international agreements and complying with national laws to regulate the cross-border flow of sensitive data, software, and technology.4 slides · 3 min read
  45. 45Organizational Governance ProcessesOrganizational governance includes strategic planning, risk management, compliance, performance monitoring, and decisionmaking processes to ensure accountability and alignment with goals.6 slides · 3 min read
  46. 46Methods and Techniques to Present Awareness and TrainingCybersecurity awareness and training are best supported through regular sessions, real-world simulations, clear policies, and engaging, role-specific content that highlights threats and safe practices.4 slides · 3 min read
  47. 47Organizational Code of EthicsAn organizational code of ethics defines acceptable and prohibited behaviors, and helps ensure compliance with laws and regulations, fostering a responsible and accountable environment.2 slides · 2 min read
  48. 48The Legal EnvironmentThe legal environment dictates compliance requirements, with leadership responsible for ensuring adherence, while auditing verifies alignment with regulations and standards.3 slides · 2 min read
  49. 49Case Study Marriott Data BreachThe Marriott data breach in 2018 was a significant cyber incident that exposed the personal information of approximately 500 million guests. The breach, attributed to unauthorized access within the Starwood guest reservation database, compromised sensitive…4 slides · 2 min read
  50. 50ISC2 Code of Professional EthicsISC2 members are expected to behave professionallly and personally in accordance with the high standards set by ISC2. These are set in the Code of Ethics, which can be found on the ISC2 Ethics website: www.isc2.org/Ethics4 slides · 1 min read
  51. 51Conutermeasure Selection and ImplementationCountermeasures are chosen by balancing effectiveness, cost, and potential impact to optimize security while minimizing expenses and disruptions.3 slides · 1 min read
  52. 52Professional Ethics 1MDBThis is a case study of a real-life situation that demonstrates how security concepts apply not just to your professional life, but to the world stage.6 slides · 2 min read