Domain 1 · 16% of the exam
Security and Risk Management
Security professionals need to develop a comprehensive understanding of the principles, concepts, and best practices related to information security management. This includes not only technical skills but also an understanding of ethics, legal and regulatory requirements, risk management, and security governance.
Learning objectives
- Define and explain the importance of an organizational code of ethics.
- Explain the ethical standards every professional security professional is expected to uphold.
- Specify the standards of behavior and performance expected of ISC2 members.
- Explain confidentiality, integrity, availability, authenticity, non-repudiation, privacy, and safety.
- Relate security governance to organizational business strategies, goals, missions, and objectives.
- Relate concepts and principles to due care and due diligence.
- Describe contractual, legal, and industry standards, as well as regulatory requirements for information security.
- Explain the relationship of privacy protection to organizational information security risk management.
- Explain how cybercrimes and data breaches apply to privacy.
- Explain how licensing and intellectual property (IP) requirements apply to privacy.
- Explain how import and export controls apply to data protection.
- Explain how transborder data flow applies to privacy.
- Understand requirements for investigation types an organization may conduct in the case of a cyber incident.
- Link various privacy, cybersecurity, and risk frameworks as compliance requirements to their role in operational processes.
- Compare and contrast different frameworks from an operational security perspective.
- Explain the overall organizational business continuity practice.
- Describe the importance of the business impact analysis (BIA) to the planning process.
- Identify the key steps and resources necessary to support the BIA.
- Advocate for security considerations in personnel practices.
- Apply basic risk management theory to information security risks.
- Identify various threat modeling concepts and methodologies and their applications.
- Apply risk management practices to an example business area.
- Identify standards associated with supply chain risk management (SCRM).
- Describe service-level agreements (SLAs) to support contractual relationships.
- Demonstrate the readiness of the human component of organizational information security.
Key topics
- Professional Ethics
- Legal, Regulatory, and Compliance Concerns
- Standards, Procedures, and Guidelines
- Risk Management Concepts
- Security Concepts
- Investigation Types
- Business Continuity Requirements
- Threat Modeling Concepts and Methodologies
- Security Awareness, Education, and Training Programs
- Security Governance Principles
- Security Policy
- Personnel Security Policies and Procedures
- Supply Chain Risk Management Concepts
Lessons
Ordered the way the course presents them. Work top to bottom, or jump to whatever you need.
- 01Organizational Roles and ResponsibilitiesRoles and responsibilities in cybersecurity define who is accountable for securing systems and data, helping prevent vulnerabilities and ensuring effective threat response and compliance.5 slides · 3 min read
- 02Applicable Types of Controls and Control CategoriesEffective risk management involves applying technical, physical, and administrative controls, including directive, deterrent, preventive, and compensating measures tailored to specific threats.7 slides · 4 min read
- 03Privacy TermsYou should be familiar with these general concepts.4 slides · 3 min read
- 04Select Appropriate Business Continuity StandardsAn organization that wishes to implement a Business Continuity Plan (BCP) can either build the plan independently or use wellknown industry standards either as a reference or adopt the standard in its entirety.3 slides · 1 min read
- 05Risk Assessment and Treatment DecisionsAn important use of risk assessments is to inform a cost-benefits decision about how to deal with a particular risk or a set of related risks.8 slides · 5 min read
- 06Types of InvestigationsCivil Investigation14 slides · 8 min read
- 07Industry StandardsThere are many industry standards for investigations of all sorts, including IT security and data investigations; applicable standards for a given organization depend on a host of variables, such as geographic region/jurisdiction, the nature of the data in…4 slides · 1 min read
- 08Implement Candidate Screening and HiringThere are several measures and tools that can be implemented for screening and hiring such as the following:4 slides · 2 min read
- 09Candidate Screening and HiringEffective candidate screening and hiring practices help reduce insider threats by identifying risk factors before granting access to sensitive systems and data.8 slides · 3 min read
- 10Non-Disclosure AgreementNon-disclosure agreements are formal agreements that restrict the sharing of information disclosed between two parties to any third party without prior consent.4 slides · 2 min read
- 11Vendor, Consultant, and Contractor Agreements and ControlsExternal parties such as vendors, consultants, and contractors from outside the organization might also have access to the organization's IT environment and internal information.4 slides · 1 min read
- 12Employment Agreements and PoliciesOnce the organization has decided which candidate should fill a position, additional tools are available to enhance or support the trustworthiness and security of employees and staff.2 slides · 1 min read
- 13Periodic Content ReviewsAs we know, the security threat landscape is ever changing, and if we want our security training to be effective, we must ensure that our training and awareness materials are updated and relevant. Pertinent security aspects that should be included in the…2 slides · 1 min read
- 14Cybersecurity FrameworkJust like in the case of privacy frameworks, there are various frameworks in the cybersecurity world that can help guide an organization on how cybersecurity is governed.6 slides · 4 min read
- 15Risk FrameworksSimilar to (and, in some cases, overlapping with) the security control frameworks, the security professional may also make use of risk frameworks to optimize the organization's response to risk. In many mature organizations, this effort defines the…4 slides · 2 min read
- 16Security Control FrameworksIn marked contrast with many of the frameworks just reviewed, security control frameworks (SCFs) provide the framework publishers' minimum acceptable practices for implementation and operation of security controls within their span of activities.2 slides · 1 min read
- 17National and Regional FrameworksAt its heart, GDPR consists of rules, regulations and penalties that provide European citizens more control over their own personal data.4 slides · 2 min read
- 18Is Privacy Shield DeadAs the GDPR was being published, the United States developed concepts known as Safe Harbor and the Privacy Shield, which were voluntary for U.S. organizations wishing to do business with EU persons or organizations. In essence it provided an early on-ramp…2 slides · 1 min read
- 19GDPR Privacy PrinciplesThe GDPR codifies these concepts of privacy (in its Article 5) into six broad principles regarding the use of personal data.3 slides · 1 min read
- 20Cybercrimes and Data BreachesData breaches happen all the time. Some breaches are caused by the negligence of internal users, while other breaches are realized due to malicious activities and cybercrime. Some data breaches have dire repercussions. And unfortunately, jurisdiction by…5 slides · 2 min read
- 21Definitions Related to RiskFor purposes of this module, let's use the following definitions for some key risk terms.3 slides · 1 min read
- 22When to Use Which Risk Assessment TechniqueUse qualitative methods for general, subjective analysis, and use quantitative methods when precise data allows for detailed measurement and analysis of financial impact. For most of the last 50 years, the choice of when to use which assessment technique…3 slides · 2 min read
- 23Monitoring and MeasurementSelecting, installing, and making good operational use out of all security controls - including those focused on safety, privacy, and all other aspects of information security - are part of fulfilling the organization's due care responsibilities.3 slides · 2 min read
- 24Risks Associated with Hardware, Software, and ServicesOrganizations cannot operate solely alone; there are many dependencies and interconnections that organizations have with their entire supply chain, which includes suppliers, vendors, contractors and customers.2 slides · 1 min read
- 25Planning Factors for Business Continuity and Disaster RecoveryCreating a business continuity and disaster recovery plan involves identifying critical operations, assessing risks, defining recovery strategies, and establishing procedures to maintain or quickly resume essential services.5 slides · 4 min read
- 26Threat ModelingIn some threat models used for specific targets (systems/applications, instead of the overall organization), other elements can be used (mostly in addition to, not in lieu of, the abstract); incorporating those same threat modeling techniques into the…6 slides · 2 min read
- 27Privacy Concepts Continually and Rapidly EvolvePrivacy regulations and expectations shift frequently, driven by technological advances, legal challenges, and changing views on how personal data should be handled and safeguarded.5 slides · 3 min read
- 28Identify and Prioritize Business Continuity RequirementsBusiness continuity requirements are the essential tasks and systems an organization needs to keep running or restore quickly to minimize disruption during and after an unexpected incident.3 slides · 2 min read
- 29Four Perspectives What is at RiskRisk management should be approached by evaluating assets, anticipating outcomes, analyzing processes, and understanding vulnerabilities and threats that could impact security objectives.4 slides · 3 min read
- 30Continuous Improvement (Risk Maturity Modeling)Continuous improvement and risk maturity models help organizations strengthen risk management practices by identifying gaps, tracking progress, and guiding measurable enhancements over time.3 slides · 2 min read
- 31Third-Party Assessments and MonitoringIt is imperative that an organization apply the same risk-management methodologies and perspectives to its supply chain as the organization did for its own internal operations.3 slides · 2 min read
- 32Compliance Policy RequirementsOrganizations should use acceptable use policies (AUPS) for all personnel.4 slides · 1 min read
- 33Control Selection (Security and Privacy)When selecting security and privacy controls, an organization can use various frameworks. According to NIST SP 800-37, Revision 2, the Select Step of the Risk Management Framework, there are two approaches that can be used for the initial selection of…4 slides · 1 min read
- 34Service-Level RequirementsClients define service-level requirements by specifying the performance and quality standards a service must meet, forming the basis for service-level agreements.5 slides · 2 min read
- 35Privacy FrameworksAn organization might implement a privacy framework to be used by the organization. It is a set of privacy principles, standards, and or guidelines.4 slides · 2 min read
- 36Minimum Security RequirementsMeeting minimum security requirements at every level demands consistent enforcement of policies, controls, and protections across systems, applications, data, and organizational processes.3 slides · 1 min read
- 37The Right to Be ForgottenThe right to be forgotten is part of the EU's General Data Protection Regulation, allowing individuals to request deletion of their personal data.4 slides · 2 min read
- 38Data LocalizationLocal data protection laws govern how organizations collect, use, and share personal data, often requiring transparency, consent, security measures, and individual rights.4 slides · 2 min read
- 39National and Regional Framework ExamplesOrganizations handling and processing user data must comply with regional data privacy laws protecting data against inappropriate use.5 slides · 4 min read
- 40Data PortabilityData portability is a critical capability in modern IT environments, enabling seamless data movement across platforms and supporting technical operations and regulatory compliance.2 slides · 1 min read
- 41Privacy ProtectionPrivacy protection for data is guided by OECD privacy principles, which focus on user consent, transparency, and ensuring secure handling of personal information, particularly during cross-border transfers.3 slides · 1 min read
- 42Privacy Policy RequirementsPrivacy policies must clearly outline data collection, use, sharing, and retention practices while aligning with legal requirements and supporting controls that protect personal information throughout its life cycle.3 slides · 1 min read
- 43Program Effectiveness EvaluationDue care requires us to provide effective education, training, and awareness to employees; due diligence requires us to evaluate the effectiveness of that training.5 slides · 2 min read
- 44Import and Export ControlsImport and export controls require navigating international agreements and complying with national laws to regulate the cross-border flow of sensitive data, software, and technology.4 slides · 3 min read
- 45Organizational Governance ProcessesOrganizational governance includes strategic planning, risk management, compliance, performance monitoring, and decisionmaking processes to ensure accountability and alignment with goals.6 slides · 3 min read
- 46Methods and Techniques to Present Awareness and TrainingCybersecurity awareness and training are best supported through regular sessions, real-world simulations, clear policies, and engaging, role-specific content that highlights threats and safe practices.4 slides · 3 min read
- 47Organizational Code of EthicsAn organizational code of ethics defines acceptable and prohibited behaviors, and helps ensure compliance with laws and regulations, fostering a responsible and accountable environment.2 slides · 2 min read
- 48The Legal EnvironmentThe legal environment dictates compliance requirements, with leadership responsible for ensuring adherence, while auditing verifies alignment with regulations and standards.3 slides · 2 min read
- 49Case Study Marriott Data BreachThe Marriott data breach in 2018 was a significant cyber incident that exposed the personal information of approximately 500 million guests. The breach, attributed to unauthorized access within the Starwood guest reservation database, compromised sensitive…4 slides · 2 min read
- 50ISC2 Code of Professional EthicsISC2 members are expected to behave professionallly and personally in accordance with the high standards set by ISC2. These are set in the Code of Ethics, which can be found on the ISC2 Ethics website: www.isc2.org/Ethics4 slides · 1 min read
- 51Conutermeasure Selection and ImplementationCountermeasures are chosen by balancing effectiveness, cost, and potential impact to optimize security while minimizing expenses and disruptions.3 slides · 1 min read
- 52Professional Ethics 1MDBThis is a case study of a real-life situation that demonstrates how security concepts apply not just to your professional life, but to the world stage.6 slides · 2 min read
