Security Program Management and Oversight

Worth 20% of the CompTIA Security+ (SY0-701) exam. CertClue has 234 questions on this objective.

What this objective covers

Risk Management Process

Risk management is a repeatable cycle: you identify risk, assess it, treat it, and then keep monitoring it. Which response you choose comes from the likelihood and the impact, guided by your risk appetite. You are never going to eliminate risk entirely, so the goal is getting it down to a residual level you can accept.

Exam tip. You cannot cost-effectively eliminate all risk. Reduce it to a residual level inside your risk appetite, then formally accept what is left.

Risk Calculations (SLE, ALE, ARO)

Quantitative risk analysis puts risk into money terms, which is what lets you justify spending on a control. The formulas chain together: SLE = AV x EF, ARO is how many events you expect per year, and ALE = SLE x ARO. A control is justified when the reduction in ALE is worth more than the control costs.

Exam tip. Convert once every N years into a fractional ARO, 1 divided by N, before you multiply anything. And do not mistake the gross ALE reduction for the net benefit: you still have to subtract the cost of the control.

Business Continuity and Disaster Recovery

Business continuity is about keeping the whole organization running through a disruption. Disaster recovery is the IT-focused piece inside it. The business impact analysis is what drives your recovery objectives, and none of it is worth much unless the plans are tested and kept current.

Exam tip. Disaster recovery is the IT focus, but continuity also has to plan for people, facilities, and communications. Plans that are not tested and maintained fail when a real disaster hits.

Data Classification and Governance

Classification labels data by how sensitive it is, so the controls you apply scale with it. Governance defines the accountability around that: who owns the data versus who looks after it, how it is classified, how quality and retention are handled, and how it all gets enforced. Classification only pays off when the labels drive real protections.

Exam tip. Classification pays off at the point where labels drive automated controls. Remember the split: the data owner is the business role deciding classification and access, and the custodian is the IT role handling storage and backups.

Privacy Regulations (GDPR, CCPA, HIPAA, PCI-DSS)

Privacy and compliance regulations each govern a specific type of data or a specific population, so most of the work is matching the data in the scenario to the right law. For GDPR in particular, know its extraterritorial scope, its roles, the rights it grants, and the 72-hour breach notification.

Exam tip. GDPR applies extraterritorially if you process the data of EU residents or target them. Remember the 72-hour breach notification, and match each type of data to the specific regulation that covers it.

Security Policies, Standards, Procedures, and Guidelines

Governance documents form a hierarchy that runs from high-level intent down to specific implementation. You need the distinctions between the levels, the common documents such as an AUP or a clean desk policy, and the personnel controls that cut down on fraud and error.

Exam tip. If it is mandatory and specific, it is a standard. If it is only recommended, it is a guideline. Step-by-step means procedure, and high-level intent means policy.

Third-Party and Vendor Risk Management

Every vendor extends your attack surface, which makes third-party risk management continuous rather than a one-time gate. You vet them before onboarding, which is due diligence, and you keep monitoring them for the length of the relationship. Contracts are what turn your expectations into obligations you can actually enforce.

Exam tip. Third-party risk is continuous, not one-time. And you often stay accountable to your own customers even when it is a vendor that got breached, which is why you require breach notification and audit rights.

Security Awareness and Training Programs

People are a primary target, which makes awareness training the frontline defense against social engineering. The programs that work are role-based, measured by behavior rather than attendance, backed by a reporting channel that is easy to use, and supported by a blameless culture.

Exam tip. Punitive approaches suppress reporting. Measure outcomes, click rate down and reporting up, rather than activity. Making reporting easy is what turns employees into a detection asset.

Practice questions

Free, with the answer and the reasoning. No account needed.

1. A company's legal team advises that customer data collected from European Union residents must remain stored within EU data centers due to regulatory requirements. What concept does this requirement reflect?

  • A. Non-repudiation
  • B. Data sovereigntycorrect
  • C. Data masking
  • D. Least privilege

This is data sovereignty at work: the principle that data is governed by the laws of the country or region where it's collected or stored, which is exactly why EU regulations can require it to physically stay within EU data centers. Data masking obscures values for things like testing environments and has nothing to do with where data physically resides. Least privilege limits who can access what, a completely different governance concept from storage location. Non-repudiation ensures someone can't deny having taken an action, again unrelated to physical data location. The legal requirement to keep data in a specific place is what data sovereignty is about.

2. Nexus Logistics writes a formal document, prepared before any disaster, listing who does what, contact details, and the order to restore critical systems. What is this document called?

  • A. A certificate signing request
  • B. A disaster recovery plancorrect
  • C. A penetration test report
  • D. A software bill of materials

A disaster recovery plan is written before anything happens, and that is the point: it names who does what, holds the contact details nobody will have time to hunt for mid-crisis, and sets the order in which critical systems come back. A penetration test report documents the findings of a security assessment. A software bill of materials lists the components inside a piece of software. A certificate signing request is a PKI artifact used to obtain a certificate. The document prepared in advance for restoring operations is the DR plan.

Work the whole objective

The full CompTIA Security+ bank, the study notes behind these summaries, and a readiness score that tells you which objective to revise next. Free, no paid tier.

Take the free CompTIA Security+ practice test

The other CompTIA Security+ objectives