Risk Management Process
Risk management is a repeatable cycle: you identify risk, assess it, treat it, and then keep monitoring it. Which response you choose comes from the likelihood and the impact, guided by your risk appetite. You are never going to eliminate risk entirely, so the goal is getting it down to a residual level you can accept.
Exam tip. You cannot cost-effectively eliminate all risk. Reduce it to a residual level inside your risk appetite, then formally accept what is left.
Risk Calculations (SLE, ALE, ARO)
Quantitative risk analysis puts risk into money terms, which is what lets you justify spending on a control. The formulas chain together: SLE = AV x EF, ARO is how many events you expect per year, and ALE = SLE x ARO. A control is justified when the reduction in ALE is worth more than the control costs.
Exam tip. Convert once every N years into a fractional ARO, 1 divided by N, before you multiply anything. And do not mistake the gross ALE reduction for the net benefit: you still have to subtract the cost of the control.
Business Continuity and Disaster Recovery
Business continuity is about keeping the whole organization running through a disruption. Disaster recovery is the IT-focused piece inside it. The business impact analysis is what drives your recovery objectives, and none of it is worth much unless the plans are tested and kept current.
Exam tip. Disaster recovery is the IT focus, but continuity also has to plan for people, facilities, and communications. Plans that are not tested and maintained fail when a real disaster hits.
Data Classification and Governance
Classification labels data by how sensitive it is, so the controls you apply scale with it. Governance defines the accountability around that: who owns the data versus who looks after it, how it is classified, how quality and retention are handled, and how it all gets enforced. Classification only pays off when the labels drive real protections.
Exam tip. Classification pays off at the point where labels drive automated controls. Remember the split: the data owner is the business role deciding classification and access, and the custodian is the IT role handling storage and backups.
Privacy Regulations (GDPR, CCPA, HIPAA, PCI-DSS)
Privacy and compliance regulations each govern a specific type of data or a specific population, so most of the work is matching the data in the scenario to the right law. For GDPR in particular, know its extraterritorial scope, its roles, the rights it grants, and the 72-hour breach notification.
Exam tip. GDPR applies extraterritorially if you process the data of EU residents or target them. Remember the 72-hour breach notification, and match each type of data to the specific regulation that covers it.
Security Policies, Standards, Procedures, and Guidelines
Governance documents form a hierarchy that runs from high-level intent down to specific implementation. You need the distinctions between the levels, the common documents such as an AUP or a clean desk policy, and the personnel controls that cut down on fraud and error.
Exam tip. If it is mandatory and specific, it is a standard. If it is only recommended, it is a guideline. Step-by-step means procedure, and high-level intent means policy.
Third-Party and Vendor Risk Management
Every vendor extends your attack surface, which makes third-party risk management continuous rather than a one-time gate. You vet them before onboarding, which is due diligence, and you keep monitoring them for the length of the relationship. Contracts are what turn your expectations into obligations you can actually enforce.
Exam tip. Third-party risk is continuous, not one-time. And you often stay accountable to your own customers even when it is a vendor that got breached, which is why you require breach notification and audit rights.
Security Awareness and Training Programs
People are a primary target, which makes awareness training the frontline defense against social engineering. The programs that work are role-based, measured by behavior rather than attendance, backed by a reporting channel that is easy to use, and supported by a blameless culture.
Exam tip. Punitive approaches suppress reporting. Measure outcomes, click rate down and reporting up, rather than activity. Making reporting easy is what turns employees into a detection asset.