Security and Risk Management

Worth 16% of the ISC2 CISSP (CISSP) exam. CertClue has 59 questions on this objective.

What this objective covers

Risk Analysis: SLE, ARO and ALE

Quantitative risk analysis puts a currency figure on risk so that a control can be judged on whether it pays for itself. The whole model rests on three numbers you build up in order: what one incident costs, how often it happens in a year, and therefore what it costs you annually. Once you can express a risk as an annual figure, comparing it against the annual cost of a safeguard becomes simple arithmetic, and that comparison is the entire point of the exercise.

Exam tip. Read the frequency wording very carefully. Once every twenty years is an ARO of 0.05, and candidates lose these questions by using 20 instead. Also watch for the trap where the safeguard reduces but does not eliminate the risk, which means you must subtract the remaining ALE, not the original one.

Risk Treatment, Risk Appetite and Residual Risk

Once a risk has been analyzed, someone has to decide what to do about it, and there are only a handful of legitimate answers. You can reduce the risk with controls, hand the financial consequence to someone else, stop doing the activity entirely, or knowingly live with it. What you can never do is ignore it, because ignoring a known risk is negligence rather than a risk decision. Whatever you choose, some risk always remains afterward, and senior management owns that remainder.

Exam tip. If an answer option says the risk was ignored or that residual risk was eliminated, it is wrong. Also remember who accepts risk: the exam wants senior management or the business owner, never the security practitioner, because accepting risk is a business decision and not a technical one.

Business Impact Analysis and Recovery Objectives

The Business Impact Analysis is the step that turns continuity planning from guesswork into something defensible. It identifies critical business processes, works out what it actually costs the organization when each one stops, and from that derives how quickly each must come back and how much data it can afford to lose. Every recovery strategy you later choose, and every pound you spend on redundancy, has to trace back to a number the BIA produced. Note the direction of travel: the BIA measures business impact first, and technology priorities fall out of it, not the other way around.

Exam tip. The single most common trap is swapping RTO and RPO. If the question talks about how much data can be lost, it is RPO and the fix is more frequent backups or replication. If it talks about how long the outage can last, it is RTO and the fix is a faster recovery site. And RTO plus WRT can never exceed MTD.

Security Governance Documents: Policies, Standards, Procedures and Guidelines

Security governance is expressed through a hierarchy of documents, and the exam expects you to know exactly which one does what. A policy states management intent at a high level and is mandatory. Standards make that intent specific and are also mandatory. Procedures give the step-by-step instructions. Guidelines offer recommended practice and are the only tier that is optional. Getting the mandatory versus discretionary distinction right, and knowing that everything hangs off a policy signed by senior management, answers a surprising number of questions on its own.

Exam tip. Watch the wording of the stem. Should and recommended point to a guideline, must and shall point to a policy or standard. If a document names a specific product, version or key length, it is a standard, and if the question asks what a security program most needs to succeed, the answer is senior management support.

Due Care, Due Diligence and the ISC2 Code of Ethics

Due care and due diligence sound interchangeable in everyday speech, and the exam relies on the fact that they are not. Due diligence is the investigating: researching risks, evaluating vendors, understanding what a reasonable organization in your position would be expected to know. Due care is the doing: actually implementing and maintaining the controls that follow from that knowledge. Failing either one is negligence, which is precisely the exposure that legal concepts like the prudent person rule are there to test. Alongside that sits the ISC2 Code of Ethics, whose four canons must be applied in their published order.

Exam tip. Ethics questions are almost always solved by canon order. When an answer pits your employer's interests against public safety or the profession's integrity, protecting society wins. For due care versus due diligence, ask whether the described activity is finding out or carrying out.

Personnel Security and Third-Party Risk

People are the control surface that technology cannot cover, so a large part of risk management is administrative rather than technical. Hiring, role design, and termination all carry specific controls the exam expects you to name, and most of them exist to make fraud require collusion rather than a single dishonest person. The same logic extends outward to suppliers: bringing a third party inside your processes imports their risk, and the only real defenses are contractual language agreed before the work starts and assessment that continues after it.

Exam tip. Job rotation and mandatory vacation are detective controls, not preventive ones, and that distinction is tested directly. On termination questions the first action is always to disable the accounts, before the conversation and before collecting equipment, and for supplier questions the control the exam wants is contractual language settled in advance.

Law, Intellectual Property and Privacy Obligations

CISSP is an international exam, so it tests legal concepts rather than the statutes of any one country. You need to recognize the categories of law, know which form of intellectual property protection fits which asset, and understand the privacy principles that modern data protection regimes share. The practical thread running through all of it is that legal exposure is an organizational risk like any other, and the security professional's job is to know which obligations attach to the data being handled before it is collected, not after a regulator asks.

Exam tip. Software is the classic trap. The source code is protected by copyright, the algorithm it implements may be patentable, the product name is a trademark, and if you never publish any of it you are relying on trade secret. Match the answer to which aspect of the asset the question is describing.

Practice questions

Free, with the answer and the reasoning. No account needed.

1. Ransomware encrypts a manufacturing company's production scheduling files. Investigators confirm no data left the network and no records were altered before encryption. Which element of the CIA triad has been MOST directly compromised?

  • A. Confidentiality, because the attacker gained access to sensitive files
  • B. Integrity, because the files can no longer be trusted as accurate
  • C. Availability, because authorized users can no longer reach the data they needcorrect
  • D. Non-repudiation, because the source of the change cannot be proven

Encryption without a key turns useful data into noise for the people who own it, and that is availability failing in its purest form: the information still exists, it is simply out of reach when the business needs it. Confidentiality is tempting because an attacker touched the files, but the investigation is explicit that nothing was exfiltrated or read out, and mere presence on a system is not a disclosure. Integrity does not fit either, since the underlying records were not modified before being encrypted, and the plaintext returns unchanged if the key is recovered. Non-repudiation concerns proving who performed an action, which is not what the scenario is asking about at all. Ransomware is the classic availability attack, even though it uses a confidentiality tool to do its work.

2. A board states that the company is willing to take on significant risk to enter new markets quickly, but that any single initiative may not exceed a defined loss threshold before it must be escalated. Which pair of concepts does this statement describe?

  • A. Residual risk and total risk
  • B. Inherent risk and control risk
  • C. Risk avoidance and risk acceptance
  • D. Risk appetite and risk tolerancecorrect

Risk appetite is the broad amount of risk an organization is willing to take on in pursuit of its objectives, and the board's willingness to move fast into new markets is that appetite stated plainly, while the defined loss threshold on a single initiative is risk tolerance, the acceptable variation before escalation is required. Residual and total risk describe how much risk exists before and after controls, which is a measurement idea rather than a statement of willingness. Inherent and control risk come from the audit vocabulary and describe sources of risk in an assurance opinion, not a board's strategic posture. Avoidance and acceptance are individual responses to specific risks, whereas the board is setting the boundaries within which those responses will later be chosen. Appetite is the direction of travel, tolerance is the guardrail on the road.

Work the whole objective

The full ISC2 CISSP bank, the study notes behind these summaries, and a readiness score that tells you which objective to revise next. Free, no paid tier.

Take the free ISC2 CISSP practice test

The other ISC2 CISSP objectives