Risk Analysis: SLE, ARO and ALE
Quantitative risk analysis puts a currency figure on risk so that a control can be judged on whether it pays for itself. The whole model rests on three numbers you build up in order: what one incident costs, how often it happens in a year, and therefore what it costs you annually. Once you can express a risk as an annual figure, comparing it against the annual cost of a safeguard becomes simple arithmetic, and that comparison is the entire point of the exercise.
Exam tip. Read the frequency wording very carefully. Once every twenty years is an ARO of 0.05, and candidates lose these questions by using 20 instead. Also watch for the trap where the safeguard reduces but does not eliminate the risk, which means you must subtract the remaining ALE, not the original one.
Risk Treatment, Risk Appetite and Residual Risk
Once a risk has been analyzed, someone has to decide what to do about it, and there are only a handful of legitimate answers. You can reduce the risk with controls, hand the financial consequence to someone else, stop doing the activity entirely, or knowingly live with it. What you can never do is ignore it, because ignoring a known risk is negligence rather than a risk decision. Whatever you choose, some risk always remains afterward, and senior management owns that remainder.
Exam tip. If an answer option says the risk was ignored or that residual risk was eliminated, it is wrong. Also remember who accepts risk: the exam wants senior management or the business owner, never the security practitioner, because accepting risk is a business decision and not a technical one.
Business Impact Analysis and Recovery Objectives
The Business Impact Analysis is the step that turns continuity planning from guesswork into something defensible. It identifies critical business processes, works out what it actually costs the organization when each one stops, and from that derives how quickly each must come back and how much data it can afford to lose. Every recovery strategy you later choose, and every pound you spend on redundancy, has to trace back to a number the BIA produced. Note the direction of travel: the BIA measures business impact first, and technology priorities fall out of it, not the other way around.
Exam tip. The single most common trap is swapping RTO and RPO. If the question talks about how much data can be lost, it is RPO and the fix is more frequent backups or replication. If it talks about how long the outage can last, it is RTO and the fix is a faster recovery site. And RTO plus WRT can never exceed MTD.
Security Governance Documents: Policies, Standards, Procedures and Guidelines
Security governance is expressed through a hierarchy of documents, and the exam expects you to know exactly which one does what. A policy states management intent at a high level and is mandatory. Standards make that intent specific and are also mandatory. Procedures give the step-by-step instructions. Guidelines offer recommended practice and are the only tier that is optional. Getting the mandatory versus discretionary distinction right, and knowing that everything hangs off a policy signed by senior management, answers a surprising number of questions on its own.
Exam tip. Watch the wording of the stem. Should and recommended point to a guideline, must and shall point to a policy or standard. If a document names a specific product, version or key length, it is a standard, and if the question asks what a security program most needs to succeed, the answer is senior management support.
Due Care, Due Diligence and the ISC2 Code of Ethics
Due care and due diligence sound interchangeable in everyday speech, and the exam relies on the fact that they are not. Due diligence is the investigating: researching risks, evaluating vendors, understanding what a reasonable organization in your position would be expected to know. Due care is the doing: actually implementing and maintaining the controls that follow from that knowledge. Failing either one is negligence, which is precisely the exposure that legal concepts like the prudent person rule are there to test. Alongside that sits the ISC2 Code of Ethics, whose four canons must be applied in their published order.
Exam tip. Ethics questions are almost always solved by canon order. When an answer pits your employer's interests against public safety or the profession's integrity, protecting society wins. For due care versus due diligence, ask whether the described activity is finding out or carrying out.
Personnel Security and Third-Party Risk
People are the control surface that technology cannot cover, so a large part of risk management is administrative rather than technical. Hiring, role design, and termination all carry specific controls the exam expects you to name, and most of them exist to make fraud require collusion rather than a single dishonest person. The same logic extends outward to suppliers: bringing a third party inside your processes imports their risk, and the only real defenses are contractual language agreed before the work starts and assessment that continues after it.
Exam tip. Job rotation and mandatory vacation are detective controls, not preventive ones, and that distinction is tested directly. On termination questions the first action is always to disable the accounts, before the conversation and before collecting equipment, and for supplier questions the control the exam wants is contractual language settled in advance.
Law, Intellectual Property and Privacy Obligations
CISSP is an international exam, so it tests legal concepts rather than the statutes of any one country. You need to recognize the categories of law, know which form of intellectual property protection fits which asset, and understand the privacy principles that modern data protection regimes share. The practical thread running through all of it is that legal exposure is an organizational risk like any other, and the security professional's job is to know which obligations attach to the data being handled before it is collected, not after a regulator asks.
Exam tip. Software is the classic trap. The source code is protected by copyright, the algorithm it implements may be patentable, the product name is a trademark, and if you never publish any of it you are relying on trade secret. Match the answer to which aspect of the asset the question is describing.