Domain 1 is the broadest domain on the CISSP exam and carries the highest weight (16%). It covers the governance, legal, and risk-management foundation that every other domain sits on top of: confidentiality/integrity/availability, security governance principles, compliance and legal/regulatory requirements, professional ethics, business continuity concepts, personnel security policies, and risk management frameworks.
Because it's foundational rather than technical, this domain is deceptively hard to study for: the questions are scenario-based and test judgment ("what should the CISO do first") more than memorization. Candidates who treat it as a vocabulary list tend to underperform relative to candidates who understand the reasoning behind each framework.
CIA Triad
Confidentiality, Integrity, Availability: the three properties every control ultimately protects. Most exam scenarios ask which property is most at risk in a given situation, not just to define the terms.
Due care vs. due diligence
Due care is acting the way a reasonable person would (ongoing, action-oriented); due diligence is investigating before acting (research, one-time). Confused constantly on the exam.
Risk management lifecycle
Identify, assess, respond (avoid, mitigate, transfer, accept), then monitor. Know that risk can never be reduced to zero, only to an acceptable residual level.
Quantitative vs. qualitative risk analysis
Quantitative uses dollar figures (SLE, ARO, ALE); qualitative uses relative ratings (high/medium/low). Know the SLE = Asset Value × Exposure Factor and ALE = SLE × ARO formulas cold.
Security governance frameworks
COBIT, ISO/IEC 27001, and NIST CSF: know what each is for (IT governance, ISMS certification, and a risk-based framework, respectively), not just that they exist.
Third-party governance
SLAs, vendor risk assessments, and right-to-audit clauses: the exam expects you to know an organization remains accountable for a vendor's failures, even when the vendor caused the incident.
Policy vs. standard vs. procedure vs. guideline
Policy is high-level mandatory intent. Standard is a mandatory specific requirement. Procedure is mandatory step-by-step instructions. Guideline is recommended, not mandatory. Ordering questions ("most general to most specific") are common.
Risk acceptance vs. risk transference
Accepting risk means doing nothing further and living with the outcome; transferring risk (e.g., insurance) still leaves the org exposed operationally even though the financial impact shifts.
Prudent person rule vs. due diligence
These get used almost interchangeably in casual writing, but the exam treats "prudent person" as the legal standard due care is measured against.
Practice D1 questions with instant feedback, free to start, no card required.
Start Free