MTC Group
← All Study Guides

D1: Security and Risk Management

CISSP (ISC2) study guide

Domain 1 is the broadest domain on the CISSP exam and carries the highest weight (16%). It covers the governance, legal, and risk-management foundation that every other domain sits on top of: confidentiality/integrity/availability, security governance principles, compliance and legal/regulatory requirements, professional ethics, business continuity concepts, personnel security policies, and risk management frameworks.

Because it's foundational rather than technical, this domain is deceptively hard to study for: the questions are scenario-based and test judgment ("what should the CISO do first") more than memorization. Candidates who treat it as a vocabulary list tend to underperform relative to candidates who understand the reasoning behind each framework.

Key Concepts
  • CIA Triad

    Confidentiality, Integrity, Availability: the three properties every control ultimately protects. Most exam scenarios ask which property is most at risk in a given situation, not just to define the terms.

  • Due care vs. due diligence

    Due care is acting the way a reasonable person would (ongoing, action-oriented); due diligence is investigating before acting (research, one-time). Confused constantly on the exam.

  • Risk management lifecycle

    Identify, assess, respond (avoid, mitigate, transfer, accept), then monitor. Know that risk can never be reduced to zero, only to an acceptable residual level.

  • Quantitative vs. qualitative risk analysis

    Quantitative uses dollar figures (SLE, ARO, ALE); qualitative uses relative ratings (high/medium/low). Know the SLE = Asset Value × Exposure Factor and ALE = SLE × ARO formulas cold.

  • Security governance frameworks

    COBIT, ISO/IEC 27001, and NIST CSF: know what each is for (IT governance, ISMS certification, and a risk-based framework, respectively), not just that they exist.

  • Third-party governance

    SLAs, vendor risk assessments, and right-to-audit clauses: the exam expects you to know an organization remains accountable for a vendor's failures, even when the vendor caused the incident.

Confusable Pairs
  • Policy vs. standard vs. procedure vs. guideline

    Policy is high-level mandatory intent. Standard is a mandatory specific requirement. Procedure is mandatory step-by-step instructions. Guideline is recommended, not mandatory. Ordering questions ("most general to most specific") are common.

  • Risk acceptance vs. risk transference

    Accepting risk means doing nothing further and living with the outcome; transferring risk (e.g., insurance) still leaves the org exposed operationally even though the financial impact shifts.

  • Prudent person rule vs. due diligence

    These get used almost interchangeably in casual writing, but the exam treats "prudent person" as the legal standard due care is measured against.

Practice D1 questions with instant feedback, free to start, no card required.

Start Free