CISSP Domain 1: Security and Risk Management
Domain 1.0: Security and Risk Management · 16% of the exam
The largest domain on the CISSP exam and the conceptual foundation of the whole certification: all 12 objectives (1.1–1.12), from professional ethics and security governance through legal and regulatory obligation, business continuity requirements, personnel security, the risk management vocabulary the rest of the exam assumes, threat modeling, supply chain risk and the awareness program that makes any of it real.
All study guides, current and every new one.
- Interactive online guide
- Downloadable PDF
- Lifetime updates
- 30-day money-back guarantee
Secure checkout via Stripe · no account needed · instant access
16% of your exam score
Domain 1.0 is worth 16% of the CISSP exam. Walk in having mastered it, not hoping it doesn't come up.
Every objective, nothing extra
Built line by line from the official ISC2 CISSP objectives 1.1–1.12: 60 in-depth topics with worked scenarios and exam tips, in a 192-page guide you'll actually finish.
120 exam-style questions
Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.
The cert that changes what you're paid
CISSP is the management-track credential for security: five years of experience to hold it, eight domains wide, and the one most senior security job descriptions name by itself.
Serving, transitioning, or a military spouse?
CISSP appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →
Read a real excerpt, free
This is the actual opening of Module 1.1, Professional ethics, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.
Understand, adhere to, and promote professional ethics
The ISC2 Code of Professional Ethics, the four canons and the order they are applied in, who may bring a complaint, and how organizational codes sit alongside it.
Ines Okafor had been Chief Information Security Officer of Aurora Logistics for nine days when the first genuinely difficult decision arrived, and it was not a technical one. A penetration test of the customs-clearance platform — the system that moves 40,000 shipments a day through eleven jurisdictions — had found an authentication flaw that let any authenticated freight customer read any other customer's manifests. The Chief Operating Officer wanted the finding kept inside the company until after the Q3 results. The pen-test firm's lead had already told Ines she considered the exposure reportable.
Nothing in that situation is resolved by knowing how OAuth works. It is resolved by knowing which obligation outranks which — and that is precisely why ISC2 puts ethics first, and why the exam asks about it far more often than its share of the outline suggests.
Ethics questions on this exam are nearly always conflicts: your employer wants one thing, the public interest another; a client instructs you to do something questionable; a colleague asks you to cover a mistake. The technique is always the same — identify which canons are in play, then apply the lower-numbered canon first. If you can recite the canons in order, you can answer these questions without agonising over them.
The ISC2 Code of Professional Ethics
Every ISC2 certification holder agrees to the code as a condition of certification. It is deliberately short: a preamble and four canons. The preamble establishes that the safety and welfare of society and the common good, duty to principals, and duty to one another require adherence to the highest ethical standards of behaviour, and that strict adherence is a condition of certification.
| # | Canon | What it governs in practice |
|---|---|---|
| 1 | Protect society, the common good, necessary public trust and confidence, and the infrastructure. | The public interest. Safety, critical infrastructure, the trustworthiness of systems people depend on. This one wins every conflict it enters. |
| 2 | Act honorably, honestly, justly, responsibly, and legally. | Your own conduct. Do not lie, do not break the law, do not misrepresent your qualifications or your findings — even when instructed to. |
| 3 | Provide diligent and competent service to principals. | Duty to employers and clients. Competence, confidentiality of their information, avoiding conflicts of interest, not taking work you cannot do. |
| 4 | Advance and protect the profession. | The profession itself. Do not certify unqualified people, do not associate the credential with disreputable practice, mentor honestly. |
The canons are listed in order of precedence. When two conflict, the lower number governs. So a duty to your employer (canon 3) never justifies concealing a danger to the public (canon 1), and it never justifies an illegal act (canon 2). Candidates lose these questions by reasoning from loyalty rather than from order.
Not ready to buy? Read it later.
We'll email you a free sample of this guide as a PDF, no purchase needed.
Try 3 sample questions
Pulled straight from the guide's 120-question bank. Tap an answer for instant feedback and the explanation.
From module 1.1 · Professional ethics
1. An employer instructs a CISSP to withhold a security finding that exposes customer data, until after a financial announcement. Which canon governs the response?
From module 1.2 · Core security concepts
1. Which property allows a recipient to prove to a third party that a specific sender produced a message?
From module 1.3 · Security governance principles
1. Who holds ultimate accountability for an organization's information security programme?
117 more questions like these are waiting inside.
What's inside
- 60 in-depth topics across 12 modules, mapped to objectives 1.1–1.12
- 120 exam-style practice questions with instant feedback
- Full answer key explaining why every distractor is wrong
- The ISC2 canons in order: the answer to most ethics questions
- The full ALE arithmetic, worked, including safeguard value
- Complete CISSP acronym & key-term reference
- 192-page downloadable PDF for offline study and printing
- Lifetime updates as the exam evolves
The modules, mapped to the objectives
- 1.110 Qs
Professional ethics
Understand, adhere to, and promote professional ethics
ISC2 Code of Professional EthicsThe four canons & their orderEthics complaint eligibilityOrganizational code of ethicsRFC 1087 & computing ethicsWhistleblowing vs. due process - 1.210 Qs
Core security concepts
Understand and apply security concepts
Confidentiality, integrity, availabilityAuthenticity & nonrepudiationDAD triadIAAA sequenceDefence in depth & layeringBalancing the pillars against business need - 1.310 Qs
Security governance principles
Evaluate, apply, and sustain security governance principles
Alignment to business strategyAcquisitions, divestitures & committeesRoles: owner, custodian, CISO, auditorISO, NIST, COBIT, SABSA, PCI, FedRAMPDue care vs. due diligenceSustaining governance over time - 1.410 Qs
Legal, regulatory & compliance
Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
Criminal, civil & administrative lawCopyright, patent, trademark, trade secretEAR, ITAR & WassenaarTransborder data flow & adequacyGDPR, CCPA/CPRA, PIPL, POPIAContractual vs. statutory obligation - 1.510 Qs
Investigation types
Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards)
Administrative investigationsCriminal & the reasonable-doubt barCivil investigations & eDiscoveryRegulatory investigationsIndustry standards (e.g. PFI)Preserving the evidentiary option - 1.610 Qs
Policy, standards, procedures & guidelines
Develop, document, and implement security policy, standards, procedures, and guidelines
Policy, standard, procedure, guidelineBaselines & minimum configurationMandatory vs. discretionaryException handling & risk acceptanceDocument lifecycle & reviewTechnology-neutral policy writing - 1.710 Qs
Business continuity requirements
Identify, analyze, assess, prioritize, and implement Business Continuity (BC) requirements
BC lifecycle & management supportBusiness impact analysis (BIA)MTD, RTO, RPO, WRTMTBF & MTTRCritical process prioritizationExternal dependencies - 1.810 Qs
Personnel security
Contribute to and enforce personnel security policies and procedures
Screening & role-proportionate vettingNDA, AUP & IP assignmentOnboarding, transfer, terminationPrivilege creepHostile termination sequenceContractor & third-party controls - 1.910 Qs
Risk management
Understand and apply risk management concepts
Threat, vulnerability, risk, exposureSLE, ARO, ALE & safeguard valueQualitative vs. quantitative analysisMitigate, transfer, avoid, acceptControl types & functionsResidual risk & risk appetite - 1.1010 Qs
Threat modeling
Understand and apply threat modeling concepts and methodologies
Attacker-centric vs. asset-centricSTRIDE & its property mappingPASTA's seven stagesDREAD scoringAttack treesData flow diagrams & trust boundaries - 1.1110 Qs
Supply chain risk management
Apply Supply Chain Risk Management (SCRM) concepts
Tampering, counterfeits & implantsThird-party assessment & monitoringMinimum security & service level requirementsSilicon root of trustPhysically unclonable functionsSoftware bill of materials (SBOM) - 1.1210 Qs
Security awareness & training
Establish and maintain a security awareness, education, and training program
Awareness vs. training vs. educationRole-based contentPhishing simulation & social engineeringSecurity championsGamificationEffectiveness measurement

About the author
Chris Rees
Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.
More about ChrisSitting the whole exam? Get the Complete CISSP Collection.
Every domain of the exam, including this guide, for $129, one time.
See everything insideQuestions, answered
Do I need an account to buy?
No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.
Is this up to date with the real CISSP exam?
Yes. The guide is mapped module-by-module to the official ISC2 CISSP objectives (1.1–1.12), and lifetime updates are included, so as the exam evolves your guide does too.
What exactly do I get?
Instant access to the interactive online guide with all 120 practice questions, plus a 192-page PDF you can download, print, and keep forever.
Do I need the other domains too?
This guide covers Domain 1.0 (16% of the exam). To prepare for the whole exam, the Complete CISSP Collection bundles all 8 domains for $129, less than the price of three guides.
What if it isn't for me?
Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.
Who wrote it?
Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.
Be ready for 16% of the exam, for $24.95
Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.
Get the guide