Skip to content
ISC2 CISSP · CISSP

CISSP Domain 1: Security and Risk Management

Domain 1.0: Security and Risk Management · 16% of the exam

The largest domain on the CISSP exam and the conceptual foundation of the whole certification: all 12 objectives (1.1–1.12), from professional ethics and security governance through legal and regulatory obligation, business continuity requirements, personnel security, the risk management vocabulary the rest of the exam assumes, threat modeling, supply chain risk and the awareness program that makes any of it real.

12 modules · 60 topics 192-page PDF 120 practice questions
Read a free sample By the author of 51 Pluralsight courses · 4.6/5 from 2,007 ratings
Best value
$29/ month

All study guides, current and every new one.

or own the whole exam
$129one-time · all 8 domains
or just this guide
$24.95one-time · lifetime access
  • Interactive online guide
  • Downloadable PDF
  • Lifetime updates
  • 30-day money-back guarantee

Secure checkout via Stripe · no account needed · instant access

16% of your exam score

Domain 1.0 is worth 16% of the CISSP exam. Walk in having mastered it, not hoping it doesn't come up.

Every objective, nothing extra

Built line by line from the official ISC2 CISSP objectives 1.1–1.12: 60 in-depth topics with worked scenarios and exam tips, in a 192-page guide you'll actually finish.

120 exam-style questions

Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.

The cert that changes what you're paid

CISSP is the management-track credential for security: five years of experience to hold it, eight domains wide, and the one most senior security job descriptions name by itself.

Serving, transitioning, or a military spouse?

CISSP appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →

Read a real excerpt, free

This is the actual opening of Module 1.1, Professional ethics, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.

Objective 1.1

Understand, adhere to, and promote professional ethics

The ISC2 Code of Professional Ethics, the four canons and the order they are applied in, who may bring a complaint, and how organizational codes sit alongside it.

Ines Okafor had been Chief Information Security Officer of Aurora Logistics for nine days when the first genuinely difficult decision arrived, and it was not a technical one. A penetration test of the customs-clearance platform — the system that moves 40,000 shipments a day through eleven jurisdictions — had found an authentication flaw that let any authenticated freight customer read any other customer's manifests. The Chief Operating Officer wanted the finding kept inside the company until after the Q3 results. The pen-test firm's lead had already told Ines she considered the exposure reportable.

Nothing in that situation is resolved by knowing how OAuth works. It is resolved by knowing which obligation outranks which — and that is precisely why ISC2 puts ethics first, and why the exam asks about it far more often than its share of the outline suggests.

Exam focus · Order is the answer

Ethics questions on this exam are nearly always conflicts: your employer wants one thing, the public interest another; a client instructs you to do something questionable; a colleague asks you to cover a mistake. The technique is always the same — identify which canons are in play, then apply the lower-numbered canon first. If you can recite the canons in order, you can answer these questions without agonising over them.

The ISC2 Code of Professional Ethics

Every ISC2 certification holder agrees to the code as a condition of certification. It is deliberately short: a preamble and four canons. The preamble establishes that the safety and welfare of society and the common good, duty to principals, and duty to one another require adherence to the highest ethical standards of behaviour, and that strict adherence is a condition of certification.

#CanonWhat it governs in practice
1Protect society, the common good, necessary public trust and confidence, and the infrastructure.The public interest. Safety, critical infrastructure, the trustworthiness of systems people depend on. This one wins every conflict it enters.
2Act honorably, honestly, justly, responsibly, and legally.Your own conduct. Do not lie, do not break the law, do not misrepresent your qualifications or your findings — even when instructed to.
3Provide diligent and competent service to principals.Duty to employers and clients. Competence, confidentiality of their information, avoiding conflicts of interest, not taking work you cannot do.
4Advance and protect the profession.The profession itself. Do not certify unqualified people, do not associate the credential with disreputable practice, mentor honestly.
Why the order matters more than the wording

The canons are listed in order of precedence. When two conflict, the lower number governs. So a duty to your employer (canon 3) never justifies concealing a danger to the public (canon 1), and it never justifies an illegal act (canon 2). Candidates lose these questions by reasoning from loyalty rather than from order.

The guide continues for 192 pagesKeep reading: unlock the full guide

Not ready to buy? Read it later.

We'll email you a free sample of this guide as a PDF, no purchase needed.

Try 3 sample questions

Pulled straight from the guide's 120-question bank. Tap an answer for instant feedback and the explanation.

From module 1.1 · Professional ethics

  1. 1. An employer instructs a CISSP to withhold a security finding that exposes customer data, until after a financial announcement. Which canon governs the response?

From module 1.2 · Core security concepts

  1. 1. Which property allows a recipient to prove to a third party that a specific sender produced a message?

From module 1.3 · Security governance principles

  1. 1. Who holds ultimate accountability for an organization's information security programme?

117 more questions like these are waiting inside.

What's inside

  • 60 in-depth topics across 12 modules, mapped to objectives 1.1–1.12
  • 120 exam-style practice questions with instant feedback
  • Full answer key explaining why every distractor is wrong
  • The ISC2 canons in order: the answer to most ethics questions
  • The full ALE arithmetic, worked, including safeguard value
  • Complete CISSP acronym & key-term reference
  • 192-page downloadable PDF for offline study and printing
  • Lifetime updates as the exam evolves

The modules, mapped to the objectives

  1. 1.1

    Professional ethics

    Understand, adhere to, and promote professional ethics

    10 Qs
    ISC2 Code of Professional EthicsThe four canons & their orderEthics complaint eligibilityOrganizational code of ethicsRFC 1087 & computing ethicsWhistleblowing vs. due process
  2. 1.2

    Core security concepts

    Understand and apply security concepts

    10 Qs
    Confidentiality, integrity, availabilityAuthenticity & nonrepudiationDAD triadIAAA sequenceDefence in depth & layeringBalancing the pillars against business need
  3. 1.3

    Security governance principles

    Evaluate, apply, and sustain security governance principles

    10 Qs
    Alignment to business strategyAcquisitions, divestitures & committeesRoles: owner, custodian, CISO, auditorISO, NIST, COBIT, SABSA, PCI, FedRAMPDue care vs. due diligenceSustaining governance over time
  4. 1.4

    Legal, regulatory & compliance

    Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context

    10 Qs
    Criminal, civil & administrative lawCopyright, patent, trademark, trade secretEAR, ITAR & WassenaarTransborder data flow & adequacyGDPR, CCPA/CPRA, PIPL, POPIAContractual vs. statutory obligation
  5. 1.5

    Investigation types

    Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards)

    10 Qs
    Administrative investigationsCriminal & the reasonable-doubt barCivil investigations & eDiscoveryRegulatory investigationsIndustry standards (e.g. PFI)Preserving the evidentiary option
  6. 1.6

    Policy, standards, procedures & guidelines

    Develop, document, and implement security policy, standards, procedures, and guidelines

    10 Qs
    Policy, standard, procedure, guidelineBaselines & minimum configurationMandatory vs. discretionaryException handling & risk acceptanceDocument lifecycle & reviewTechnology-neutral policy writing
  7. 1.7

    Business continuity requirements

    Identify, analyze, assess, prioritize, and implement Business Continuity (BC) requirements

    10 Qs
    BC lifecycle & management supportBusiness impact analysis (BIA)MTD, RTO, RPO, WRTMTBF & MTTRCritical process prioritizationExternal dependencies
  8. 1.8

    Personnel security

    Contribute to and enforce personnel security policies and procedures

    10 Qs
    Screening & role-proportionate vettingNDA, AUP & IP assignmentOnboarding, transfer, terminationPrivilege creepHostile termination sequenceContractor & third-party controls
  9. 1.9

    Risk management

    Understand and apply risk management concepts

    10 Qs
    Threat, vulnerability, risk, exposureSLE, ARO, ALE & safeguard valueQualitative vs. quantitative analysisMitigate, transfer, avoid, acceptControl types & functionsResidual risk & risk appetite
  10. 1.10

    Threat modeling

    Understand and apply threat modeling concepts and methodologies

    10 Qs
    Attacker-centric vs. asset-centricSTRIDE & its property mappingPASTA's seven stagesDREAD scoringAttack treesData flow diagrams & trust boundaries
  11. 1.11

    Supply chain risk management

    Apply Supply Chain Risk Management (SCRM) concepts

    10 Qs
    Tampering, counterfeits & implantsThird-party assessment & monitoringMinimum security & service level requirementsSilicon root of trustPhysically unclonable functionsSoftware bill of materials (SBOM)
  12. 1.12

    Security awareness & training

    Establish and maintain a security awareness, education, and training program

    10 Qs
    Awareness vs. training vs. educationRole-based contentPhishing simulation & social engineeringSecurity championsGamificationEffectiveness measurement
Chris Rees

About the author

Chris Rees

Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.

More about Chris
All 8 CISSP domains

Sitting the whole exam? Get the Complete CISSP Collection.

Every domain of the exam, including this guide, for $129, one time.

See everything inside

Questions, answered

Do I need an account to buy?

No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.

Is this up to date with the real CISSP exam?

Yes. The guide is mapped module-by-module to the official ISC2 CISSP objectives (1.1–1.12), and lifetime updates are included, so as the exam evolves your guide does too.

What exactly do I get?

Instant access to the interactive online guide with all 120 practice questions, plus a 192-page PDF you can download, print, and keep forever.

Do I need the other domains too?

This guide covers Domain 1.0 (16% of the exam). To prepare for the whole exam, the Complete CISSP Collection bundles all 8 domains for $129, less than the price of three guides.

What if it isn't for me?

Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.

Who wrote it?

Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.

Be ready for 16% of the exam, for $24.95

Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.

Get the guide

Share this guide