CISSP Domain 1: why Security and Risk Management decides more than you expect
Security and Risk Management is the heaviest CISSP domain at 16 per cent, with 12 objectives covering ethics, governance, law, investigations, policy, continuity, personnel, risk, threat modelling, supply chain and awareness. Technical candidates neglect it because it feels like paperwork. The adaptive exam keeps probing it until it has an answer.
Candidates spend their best hours on firewalls and cryptography, then meet an exam that keeps asking about policy, law and who signs off.
What the domain contains
In the outline effective 15 April 2024, Security and Risk Management carries 16 per cent of the exam, up one point from before. It has 12 objectives. Between them they cover:
- the ISC2 Code of Ethics and organisational ethics
- security governance and compliance with legal and regulatory requirements
- investigation types
- policy, standards, procedures and guidelines
- business continuity requirements
- personnel security
- risk management concepts
- threat modelling
- supply chain risk management
- security awareness, education and training
Every other domain depends on these ideas. Whether to encrypt a record, who may approve an exception and what to do first after an incident all sit on the foundations laid here.
Why technical candidates neglect it
The topics feel like paperwork. A firewall rule has an obvious right answer; a question about accountability can look vague. So candidates postpone the domain, and the adaptive exam probes it until it has seen enough.
The book describes a candidate who rated himself on all 62 objectives and gave himself 2 out of 5 on legal and regulatory issues (1.4) and on testing recovery plans (7.12). He gave both extra hours and met scenarios on both in his exam. The lesson is not about those two objectives. It is that a self-rating costs nothing, and the exam fee does not.
The ethics canons give you a compass
Every candidate must agree to the ISC2 Code of Ethics. Its four canons ask you to protect society, act honourably, provide competent service and advance the profession. Exam questions draw on the code, and a breach can cost you the credential. When a scenario asks what to do first, the canons usually point towards the answer that protects people and follows law and policy.
Risk vocabulary, with the right owner
Three questions recur, so rehearse them.
| Question | What the answer usually turns on |
|---|---|
| Who is accountable for protecting information assets? | Senior management holds final accountability |
| A high risk costs more to fix than the asset is worth, and management accepts it. Which response is that? | Risk acceptance |
| What comes first when developing a continuity plan? | A business impact analysis |
Notice that the pattern is not "memorise a definition". It is "know who decides, and know what comes first".
A four-week method
- Week one: ethics and governance. Read the canons, then write three one-line cases from your own work that test them.
- Week two: law, policy and investigations. Make a one-page map of how a policy becomes a standard, a procedure and a guideline, and who approves each.
- Week three: continuity and personnel. Draw the sequence from impact analysis to recovery strategy to plan to test.
- Week four: risk, threats and supply chain. Practise the four risk responses with real examples from a vendor or system you know.
Each week ends with ten scenario questions on that part only, and a one-sentence review of every miss.
How much time it deserves
In a 200-hour plan, the starting split gives the domain 32 hours. If your background is technical, move six or eight more here and take them from your strongest domain. The exam treats all eight as essential, and you cannot compensate for one thin domain with strength in another.
Where to go next
Rate Domain 1 first, and use the four-week method only on the objectives you score three or less.
Questions readers ask
Is Domain 1 the hardest CISSP domain?
Do I need legal knowledge for CISSP?
How many questions will come from Domain 1?
This article is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.