CredenTrek
Blog / CISSP / Article 07 of 10
CISSP · Prepare

CISSP Domain 1: why Security and Risk Management decides more than you expect

By Mustafa K. Al-Dori · Checked against official documents on 11 October 2026 · 7 min read

The short answer

Security and Risk Management is the heaviest CISSP domain at 16 per cent, with 12 objectives covering ethics, governance, law, investigations, policy, continuity, personnel, risk, threat modelling, supply chain and awareness. Technical candidates neglect it because it feels like paperwork. The adaptive exam keeps probing it until it has an answer.

Candidates spend their best hours on firewalls and cryptography, then meet an exam that keeps asking about policy, law and who signs off.

What the domain contains

In the outline effective 15 April 2024, Security and Risk Management carries 16 per cent of the exam, up one point from before. It has 12 objectives. Between them they cover:

  • the ISC2 Code of Ethics and organisational ethics
  • security governance and compliance with legal and regulatory requirements
  • investigation types
  • policy, standards, procedures and guidelines
  • business continuity requirements
  • personnel security
  • risk management concepts
  • threat modelling
  • supply chain risk management
  • security awareness, education and training

Every other domain depends on these ideas. Whether to encrypt a record, who may approve an exception and what to do first after an incident all sit on the foundations laid here.

Why technical candidates neglect it

The topics feel like paperwork. A firewall rule has an obvious right answer; a question about accountability can look vague. So candidates postpone the domain, and the adaptive exam probes it until it has seen enough.

The book describes a candidate who rated himself on all 62 objectives and gave himself 2 out of 5 on legal and regulatory issues (1.4) and on testing recovery plans (7.12). He gave both extra hours and met scenarios on both in his exam. The lesson is not about those two objectives. It is that a self-rating costs nothing, and the exam fee does not.

The ethics canons give you a compass

Every candidate must agree to the ISC2 Code of Ethics. Its four canons ask you to protect society, act honourably, provide competent service and advance the profession. Exam questions draw on the code, and a breach can cost you the credential. When a scenario asks what to do first, the canons usually point towards the answer that protects people and follows law and policy.

Risk vocabulary, with the right owner

Three questions recur, so rehearse them.

Question What the answer usually turns on
Who is accountable for protecting information assets? Senior management holds final accountability
A high risk costs more to fix than the asset is worth, and management accepts it. Which response is that? Risk acceptance
What comes first when developing a continuity plan? A business impact analysis

Notice that the pattern is not "memorise a definition". It is "know who decides, and know what comes first".

A four-week method

  1. Week one: ethics and governance. Read the canons, then write three one-line cases from your own work that test them.
  2. Week two: law, policy and investigations. Make a one-page map of how a policy becomes a standard, a procedure and a guideline, and who approves each.
  3. Week three: continuity and personnel. Draw the sequence from impact analysis to recovery strategy to plan to test.
  4. Week four: risk, threats and supply chain. Practise the four risk responses with real examples from a vendor or system you know.

Each week ends with ten scenario questions on that part only, and a one-sentence review of every miss.

How much time it deserves

In a 200-hour plan, the starting split gives the domain 32 hours. If your background is technical, move six or eight more here and take them from your strongest domain. The exam treats all eight as essential, and you cannot compensate for one thin domain with strength in another.

Where to go next

Rate Domain 1 first, and use the four-week method only on the objectives you score three or less.

Questions readers ask

Is Domain 1 the hardest CISSP domain?
It is the heaviest, not necessarily the hardest. Many technical candidates find it the least familiar, because the questions turn on judgement, ownership and policy rather than configuration.
Do I need legal knowledge for CISSP?
You need to understand the main ideas of legal and regulatory compliance, intellectual property and privacy at the level the outline describes. You are not asked to be a lawyer.
How many questions will come from Domain 1?
ISC2 publishes weights, not counts. At 16 per cent it is the largest share, but the adaptive format means your own mix of questions can differ.
Sources

This article is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.