FIRST is almost never a purchase. Identify the asset and owner, assess threat × vulnerability × impact against risk appetite, then treat: mitigate (control), transfer / share (insurance or partner), avoid (stop the activity), or accept (owner signs residual risk). A policy is high-level and mandatory. A standard is mandatory and specific. A procedure is the how. A guideline is optional. Due diligence is the homework. Due care is acting on it. When ethics collide, ISC2 Canon I — society and the common good — wins.
I do not buy a control first. I frame the risk, pick a treatment the business can live with, write the right document, and leave evidence that I both knew and acted.
1. Why the manager move comes first
Interview, 40 minutes in. “We are onboarding a third-party credit-scoring model next sprint. What does the security professional do first?” The engineer answers “put a WAF in front and turn on MFA.” That is a control. It is not first.
ISC2 Domain 1 — Security and Risk Management — is the heaviest domain on the official April 2024 exam outline (16%). The outline is not asking you to configure the WAF. It is asking whether security is aligned to the business, whether you can treat risk, and whether you can prove you were not negligent.
Three reasons this domain fails people who are otherwise strong operators:
- FIRST / BEST / PRIMARY are sequencing words. They pull you one layer above the technical fix — policy, risk assessment, owner decision.
- Security enables the mission. Blocking the business is rarely the BEST answer. Secure enablement is.
- Evidence beats intent. After an incident, counsel will ask what you knew (diligence) and what you did (care). A tool with no signed residual-risk memo is a gap.
Risk — a function of threat, vulnerability, and impact on an asset. Not a synonym for “vulnerability.”
Risk appetite — how much risk the organization is willing to take to pursue its mission. Set by senior management / the board, not by the SOC.
Residual risk — what is left after treatment. Someone with authority must accept it in writing.
Data / asset owner — business role that classifies the asset and accepts residual risk. Security advises and implements.
Due diligence — research, assessment, vendor review, ongoing investigation. Knowing.
Due care — taking the reasonable actions a prudent professional would take. Doing.
2. Mental model · pillars, owners, documents
Hold three parts. Interviews fail when people treat CIA as a slogan, treat “policy” as any PDF, or let security decide residual risk.
Part 1 · five pillars, not three slogans
The official CISSP outline (objective 1.2) names confidentiality, integrity, availability, authenticity, and non-repudiation as the five pillars of information security. CIA is still the everyday triad. The 2024 wording adds the two proof pillars so you do not stop at “keep it secret, keep it intact, keep it up.”
Confidentiality
Unauthorized disclosure. Encryption, classification, need-to-know. A leak of loan files is a C failure even if the system stayed up.
Integrity
Unauthorized modification. Hashing, change control, input validation. A silently edited credit score is an I failure.
Availability
Timely, reliable access. Redundancy, backups, DDoS defense. In a hospital or OT plant, A (and safety) can outrank C.
Authenticity + non-repudiation
Authenticity proves origin or identity. Non-repudiation means the actor cannot later deny the action — typically digital signatures and audit trails, not “we have logs.”
Do not force “confidentiality always wins.” That is a study-guide shortcut, not the outline. Safety-critical and availability-critical missions flip the default. Read the scenario, not the mnemonic.
Part 2 · governance is top-down
Objective 1.3: align security to business strategy, mission, and objectives. Board and senior management set appetite and sponsor policy. The CISO designs the program. Owners classify. Custodians implement. Users comply. Bottom-up “we wrote a standard in the SOC and emailed it” is not governance.
Due care and due diligence sit in the same objective. Diligence is the investigation that tells you the plant still has unpatched HMIs. Care is the reasonable action you take once you know — patch, compensate, or get a signed exception. Knowing and doing nothing is the negligence story.
Part 3 · the document stack is not four names for one PDF
Objective 1.6 is four artifacts with different force. If the sentence is high-level and mandatory, it is a policy. If it names a specific required value, it is a standard. If it is a numbered how-to, it is a procedure. If it says “should” with no penalty, it is a guideline. A baseline is the minimum mandatory configuration — closer to a standard than to a wish.
Read top → bottom. Width = force. Magenta border = optional. If the exam sentence has SHALL plus a number, it is a standard, not a policy.
Policy is the why. Standard is the required number. Procedure is the how. Guideline is advice. Owners classify. Security implements. Residual risk is not mine to accept silently.
3. Decision flow · treat the risk
Read top → bottom. Diamond = decision. Green border = you can stay in the activity. NIST’s risk-response language is accept, avoid, mitigate, share, or transfer — “ignore” is not on the list.
NIST SP 800-39 / 800-30 / 800-37 use that five-verb list. CISSP stems still lean on the four-word CBK set mitigate, transfer, avoid, accept. Share is the close cousin of transfer (you keep some of the risk; a partner or captive takes the rest). Cybersecurity insurance is the outline’s own example under 1.9 risk response and treatment.
4. How to choose treatment and document type
Use the tables, then the numbers. Qualitative ranking is fast and good enough for most FIRST questions. Quantitative numbers show up when the stem hands you rupees or dollars and asks whether the control is worth it.
| If the ticket looks like… | Treatment | Who signs |
|---|---|---|
| We will keep doing this; a control will lower likelihood or impact. | Mitigate (apply preventive / detective / corrective controls). | Owner accepts leftover residual risk after the control. |
| A contract or policy can move impact to an insurer or processor. | Transfer or share. | Legal + owner. Insurance does not transfer reputation or regulatory duty. |
| The activity itself is the problem (shadow AI, unsanctioned region). | Avoid — do not start, or shut it down. | Business leadership. Security does not “avoid” by hiding the request. |
| After treatment, leftover risk sits inside appetite. | Accept. | Asset / data owner, or the authorizing official in an RMF shop. |
| Nobody wrote it down and the team “will watch it.” | Not a treatment. This is ignore — the trap answer. | Nobody valid. Exam: never pick ignore. |
| Wording in the document | Artifact | Force |
|---|---|---|
| “The organization shall protect customer data.” | Policy | Mandatory, high-level, management-approved. |
| “Production systems SHALL use AES-256 / 14-character passwords.” | Standard (or baseline) | Mandatory, measurable. Audit can fail you. |
| “Step 1 snapshot. Step 2 patch. Step 3 verify CVE.” | Procedure | Mandatory how-to. Operators follow it. |
| “Teams should preferably rotate keys every 90 days.” | Guideline | Advice. No penalty if skipped. |
Qualitative vs quantitative — well-known CBK math
When the stem gives money, use the classic formulas. They are well-known CBK, not an ISC2-invented “exam percentage.”
SLE = AV × EF ALE = SLE × ARO Compare: cost of control vs reduction in ALE
AV is asset value. EF is the fraction lost in one event. SLE is one-event loss. ARO is how often per year. ALE is expected yearly loss. A control that costs more than the ALE it removes is usually a poor BEST answer unless a law or contract forces it.
Qualitative work uses High / Medium / Low (or a 5×5 matrix) when you do not have clean numbers. Use it to rank. Do not pretend a red cell is a rupee figure.
Objective 1.3 and 1.9 list ISO, NIST, COBIT, SABSA, PCI, and FedRAMP as examples — plus cybersecurity insurance under treatment. Pick the framework the scenario already lives in (federal system → RMF / FedRAMP; card data → PCI as a contractual standard). Do not invent a “best framework for 40% of the exam.”
5. Runbook · Side A assess, B treat, C prove
This is not a vendor console path. It is the Domain 1 operating path you walk on a new system, a new vendor, or a new AI use case. Each side cites one primary source.
Side A · identify and assess (due diligence)
Primary source: NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments.
-
Name the asset and the owner
What is at risk — data, process, model, plant, reputation? Who in the business classifies it? If nobody will claim ownership, stop. Security does not become the owner by default.
-
Identify threats and vulnerabilities
Threat is the actor or event. Vulnerability is the weakness. A CVE with no realistic threat against this asset is not automatically high risk. Include supply-chain items the outline calls out in 1.11: counterfeit, implant, weak third-party, missing SBOM, no silicon root of trust.
-
Scope the assessment
Which systems, which data types, which jurisdictions? GDPR is in the official privacy example list. PCI is contractual, not a statute. Investigation type (objective 1.5) matters later if this becomes an incident — administrative, criminal, civil, regulatory, or industry-standard — but you do not pick a lawyer before you have a risk picture.
-
Estimate likelihood and impact
Qualitative matrix unless the stem gives money. If it gives money, compute SLE and ALE. Record assumptions. That record is diligence evidence.
Side B · treat and write the right document
Primary source: NIST CSRC glossary — risk response (accept, avoid, mitigate, share, transfer) and ISC2 outline 1.6 / 1.9.
-
Compare to appetite and to any legal floor
Even a “cheap” risk can be unacceptable if a regulation forbids it. Legal floors are not optional appetite.
-
Pick one primary treatment
Mitigate with a control type the outline names — preventive, detective, or corrective — or transfer/share, or avoid. Then compute leftover residual risk. Do not stack four treatments as a way to avoid a decision.
-
Write the matching artifact
If leadership is stating intent, that is a policy update. If you are locking AES-256, that is a standard. If ops must patch in 14 days, that is a procedure. If you are offering a tip, that is a guideline — and a guideline will not save you in an audit of a SHALL.
-
Handle people and vendors in the same cycle
Outline 1.8: screening, agreements, onboarding, transfer, termination, contractor controls. Outline 1.11: minimum security requirements and service levels in the contract. A control that ignores the joiner-mover-leaver path is an incomplete treatment.
Side C · prove due care
Primary source: ISC2 outline 1.3 (due care / due diligence) and NIST RMF Authorize + Monitor.
-
Get the owner’s signature on residual risk
In an RMF environment the authorizing official makes the risk-based decision to operate. In a commercial shop the data/asset owner (or a documented risk committee) signs. A Slack “looks fine” is not acceptance.
-
Show the control is in place and working
Assessment evidence: config, ticket, scan, tabletop, awareness metrics. Outline 1.12 wants awareness that is role-based and measured — phishing simulations, champions — not a once-a-year video.
-
Put it on the register and keep watching
Continuous monitoring and reporting (1.9) is how diligence stays current. A one-time review at go-live is a due-diligence miss.
Asset and owner are named. Assessment is on file. Treatment is explicit. The matching policy/standard/procedure exists. Residual risk has a dated owner signature. A monitor owner will look at it again.
6. Runtime path after the sign-off
Go-live is the Authorize step, not the end. NIST RMF’s seven steps are Prepare → Categorize → Select → Implement → Assess → Authorize → Monitor. Domain 1 lives hardest in Prepare, Assess, Authorize, and Monitor. The other steps still happen; they just move toward Domains 2, 3, and 7.
Read left → right. A new vendor model, a merger, or a failed control sends you back to Side A. Acceptance expires when the facts change.
Business continuity sits in the same domain (objective 1.7). The business impact analysis comes before recovery-strategy shopping. Well-known CBK metrics: MTD (how long the business can stand the outage), RTO (how fast IT comes back), RPO (how much data you can lose). Recovery design that cannot meet the BIA is not a continuity plan — it is a hope. Full IR / DR mechanics live in Domain 7; Domain 1 only needs you to insist on the BIA first.
7. Traps + proof checklist
| Stem pattern | What ISC2 is testing | Engineer trap | Manager move |
|---|---|---|---|
| What do you do FIRST? | Sequencing. Diligence before tooling. | Buy / enable / block now. | Identify asset + assess risk (and policy if none exists). |
| What is BEST / MOST cost-effective? | Risk economics and completeness. | Cheapest SKU, or the fanciest SKU. | Treatment whose leftover risk the owner can accept; control cost vs ALE. |
| New vendor / AI / acquisition | Third-party and organizational process (1.3, 1.11). | Pilot in production, then write policy. | Risk assessment and contract requirements first. |
| Access or classification dispute | Roles (1.3). Owner decides. | CISO or admin decides. | Data / asset owner classifies and approves. |
| Public harm vs employer order | Ethics canons (1.1). | Protect the company quietly. | Canon I: society, common good, infrastructure first. |
| PCI vs GDPR vs “Indian law” | Regulatory vs contractual (1.4). | Only statutes count. | PCI is contractual and still binding. Privacy laws named in the outline include GDPR and others; apply the ones the data subjects trigger. |
| “Should preferably” document | Policy vs standard vs guideline (1.6). | Call it a standard because it has a number. | Optional wording = guideline. |
| We reviewed once at launch | Due diligence is ongoing (1.3, 1.9). | One review = care. | Monitor, re-assess, report. Care is the action you keep taking. |
From the ISC2 Code of Ethics: (1) Protect society, the common good, necessary public trust and confidence, and the infrastructure. (2) Act honorably, honestly, justly, responsibly, and legally. (3) Provide diligent and competent service to principals. (4) Advance and protect the profession. When they collide, start at Canon I. Complaints must name a canon; Canon III complaints come from principals, Canon IV from other professionals.
- I can say the five pillars without stopping at CIA.
- I can point to the owner on a real system I have touched.
- I can classify one document on my desk as policy, standard, procedure, or guideline from its verbs.
- I can pick a treatment and say who signs residual risk.
- I can explain diligence vs care in one sentence each.
- I can recite the four canons in order.
- I did not quote a made-up “this subtopic is X% of the exam.” Domain 1’s official weight is 16% of the whole exam — that is the only percentage this page uses.
Weak: “Domain 1 is CIA and policies.” Strong: “I assess before I buy. Policy is mandatory intent, a standard is a mandatory number, a guideline is optional. Diligence is what I knew; care is what I did. Residual risk is an owner signature, not a SOC opinion. If public safety is on the table, Canon I beats the employer ticket.”
Knowledge check
Six judgment items. Map each one to a FIRST/BEST stem, not a definition. Check answers, then reset and retry the misses.
Sources
- ISC2 — CISSP Certification Exam Outline (effective 15 April 2024). Domain 1 weight 16%. Objectives 1.1–1.12 used as the spine of this lesson. No other exam percentages are claimed.
- ISC2 — Code of Ethics (preamble + four canons, official wording).
- NIST — SP 800-37 Rev. 2, Risk Management Framework (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor).
- NIST — SP 800-30 Rev. 1, Guide for Conducting Risk Assessments.
- NIST — CSRC glossary: risk response — accept, avoid, mitigate, share, or transfer (from SP 800-39 / 800-37 / 800-30).
- NIST — SP 800-34 Rev. 1, Contingency Planning Guide (BIA before recovery strategy; RTO / RPO as well-known CBK metrics).
- Well-known CBK (not an ISC2 percentage claim): SLE = AV × EF; ALE = SLE × ARO; policy / standard / procedure / guideline force; owner vs custodian.
Related: CISSP overview (all 8 domains) · Domain 2: Asset Security · Domain 1 assessment · 8-week roadmap