T Techclick ← All lessons
ISC2 CISSP · Domain 1 · Security and Risk Management

CISSP Domain 1 — think like a manager, then treat the risk

The ticket says “buy the WAF this sprint.” The stem says FIRST. The engineer brain reaches for a rule. The CISSP brain asks which asset, which owner, which appetite, and which document is actually mandatory. This page is that shift — CIA, treatment, policy vs standard, due care vs due diligence — using the official ISC2 Domain 1 outline and well-known CBK, not invented exam weights.

20 min read · L2 primary · Quiz at end

⚡ Quick Answer

CISSP Domain 1 manager lesson: five security pillars, risk treatment (accept avoid mitigate share transfer), policy vs standard, due care vs due diligence. Official ISC2 outline + well-known CBK.

After this page you can

Quick answer

FIRST is almost never a purchase. Identify the asset and owner, assess threat × vulnerability × impact against risk appetite, then treat: mitigate (control), transfer / share (insurance or partner), avoid (stop the activity), or accept (owner signs residual risk). A policy is high-level and mandatory. A standard is mandatory and specific. A procedure is the how. A guideline is optional. Due diligence is the homework. Due care is acting on it. When ethics collide, ISC2 Canon I — society and the common good — wins.

Say this out loud

I do not buy a control first. I frame the risk, pick a treatment the business can live with, write the right document, and leave evidence that I both knew and acted.

1. Why the manager move comes first

Interview, 40 minutes in. “We are onboarding a third-party credit-scoring model next sprint. What does the security professional do first?” The engineer answers “put a WAF in front and turn on MFA.” That is a control. It is not first.

ISC2 Domain 1 — Security and Risk Management — is the heaviest domain on the official April 2024 exam outline (16%). The outline is not asking you to configure the WAF. It is asking whether security is aligned to the business, whether you can treat risk, and whether you can prove you were not negligent.

Hero · pillars sit on the register, not on a product SKU
Three glass pillars labeled C, I, and A standing on a table next to a risk-register tablet
Notice: the tablet is the work. Confidentiality, integrity, and availability are how you describe harm to an asset — they are not three products you buy.

Three reasons this domain fails people who are otherwise strong operators:

Hard words before the runbook

Risk — a function of threat, vulnerability, and impact on an asset. Not a synonym for “vulnerability.”

Risk appetite — how much risk the organization is willing to take to pursue its mission. Set by senior management / the board, not by the SOC.

Residual risk — what is left after treatment. Someone with authority must accept it in writing.

Data / asset owner — business role that classifies the asset and accepts residual risk. Security advises and implements.

Due diligence — research, assessment, vendor review, ongoing investigation. Knowing.

Due care — taking the reasonable actions a prudent professional would take. Doing.

2. Mental model · pillars, owners, documents

Hold three parts. Interviews fail when people treat CIA as a slogan, treat “policy” as any PDF, or let security decide residual risk.

Journey · identify, assess, treat, prove
Four glass panels labeled Identify, Assess, Treat, and Prove
Read left to right. Prove is not optional decoration. If you cannot show the assessment and the owner’s sign-off, you did not finish the cycle.

Part 1 · five pillars, not three slogans

The official CISSP outline (objective 1.2) names confidentiality, integrity, availability, authenticity, and non-repudiation as the five pillars of information security. CIA is still the everyday triad. The 2024 wording adds the two proof pillars so you do not stop at “keep it secret, keep it intact, keep it up.”

Confidentiality

Unauthorized disclosure. Encryption, classification, need-to-know. A leak of loan files is a C failure even if the system stayed up.

Integrity

Unauthorized modification. Hashing, change control, input validation. A silently edited credit score is an I failure.

Availability

Timely, reliable access. Redundancy, backups, DDoS defense. In a hospital or OT plant, A (and safety) can outrank C.

Authenticity + non-repudiation

Authenticity proves origin or identity. Non-repudiation means the actor cannot later deny the action — typically digital signatures and audit trails, not “we have logs.”

Common trap

Do not force “confidentiality always wins.” That is a study-guide shortcut, not the outline. Safety-critical and availability-critical missions flip the default. Read the scenario, not the mnemonic.

Part 2 · governance is top-down

Objective 1.3: align security to business strategy, mission, and objectives. Board and senior management set appetite and sponsor policy. The CISO designs the program. Owners classify. Custodians implement. Users comply. Bottom-up “we wrote a standard in the SOC and emailed it” is not governance.

Due care and due diligence sit in the same objective. Diligence is the investigation that tells you the plant still has unpatched HMIs. Care is the reasonable action you take once you know — patch, compensate, or get a signed exception. Knowing and doing nothing is the negligence story.

Part 3 · the document stack is not four names for one PDF

Objective 1.6 is four artifacts with different force. If the sentence is high-level and mandatory, it is a policy. If it names a specific required value, it is a standard. If it is a numbered how-to, it is a procedure. If it says “should” with no penalty, it is a guideline. A baseline is the minimum mandatory configuration — closer to a standard than to a wish.

Flow 1 · document force, top down
Governance documents · who they bind Policy · mandatory · why and what Board / senior management. “Information shall be protected according to classification.” Standard · mandatory · specific criteria “Production data at rest SHALL use AES-256.” Baseline lives here. Procedure · mandatory · how, step by step “Open ticket → take snapshot → apply patch → verify CVE closed.” Guideline · recommended, not enforced “Teams should preferably rotate keys every 90 days.”

Read top → bottom. Width = force. Magenta border = optional. If the exam sentence has SHALL plus a number, it is a standard, not a policy.

Say this out loud

Policy is the why. Standard is the required number. Procedure is the how. Guideline is advice. Owners classify. Security implements. Residual risk is not mine to accept silently.

3. Decision flow · treat the risk

Decision · treat or accept is not the first diamond
A glowing decision diamond splitting into paths labeled Treat and Accept
Caption, not the art: you only reach Treat vs Accept after the risk is identified and compared to appetite. Skipping the assessment is the engineer-brain miss.
Flow 2 · from ticket to treatment
New system, vendor, or AI activity Identify asset + owner Assess threat × vuln × impact Above appetite or legal floor? no Accept owner signs yes · treat Can we stop the activity? Avoid do not do it yes no · stay in business Shift to a third party / insurer? Transfer / share insurance, partner yes Mitigate control, then residual

Read top → bottom. Diamond = decision. Green border = you can stay in the activity. NIST’s risk-response language is accept, avoid, mitigate, share, or transfer — “ignore” is not on the list.

NIST SP 800-39 / 800-30 / 800-37 use that five-verb list. CISSP stems still lean on the four-word CBK set mitigate, transfer, avoid, accept. Share is the close cousin of transfer (you keep some of the risk; a partner or captive takes the rest). Cybersecurity insurance is the outline’s own example under 1.9 risk response and treatment.

4. How to choose treatment and document type

Use the tables, then the numbers. Qualitative ranking is fast and good enough for most FIRST questions. Quantitative numbers show up when the stem hands you rupees or dollars and asks whether the control is worth it.

If the ticket looks like…TreatmentWho signs
We will keep doing this; a control will lower likelihood or impact. Mitigate (apply preventive / detective / corrective controls). Owner accepts leftover residual risk after the control.
A contract or policy can move impact to an insurer or processor. Transfer or share. Legal + owner. Insurance does not transfer reputation or regulatory duty.
The activity itself is the problem (shadow AI, unsanctioned region). Avoid — do not start, or shut it down. Business leadership. Security does not “avoid” by hiding the request.
After treatment, leftover risk sits inside appetite. Accept. Asset / data owner, or the authorizing official in an RMF shop.
Nobody wrote it down and the team “will watch it.” Not a treatment. This is ignore — the trap answer. Nobody valid. Exam: never pick ignore.
Wording in the documentArtifactForce
“The organization shall protect customer data.” Policy Mandatory, high-level, management-approved.
“Production systems SHALL use AES-256 / 14-character passwords.” Standard (or baseline) Mandatory, measurable. Audit can fail you.
“Step 1 snapshot. Step 2 patch. Step 3 verify CVE.” Procedure Mandatory how-to. Operators follow it.
“Teams should preferably rotate keys every 90 days.” Guideline Advice. No penalty if skipped.

Qualitative vs quantitative — well-known CBK math

When the stem gives money, use the classic formulas. They are well-known CBK, not an ISC2-invented “exam percentage.”

Quantitative risk — remember the chain
SLE = AV × EF
ALE = SLE × ARO
Compare: cost of control vs reduction in ALE

AV is asset value. EF is the fraction lost in one event. SLE is one-event loss. ARO is how often per year. ALE is expected yearly loss. A control that costs more than the ALE it removes is usually a poor BEST answer unless a law or contract forces it.

Qualitative work uses High / Medium / Low (or a 5×5 matrix) when you do not have clean numbers. Use it to rank. Do not pretend a red cell is a rupee figure.

Frameworks the outline actually names

Objective 1.3 and 1.9 list ISO, NIST, COBIT, SABSA, PCI, and FedRAMP as examples — plus cybersecurity insurance under treatment. Pick the framework the scenario already lives in (federal system → RMF / FedRAMP; card data → PCI as a contractual standard). Do not invent a “best framework for 40% of the exam.”

5. Runbook · Side A assess, B treat, C prove

This is not a vendor console path. It is the Domain 1 operating path you walk on a new system, a new vendor, or a new AI use case. Each side cites one primary source.

Side A · identify and assess (due diligence)

Primary source: NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments.

  1. Name the asset and the owner

    What is at risk — data, process, model, plant, reputation? Who in the business classifies it? If nobody will claim ownership, stop. Security does not become the owner by default.

  2. Identify threats and vulnerabilities

    Threat is the actor or event. Vulnerability is the weakness. A CVE with no realistic threat against this asset is not automatically high risk. Include supply-chain items the outline calls out in 1.11: counterfeit, implant, weak third-party, missing SBOM, no silicon root of trust.

  3. Scope the assessment

    Which systems, which data types, which jurisdictions? GDPR is in the official privacy example list. PCI is contractual, not a statute. Investigation type (objective 1.5) matters later if this becomes an incident — administrative, criminal, civil, regulatory, or industry-standard — but you do not pick a lawyer before you have a risk picture.

  4. Estimate likelihood and impact

    Qualitative matrix unless the stem gives money. If it gives money, compute SLE and ALE. Record assumptions. That record is diligence evidence.

Side B · treat and write the right document

Primary source: NIST CSRC glossary — risk response (accept, avoid, mitigate, share, transfer) and ISC2 outline 1.6 / 1.9.

  1. Compare to appetite and to any legal floor

    Even a “cheap” risk can be unacceptable if a regulation forbids it. Legal floors are not optional appetite.

  2. Pick one primary treatment

    Mitigate with a control type the outline names — preventive, detective, or corrective — or transfer/share, or avoid. Then compute leftover residual risk. Do not stack four treatments as a way to avoid a decision.

  3. Write the matching artifact

    If leadership is stating intent, that is a policy update. If you are locking AES-256, that is a standard. If ops must patch in 14 days, that is a procedure. If you are offering a tip, that is a guideline — and a guideline will not save you in an audit of a SHALL.

  4. Handle people and vendors in the same cycle

    Outline 1.8: screening, agreements, onboarding, transfer, termination, contractor controls. Outline 1.11: minimum security requirements and service levels in the contract. A control that ignores the joiner-mover-leaver path is an incomplete treatment.

Side C · prove due care

Primary source: ISC2 outline 1.3 (due care / due diligence) and NIST RMF Authorize + Monitor.

  1. Get the owner’s signature on residual risk

    In an RMF environment the authorizing official makes the risk-based decision to operate. In a commercial shop the data/asset owner (or a documented risk committee) signs. A Slack “looks fine” is not acceptance.

  2. Show the control is in place and working

    Assessment evidence: config, ticket, scan, tabletop, awareness metrics. Outline 1.12 wants awareness that is role-based and measured — phishing simulations, champions — not a once-a-year video.

  3. Put it on the register and keep watching

    Continuous monitoring and reporting (1.9) is how diligence stays current. A one-time review at go-live is a due-diligence miss.

Green path — you finished Domain 1 work when

Asset and owner are named. Assessment is on file. Treatment is explicit. The matching policy/standard/procedure exists. Residual risk has a dated owner signature. A monitor owner will look at it again.

6. Runtime path after the sign-off

Go-live is the Authorize step, not the end. NIST RMF’s seven steps are Prepare → Categorize → Select → Implement → Assess → Authorize → Monitor. Domain 1 lives hardest in Prepare, Assess, Authorize, and Monitor. The other steps still happen; they just move toward Domains 2, 3, and 7.

Proof · residual risk is a signed fact, not a vibe
Operations desk with signed documents and a monitor showing residual risk accepted
Notice: the stack of signed pages is the care. The green screen is only useful if it matches that file.
Flow 3 · after authorization
Authorize owner / AO signs Operate controls stay on Monitor KRIs, audits, drift Re-assess change, incident, AI Retreatment or re-accept

Read left → right. A new vendor model, a merger, or a failed control sends you back to Side A. Acceptance expires when the facts change.

Business continuity sits in the same domain (objective 1.7). The business impact analysis comes before recovery-strategy shopping. Well-known CBK metrics: MTD (how long the business can stand the outage), RTO (how fast IT comes back), RPO (how much data you can lose). Recovery design that cannot meet the BIA is not a continuity plan — it is a hope. Full IR / DR mechanics live in Domain 7; Domain 1 only needs you to insist on the BIA first.

7. Traps + proof checklist

Stem patternWhat ISC2 is testingEngineer trapManager move
What do you do FIRST? Sequencing. Diligence before tooling. Buy / enable / block now. Identify asset + assess risk (and policy if none exists).
What is BEST / MOST cost-effective? Risk economics and completeness. Cheapest SKU, or the fanciest SKU. Treatment whose leftover risk the owner can accept; control cost vs ALE.
New vendor / AI / acquisition Third-party and organizational process (1.3, 1.11). Pilot in production, then write policy. Risk assessment and contract requirements first.
Access or classification dispute Roles (1.3). Owner decides. CISO or admin decides. Data / asset owner classifies and approves.
Public harm vs employer order Ethics canons (1.1). Protect the company quietly. Canon I: society, common good, infrastructure first.
PCI vs GDPR vs “Indian law” Regulatory vs contractual (1.4). Only statutes count. PCI is contractual and still binding. Privacy laws named in the outline include GDPR and others; apply the ones the data subjects trigger.
“Should preferably” document Policy vs standard vs guideline (1.6). Call it a standard because it has a number. Optional wording = guideline.
We reviewed once at launch Due diligence is ongoing (1.3, 1.9). One review = care. Monitor, re-assess, report. Care is the action you keep taking.
Ethics canons — official wording, official order

From the ISC2 Code of Ethics: (1) Protect society, the common good, necessary public trust and confidence, and the infrastructure. (2) Act honorably, honestly, justly, responsibly, and legally. (3) Provide diligent and competent service to principals. (4) Advance and protect the profession. When they collide, start at Canon I. Complaints must name a canon; Canon III complaints come from principals, Canon IV from other professionals.

Pilot / interview proof checklist
Interview angle

Weak: “Domain 1 is CIA and policies.” Strong: “I assess before I buy. Policy is mandatory intent, a standard is a mandatory number, a guideline is optional. Diligence is what I knew; care is what I did. Residual risk is an owner signature, not a SOC opinion. If public safety is on the table, Canon I beats the employer ticket.”

Knowledge check

Six judgment items. Map each one to a FIRST/BEST stem, not a definition. Check answers, then reset and retry the misses.

Q1

Leadership wants a third-party LLM scoring loans next sprint. An engineer opens a purchase request for a WAF and MFA licenses. What does the security professional do FIRST?

Correct: c. FIRST on a new vendor or AI use case is assessment and governance, not a purchase. A procedure is later. ISO 27001 is not a prerequisite invented by the stem. Re-read Decision flow and Side A.
Q2

A document states: “All production systems SHALL encrypt data at rest with AES-256.” It is mandatory and names a specific algorithm. What is it?

Correct: b. SHALL plus a measurable value is a standard. A policy would stay high-level. A procedure would list steps. A guideline would say “should.” Re-read Mental model and the choose table.
Q3

After a breach, counsel asks whether the CISO “knew the plant still ran unpatched HMIs and failed to act.” Which distinction answers them?

Correct: a. Outline 1.3 pairs the terms. Knowing without acting is a care failure; acting blindly without assessing is a diligence failure. Insurance and hiring screens are examples, not the definition. Re-read hard words and Side C.
Q4

A WAF cut ALE from $400,000 to $40,000. The leftover $40,000 is inside documented appetite. Leadership signs a memo to live with it and buys nothing else. What is that final decision, and who should sign?

Correct: b. Mitigation already happened. Living with leftover risk inside appetite is acceptance, and the owner (or authorizing official) signs. Ignore is never a treatment. Re-read How to choose.
Q5

An employer tells a CISSP to hide a flaw that will almost certainly harm public infrastructure. The professional’s own job is at risk if they speak. Which ethics move is correct?

Correct: b. Official canons are ordered. Society and infrastructure come before principals. Canon IV is not “dump an exploit.” The preamble also says strict adherence is a condition of certification. Re-read the ethics callout in Traps.
Q6

A safety-critical plant asks which pillar to privilege if a control that encrypts an HMI also makes the emergency stop too slow. What is the Domain 1 judgment?

Correct: c. Do not apply a “C always wins” slogan. The mission (and Canon I) can flip the triad. You still assess; you do not blindly drop encryption without a treatment and an owner. Re-read Mental model.

Sources

Related: CISSP overview (all 8 domains) · Domain 2: Asset Security · Domain 1 assessment · 8-week roadmap