SecurityX (CASP+) · Domain 1
Governance, Risk & Compliance
About 20% of the exam
Program documentation
- Policy
- board level intent, mandatory
- Standard
- the mandatory technical specifics
- Procedure
- the ordered steps
- Guideline
- recommended practice only
- Baseline
- minimum accepted configuration
- Exception
- approved, documented, time-limited deviation
Governance in practice
- A steering committee sets direction
- Executive sponsorship makes it stick
- Risk owners sit in the business
- Report metrics leadership can act on
- Review documents on a fixed cycle
- Change and configuration management underpin everything
Frameworks to name
- ISO 27001
- certifiable management system requirements
- NIST CSF
- identify, protect, detect, respond, recover
- NIST SP 800-53
- a broad control catalog
- COBIT
- IT governance and value alignment
- CSA CCM
- cloud control matrix mappings
- CIS Controls
- prioritized and prescriptive control set
- SOC 2
- trust criteria audited independently
Compliance obligations
- GDPR
- personal data rights and duties
- PCI DSS
- contractual card data protection
- HIPAA
- health information safeguards
- CMMC
- defense supply chain maturity
- SOX
- financial reporting controls
- Attestation
- signed statement of compliance
- Audit evidence
- gathered continuously, not annually
Risk analysis and reporting
Quantitative
- SLE is asset value times exposure
- ALE is SLE times ARO
- Compare control cost against ALE
- FAIR models frequency and magnitude
- Data quality limits the answer
Qualitative
- Scales of high, medium and low
- Heat map of likelihood against impact
- Scenario workshops with business owners
- Faster, but harder to compare
Register and reporting
- Every risk carries one owner
- Key risk indicators warn early
- Threshold breaches escalate automatically
- Appetite is set by the board
- Tolerance cascades to business units
Boards compare cyber risk with other risk, so express exposure in money and trend rather than in vulnerability counts
Third-party and supply chain risk
Assess
- Due diligence before the contract
- Independent audit reports, not questionnaires alone
- Assess the fourth parties too
- Request an SBOM for products
Contract
- Right to audit clause
- Breach notification timelines defined
- Security requirements written as obligations
- Exit terms and data return
Monitor
- Continuous monitoring, not annual review
- Track their incidents and advisories
- Reassess whenever the service changes
- Watch concentration across shared providers
Privacy and sovereignty
- Data subject
- the identified living person
- Controller
- decides purpose and means
- Processor
- acts only on instruction
- Data sovereignty
- local law follows the data
- Cross-border transfer
- needs an approved mechanism
- Localization
- processing must stay in country
- Privacy assessment
- before high risk processing starts
- Breach notification
- the clock starts at awareness
Legal concepts
- Due care
- acting as a prudent organization
- Due diligence
- investigating before you commit
- E-discovery
- producing records for litigation
- Legal hold
- suspends normal deletion schedules
- Chain of custody
- who handled evidence, and when
- Privilege
- counsel led work may be protected
- Sanction
- fines and licensing consequences
Crisis and breach response
- Declare
- Convene
- Assess obligations
- Communicate
- Remediate
- Review
- One decision maker, one message
- Counsel decides the notification duty
- Prepare holding statements in advance
- Out-of-band channels during compromise
- Notify insurers inside policy terms
Governing AI adoption
- Name an owner for each assistant
- Approve use cases, not tools broadly
- Contract that prompts are never trained on
- Classify what data may enter prompts
- Log what was sent and returned
- Recertify agent access like human access
- Review board spans legal and privacy
AI threats to weigh
- Prompt injection
- hostile instruction inside the input
- Indirect injection
- payload hidden in retrieved content
- Data poisoning
- corrupting the training data
- Model extraction
- querying to clone behavior
- Membership inference
- revealing what training data held
- Deepfake
- synthetic voice or video fraud
- Excessive agency
- wide permissions, thin oversight
- Hallucination
- confident output with no basis
Awareness and training
- Segment training by role and risk
- Privileged users need deeper content
- Simulate phishing and voice pretexting
- Measure reporting rate over time
- Brief executives on targeted fraud
- Refresh after incidents and near misses
Key formulas
- SLE
- asset value times exposure factor
- ALE
- SLE times annual rate of occurrence
- ARO
- expected events per year
- Residual risk
- what remains after controls
- Control value
- reduction in ALE minus cost
- MTTR and MTBF
- repair time and failure interval
Rapid recall
- Appetite
- how much risk is wanted
- Tolerance
- acceptable variance around appetite
- Inherent risk
- before any control
- Residual risk
- after controls applied
- KRI
- a leading warning indicator
- KPI
- a lagging performance measure
- Heat map
- likelihood against impact
Reference strip: govern, comply, quantify, contract
Govern
- Policy, standard, procedure, guideline
- Steering committees and sponsorship
- Change and configuration management
- Exception and deviation handling
Comply
- GDPR, PCI DSS, HIPAA, CMMC, SOX
- ISO 27001, NIST CSF, SP 800-53
- COBIT, CSA CCM, CIS Controls
- Attestation and continuous evidence
Quantify
- SLE, ARO, ALE and FAIR
- Qualitative scales and heat maps
- Register, owners, thresholds
- Appetite, tolerance, residual risk
Contract
- Right to audit and notification clauses
- SBOM and fourth-party visibility
- Exit, portability and data return
- Concentration and dependency risk
AI
- Approved use cases and data classes
- Prompt injection and poisoning risks
- Deepfake enabled social engineering
- Monitoring, logging, recertification
Quick exam traps
- Trap: Risk appetite and risk tolerance are interchangeable terms
- Trap: A vendor questionnaire is equivalent to an independent audit
- Trap: Quantitative analysis is always more defensible
- Trap: Compliance with a framework proves the estate is secure
- Trap: Security owns every risk in the register
- Trap: Cross-border transfer is fine once the data is encrypted
- Trap: An AI assistant inherits no access of its own
- Trap: Deepfake fraud is a future problem, not a current one
cybercertprep.com · original revision sheet written from the public body of knowledge