CISSP · Domain 1
Security and Risk Management
About 16% of the exam, the largest domain
Governance
- Sets direction and oversight
- Aligns security with business objectives
- Accountability at every level
- Risk ownership sits with the business
- Reporting and compliance to the board
Governance decides, management executes, security enables
Senior Management
- Ultimate accountability for security
- Accepts residual risk, nobody else can
- Approves policy and funds the program
- Sets risk appetite and tolerance
Risk Management Process
- Context
- Identify
- Analyze
- Evaluate
- Treat
- Monitor
- Context
- Set scope, criteria, appetite
- Identification
- What can go wrong
- Analysis
- How big is the risk
- Evaluation
- Is it acceptable
- Treatment
- What we do about it
- Monitoring
- Is the risk changing
Risk Concepts
- Asset
- Anything of value
- Threat
- Potential cause of harm
- Vulnerability
- Weakness a threat exploits
- Exposure
- Being open to loss
- Likelihood
- Probability it happens
- Impact
- Damage if it happens
- Inherent risk
- Before any controls
- Residual risk
- Left after controls
Appetite, Tolerance, Capacity
- Appetite
- Target level the board wants
- Tolerance
- Acceptable deviation from target
- Capacity
- Maximum the organization can absorb
Risk responses in order of preference: avoid, mitigate, transfer, accept
Risk Analysis
Qualitative
- Delphi technique, anonymous expert rounds
- Risk matrix, likelihood by impact
- Scenario analysis
- Brainstorming
- High, medium, low ratings
Quantitative
- SLE = asset value x exposure factor
- ALE = SLE x ARO
- ARO = expected events per year
- Total risk = threat x vulnerability x value
- Control value = ALE before minus ALE after minus cost
Buy the control only when its annual cost is below the ALE it removes
Policy Framework
- Policy
- Standard
- Procedure
- Baseline
- Guideline
- Policy
- High level, the why, mandatory
- Standard
- Specific mandatory requirements
- Procedure
- Step by step how to
- Baseline
- Minimum secure configuration
- Guideline
- Recommended, not mandatory
Policy types: enterprise, issue specific, system specific
Policy Essentials
- Approved by management, not by IT
- Communicated to everyone it binds
- Reviewed and updated on a cycle
- Exceptions handled through a formal process
- Enforced, or it is only a suggestion
Awareness and Personnel
- Background check before hire
- NDA and onboarding on day one
- Least privilege and separation of duties
- Job rotation and mandatory vacation detect fraud
- Termination: disable access first, then exit
- Awareness
- The what, changes attitude
- Training
- The how, builds skill
- Education
- The why, builds understanding
Compliance, Legal and Ethics
ISC2 Code of Ethics, in order
- Protect society, the commonwealth, the infrastructure
- Act honorably, honestly, justly, responsibly, legally
- Provide diligent and competent service
- Advance and protect the profession
Legal systems
- Criminal
- Punishment, beyond reasonable doubt
- Civil
- Damages, preponderance of evidence
- Administrative
- Agency rules and penalties
- Regulatory
- Compliance obligations
Key Legal Concepts
- Due care
- Doing what a prudent person would
- Due diligence
- Investigating before acting
- Negligence
- Failing the prudent person test
- Downstream liability
- Your breach harms a partner
- Due process
- Fair, lawful procedure
Intellectual Property
- Patent
- Invention, about 20 years
- Trademark
- Brand, logo, name
- Copyright
- Expression, not the idea
- Trade secret
- Protected only while secret
BCP, DR and Resilience
- Scope and plan
- BIA
- Continuity planning
- Approve and implement
- Test
- Maintain
Plans
- BCP
- Keep the business running
- DRP
- Recover IT after disaster
- IRP
- Handle security incidents
- COOP
- Essential operations continue
- Crisis management
- People and communications
BIA outputs
- RTO
- Time to restore the service
- RPO
- Data loss you can tolerate
- MTD
- Maximum tolerable downtime
- WRT
- Work recovery after restore
- Criticality
- Ranking of what recovers first
RTO plus WRT must fit inside MTD
DR Test Types, least to most rigorous
- Checklist
- Walkthrough
- Simulation
- Parallel
- Full interruption
- Checklist: read the plan alone
- Walkthrough: tabletop discussion
- Simulation: act out a scenario
- Parallel: run the alternate site alongside
- Full interruption: fail over for real
Third Party and Supply Chain
- SLA
- Measurable service commitments
- MOU
- Intent, usually not binding
- SOW
- Deliverables and scope
- MSA
- Master terms across projects
- Right to audit
- Verify, do not just trust
- Fourth party
- Your supplier's supplier
- SBOM
- Inventory of software components
Reference strip
SOC reports
- SOC 1
- Financial controls
- SOC 2
- Trust services criteria
- SOC 3
- Public summary
- Type I vs II
- Design vs operating over time
Frameworks, know the purpose
- NIST CSF
- Govern, identify, protect, detect, respond, recover
- NIST RMF
- Prepare, categorize, select, implement, assess, authorize, monitor
- ISO 27001
- Certifiable ISMS
- ISO 27002
- Controls guidance
- COBIT, COSO, ITIL
- Governance, internal control, service management
Key regulations
- GDPR
- 72 hour breach notice, fines to 4%
- HIPAA
- PHI and ePHI
- SOX
- Financial reporting integrity
- PCI DSS
- Cardholder data, 12 requirements
- GLBA
- Financial privacy
Data classification
- Government
- Top secret, secret, confidential, unclassified
- Commercial
- Confidential, private, sensitive, public
Control categories
- By type
- Administrative, technical, physical
- By function
- Preventive, detective, corrective, deterrent, recovery, compensating
Quick exam traps
- Trap: Security decides the risk appetite, not the board
- Trap: Residual risk can be accepted by the CISO
- Trap: Guidelines are mandatory
- Trap: Qualitative analysis produces dollar figures
- Trap: Due diligence and due care are the same thing
- Trap: Full interruption is the first DR test to run
- Trap: RTO can exceed MTD
- Trap: A SOC 2 Type I proves controls operated all year
cybercertprep.com · original revision sheet written from the public body of knowledge