top of page

CISSP Domain 1 Master Cheat Sheet: Security & Risk Management

Security & Risk Management (16%)

Everything You Need to Remember for the CISSP Exam


1. Core Security Principles

CIA Triad

Principle

Goal

Example

Confidentiality

Prevent unauthorized disclosure

Encryption, Need-to-Know

Integrity

Prevent unauthorized modification

Hashing, Digital Signatures

Availability

Ensure timely access

Redundancy, Backups


AAA / IAAA

  • Identification – Claim an identity

  • Authentication – Verify identity

  • Authorization – Determine permissions

  • Accountability – Audit actions

Remember:

Identify → Authenticate → Authorize → Audit

DAD (Opposite of CIA)

CIA

Opposite

Confidentiality

Disclosure

Integrity

Alteration

Availability

Destruction


Fundamental Security Principles

  • Least Privilege

  • Need-to-Know

  • Separation of Duties (SoD)

  • Job Rotation

  • Mandatory Vacation

  • Dual Control

  • Split Knowledge

  • Defense in Depth

  • Zero Trust

  • Privacy by Design

  • Secure by Design

  • Fail Secure

  • Open Design

  • Economy of Mechanism

  • Complete Mediation

  • Psychological Acceptability


Security Objectives

  • Confidentiality

  • Integrity

  • Availability

  • Authenticity

  • Accountability

  • Non-repudiation


2. Security Governance & Leadership

Governance

  • Align security with business goals

  • Executive sponsorship

  • Strategic planning

  • Risk oversight

  • Compliance management

  • Performance measurement


GRC

Component

Purpose

Governance

Direct security strategy

Risk

Identify and manage uncertainty

Compliance

Meet legal and regulatory requirements


Documentation Hierarchy

Policies
      ↓
Standards
      ↓
Procedures
      ↓
Guidelines
      ↓
Baselines

Organizational Roles

  • Board of Directors

  • Senior Management

  • CISO

  • CIO

  • Privacy Officer

  • Data Owner

  • Business Owner

  • System Owner

  • Data Custodian

  • Data Processor

  • Users

  • Internal Audit



Metrics

KPI

Measures success.

Examples

  • Patch compliance

  • MFA adoption


KRI

Measures increasing risk.

Examples

  • Critical vulnerabilities

  • Phishing success rate


Governance Frameworks

  • COBIT

  • ISO 38500

  • COSO

  • ITIL (supporting governance)


3. Risk Management

Risk Formula

Risk = Threat × Vulnerability × Impact

Risk Process

  1. Identify Assets

  2. Identify Threats

  3. Identify Vulnerabilities

  4. Analyze Risk

  5. Prioritize

  6. Treat Risk

  7. Monitor

  8. Review


Risk Analysis

Qualitative

  • High

  • Medium

  • Low

Quantitative

  • Dollar values

  • Statistical analysis


Risk Register

Includes

  • Risk ID

  • Owner

  • Likelihood

  • Impact

  • Controls

  • Status

  • Residual Risk


Risk Appetite

Amount of risk organization is willing to accept.


Risk Tolerance

Acceptable deviation around objectives.


Risk Treatment

Treatment

Meaning

Avoid

Eliminate activity

Transfer

Shift financial impact

Mitigate

Reduce likelihood/impact

Accept

Formally acknowledge risk


Risk Types

  • Inherent Risk

  • Residual Risk

  • Control Risk

  • Detection Risk


Threat Modeling

  • STRIDE

  • PASTA

  • DREAD

  • OCTAVE

  • Attack Trees


Enterprise Risk Management (ERM)

Enterprise-wide approach integrating cybersecurity with overall business risk.


4. Risk Calculations

Formula

Meaning

SLE = AV × EF

Single Loss Expectancy

ALE = SLE × ARO

Annual Loss Expectancy

EF

Exposure Factor

ARO

Annual Rate of Occurrence



Financial Analysis

  • Cost-Benefit Analysis

  • Total Cost of Ownership (TCO)

  • Return on Security Investment (ROSI)

  • Annualized Cost of Safeguard (ACS)


5. Security Controls

By Type

  • Administrative

  • Technical

  • Physical

By Function

  • Preventive

  • Detective

  • Corrective

  • Recovery

  • Compensating

  • Directive

  • Deterrent


Control Selection

Consider:

  • Cost

  • Effectiveness

  • Risk Reduction

  • Business Impact


6. Compliance & Legal

Due Care vs Due Diligence

Due Care

Due Diligence

Doing the right thing

Investigating the right thing


Legal Concepts

  • Liability

  • Negligence

  • Reasonable Care

  • Fiduciary Responsibility


Intellectual Property

  • Copyright

  • Patent

  • Trademark

  • Trade Secret


Computer Crime Laws

  • CFAA

  • DMCA

  • Privacy Laws


Investigations

  • Administrative

  • Civil

  • Criminal

  • Regulatory


Digital Evidence

Maintain:

  • Integrity

  • Chain of Custody

  • Admissibility

  • Authenticity


eDiscovery

Legal preservation of electronically stored information.


7. Ethics

ISC² Code of Ethics

  1. Protect society.

  2. Act honorably.

  3. Provide diligent service.

  4. Advance the profession.


Professional Conduct

  • Honesty

  • Integrity

  • Confidentiality

  • Objectivity


8. Privacy

Personal Information

  • PII

  • PHI

  • SPI

  • Sensitive Data


Privacy Principles

  • Consent

  • Data Minimization

  • Purpose Limitation

  • Accuracy

  • Transparency

  • Accountability


Privacy Assessments

  • Privacy Impact Assessment (PIA)

  • Data Protection Impact Assessment (DPIA)


Major Privacy Regulations

  • GDPR

  • CCPA

  • HIPAA

  • PIPEDA

  • POPIA

  • PIPL


9. Data Classification & Lifecycle

Classification Levels

Public

Internal

Confidential

Restricted


Lifecycle

Create

Store

Use

Share

Archive

Destroy


Secure Disposal

  • Shredding

  • Pulverizing

  • Degaussing

  • Cryptographic Erasure

  • Secure Wipe


Data Remanence

Residual data remaining after deletion.


10. Business Continuity & Disaster Recovery

BIA Flow

Assets
    ↓
Business Processes
    ↓
Critical Functions
    ↓
RTO
    ↓
RPO
    ↓
Recovery Strategy

Recovery Metrics

  • MTD

  • RTO

  • RPO

  • WRT

  • MAO


Alternate Sites

  • Hot

  • Warm

  • Cold

  • Mobile

  • Cloud Recovery


Exercises

  • Checklist Review

  • Walkthrough

  • Tabletop

  • Simulation

  • Parallel Test

  • Full Interruption


11. Security Awareness & Human Risk

Learning Types

Awareness

Training

Education

Inform

Teach

Develop


Human Risks

  • Phishing

  • Spear Phishing

  • Whaling

  • Vishing

  • Smishing

  • BEC

  • Tailgating

  • Shoulder Surfing

  • Dumpster Diving

Insider Threat

  • Malicious

  • Negligent

  • Compromised


12. Third-Party & Supply Chain Risk

  • Vendor Risk Management

  • Supplier Assessments

  • Fourth-Party Risk

  • SBOM

  • Software Supply Chain

  • Contract Reviews

  • SLA

  • MOU

  • BPA

  • Right-to-Audit Clauses


13. Frameworks & Standards

NIST

  • CSF

  • RMF

  • SP 800-37

  • SP 800-53

  • SP 800-30

  • SP 800-61


ISO

  • ISO 27001

  • ISO 27002

  • ISO 27005

  • ISO 31000

  • ISO 22301


Other Frameworks

  • COBIT

  • CIS Controls

  • SABSA

  • PCI DSS

  • SOC 2

  • FedRAMP

  • CSA CCM


14. CISSP Exam Mindset

✔ Think like a risk advisor, not a technician.

✔ Protect the business mission, not just systems.

✔ Prioritize People → Process → Technology.

✔ Choose the BEST answer, not merely a technically correct one.

✔ Favor preventive and strategic controls before detective or reactive ones.

✔ Ensure solutions align with business objectives, governance, compliance, and risk management.

✔ Always consider cost-effectiveness and risk reduction, not maximum security at any cost.

✔ Escalate major risks through proper governance rather than acting independently.

✔ Document, obtain management approval where appropriate, and follow organizational policy.


CISSP Domain 1 Memory Aids

Topic

Memory Trick

CIA

Confidentiality • Integrity • Availability

AAA

Identify → Authenticate → Authorize → Audit

Risk Treatment

AMTA = Accept • Mitigate • Transfer • Avoid

Documentation

PSPGB = Policies → Standards → Procedures → Guidelines → Baselines

Controls

ATP = Administrative • Technical • Physical

BCP Metrics

MTD → RTO → RPO → WRT

ALE Formula

ALE = SLE × ARO

SLE Formula

SLE = AV × EF

Ethics

Protect • Honor • Serve • Advance

Exam Strategy

People → Process → Technology


Related Topics

  • CIA Triad

  • Security Governance

  • Governance, Risk & Compliance (GRC)

  • Risk Management

  • Risk Appetite vs. Risk Tolerance

  • Security Controls

  • Security Policies

  • Data Classification

  • Business Continuity Planning (BCP)

  • Disaster Recovery Planning (DRP)

  • Security Awareness

  • Compliance

  • Cryptography

  • Zero Trust Architecture

  • Defense in Depth

  • Least Privilege

  • Identity and Access Management


15. Common CISSP Domain 1 Mistakes

These are the mistakes that cause candidates to lose points on the exam.

❌ Thinking Like an Engineer Instead of a Security Leader

The CISSP exam tests business decision-making. The technically strongest solution is not always the best answer.

❌ Ignoring Business Objectives

Security should support the organization's mission, not hinder it.

❌ Confusing Due Care with Due Diligence

  • Due Care: Taking appropriate action.

  • Due Diligence: Investigating and validating before acting.

❌ Confusing Risk Appetite with Risk Tolerance

Risk Appetite = Overall willingness to accept risk.

Risk Tolerance = Acceptable variation around specific objectives.

❌ Memorizing Without Understanding

The CISSP exam emphasizes reasoning, prioritization, and applying concepts in realistic scenarios.


16. CISSP Domain 1 Exam Tips

Before Choosing an Answer, Ask Yourself

✔ Does it reduce business risk?

✔ Does it align with organizational policy?

✔ Has management approved it?

✔ Does it support governance?

✔ Is it preventive rather than reactive?

✔ Does it consider people before technology?


Questions That Often Appear

  • Governance vs Management

  • Risk treatment decisions

  • Due Care vs Due Diligence

  • Security policies

  • Risk calculations

  • Legal responsibilities

  • Privacy regulations

  • BCP vs DRP

  • Data classification

  • Security awareness


17. Quick Revision Checklist

Review these immediately before the exam.

Governance

□ Policies → Standards → Procedures → Guidelines → Baselines

□ Roles and responsibilities

□ GRC

□ KPI vs KRI


Risk

□ Risk Formula

□ ALE

□ SLE

□ ARO

□ EF

□ AMTA


Security Principles

□ CIA

□ AAA

□ DAD

□ Zero Trust

□ Defense in Depth


Legal

□ Due Care

□ Due Diligence

□ Copyright

□ Patent

□ Trademark

□ Trade Secret


BCP

□ BIA

□ MTD

□ RTO

□ RPO

□ WRT


Privacy

□ PII

□ PHI

□ GDPR

□ HIPAA


18. 5 CISSP-Style Practice Questions

Question 1

A security manager recommends implementing multi-factor authentication to reduce the likelihood of unauthorized access to critical systems. Which risk treatment strategy is being applied?

A. Accept

B. Transfer

C. Mitigate

D. Avoid

Answer: C. Mitigate

Explanation: MFA reduces the likelihood of unauthorized access. The underlying business activity continues, so the risk is being mitigated rather than avoided.


Question 2

Senior management decides that the cost of implementing a new control exceeds the expected annual financial loss. What is the MOST appropriate action?

A. Transfer the risk

B. Avoid the activity

C. Accept the risk

D. Ignore the risk

Answer: C. Accept the risk

Explanation: When mitigation costs outweigh expected losses, management may formally accept the residual risk after documenting and approving the decision.


Question 3

Which document provides mandatory, high-level management direction for an organization's information security program?

A. Guideline

B. Procedure

C. Policy

D. Baseline

Answer: C. Policy

Explanation: Policies establish management's intent and provide the highest level of direction for security governance.


Question 4

During a security assessment, a team calculates the expected annual financial loss associated with ransomware attacks. Which metric are they calculating?

A. SLE

B. ARO

C. ALE

D. EF

Answer: C. ALE

Explanation: Annual Loss Expectancy (ALE) estimates the expected yearly financial loss and is calculated as:

ALE = SLE × ARO


Question 5

An organization is deciding between two technically sound security controls. Which factor should MOST influence the final decision?

A. Lowest implementation cost

B. Strongest encryption algorithm

C. Alignment with business objectives and risk reduction

D. Newest security technology

Answer: C. Alignment with business objectives and risk reduction

Explanation: CISSP emphasizes selecting controls that best support business objectives while reducing risk in a cost-effective manner.


19. Key Takeaways

  • Domain 1 forms the foundation of the CISSP Common Body of Knowledge and underpins decision-making across all eight domains.

  • Effective security governance aligns cybersecurity initiatives with organizational objectives.

  • Risk management is a continuous process of identifying, assessing, treating, and monitoring risk.

  • Security leaders prioritize governance, compliance, and business needs over purely technical solutions.

  • Strong knowledge of legal, regulatory, privacy, and business continuity concepts is essential for success.

  • The CISSP exam rewards strategic thinking, sound judgment, and choosing the BEST answer rather than the most technical one.


20. Related CISSP Articles

Continue your Domain 1 preparation with these in-depth guides:


GoCyberNinja Master Cheat Sheet Series

Maintain a consistent naming convention across all eight domains to reinforce your brand and improve discoverability:


Continue Your CISSP Journey with GoCyberNinja

Reading about secure software development is only the beginning. The CISSP exam evaluates your ability to apply security principles, assess business risk, and make informed management decisions across the entire software lifecycle.

GoCyberNinja CISSP Exam Prep helps reinforce Domain 8 through realistic, scenario-driven practice designed to build both technical understanding and executive-level decision-making.


Strengthen Your Domain 8 Knowledge

✅ Realistic CISSP Practice Questions covering all eight CISSP domains

✅ 1,200 Full Mock Exam Questions across eight comprehensive practice exams

✅ 400+ Scenario-Based Questions designed to develop the CISSP manager's mindset

✅ 1,040+ Flashcards for rapid review and long-term retention

✅ Adaptive Smart Review that automatically focuses on your weakest topics

✅ Performance Analytics to measure readiness and identify knowledge gaps

✅ Personalized Study Plans based on your learning progress

✅ Three Free CISSP Readiness Tests to benchmark your preparation before attempting full-length exams


Practice. Analyze. Master.

The CISSP is not a programming exam—it is a security leadership and risk management exam. Success comes from understanding how secure software supports business objectives, protects organizational assets, and reduces enterprise risk.

With GoCyberNinja CISSP Exam Prep, you'll build the judgment, confidence, and practical decision-making skills expected of a CISSP professional.

Practice smarter. Analyze deeper. Master the CISSP.


Take the FREE CISSP Readiness Tests to evaluate your knowledge, identify weak areas, and receive a personalized study roadmap before tackling the full question bank.

bottom of page