Know what to study. Practice what matters. Know when you're ready.
Realistic CISSP practice, readiness tests, adaptive learning, AI Security, and full-length exam simulation across all eight CISSP domains
🟠No registration🔵 Instant Access 🟡 Works on Any Device
Three readiness tests help identify your domain strengths, weaknesses, performance patterns, and readiness trajectory—then guide what to study next.
CISSP Legal, Privacy & Compliance
CISSP Domain: Domain 1 – Security and Risk Management
CISSP Objective: 1.4 Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
Focus: Legal, Regulatory, Privacy & Compliance Requirements
Summary
CISSP Legal, Privacy & Compliance covers the legal, regulatory, contractual, and privacy requirements security professionals must understand for Domain 1. This pillar guide explores jurisdiction, privacy principles, GDPR, HIPAA, intellectual property, due care, contracts, transborder data flows, evidence, legal holds, and compliance from the risk-based perspective required for the CISSP exam.
Legal, regulatory, privacy, and compliance requirements shape nearly every modern information security program. A CISSP professional must understand not only how to protect systems and data, but also why an organization is obligated to protect them, which requirements apply, who has jurisdiction, and how legal and regulatory obligations influence security decisions.
Within CISSP Domain 1: Security and Risk Management, these concepts are particularly important because security does not operate independently of law, regulation, contracts, privacy obligations, and organizational governance.
For the CISSP exam, the objective is not to become an attorney or memorize every provision of every law. Candidates need to understand the purpose, scope, applicability, jurisdiction, and security implications of major legal and regulatory concepts.
A useful CISSP principle is:
Before implementing a security solution, understand the organization's legal, regulatory, contractual, privacy, and business obligations.
1. Why Legal, Privacy & Compliance Matter to CISSP
Organizations operate within multiple layers of requirements.
These may originate from:
Laws
Regulations
Contracts
Industry requirements
Privacy obligations
Licensing agreements
Organizational policies
Professional standards
International requirements
Security professionals help translate these obligations into security requirements and controls.
For example, an organization may need to:
Protect personal information
Retain records for defined periods
Delete information when no longer permitted or required
Notify affected parties following certain breaches
Preserve evidence
Restrict international data transfers
Protect intellectual property
Maintain audit records
Evaluate third-party security
The security professional should understand these obligations sufficiently to identify risk and involve appropriate legal, privacy, compliance, and management stakeholders.
2. Laws, Regulations, Standards, and Policies
These terms are frequently confused.
Laws
Laws are rules established by governmental authorities.
Failure to comply may result in legal consequences.
Regulations
Regulations are requirements established by authorized governmental or regulatory bodies under applicable legal authority.
They frequently provide more detailed requirements for implementing or enforcing laws.
Standards
Standards define specific requirements, practices, or specifications.
Some standards are voluntary.
Others become effectively mandatory through:
Contracts
Regulations
Customer requirements
Organizational policy
Policies
Policies are internal organizational directives expressing management's requirements and expectations.
CISSP Exam Thinking
Before determining what an organization must do, identify the source of the requirement.
Is it:
Legal? Regulatory? Contractual? Organizational?
The distinction matters.
3. Jurisdiction
Jurisdiction determines which governmental or legal authority has the power to regulate particular activities, organizations, individuals, transactions, or data.
Cybersecurity makes jurisdiction complex because:
Users may be in one country.
Servers may be in another.
The organization may be incorporated elsewhere.
Cloud providers may operate globally.
Personal information may cross multiple borders.
A security professional should not assume that the organization's headquarters determines every applicable legal obligation.
Relevant factors may include:
Location of individuals
Location of data
Location of processing
Organizational establishment
Contractual arrangements
Nature of services
Applicable national or regional law
4. Legal Systems
CISSP candidates should recognize that legal systems differ internationally.
Common legal traditions include:
Common Law
Relies significantly on judicial decisions and precedent in addition to legislation.
Civil Law
Relies heavily on codified statutes and legal codes.
Religious Law
Legal principles may derive partly or substantially from religious doctrine.
Customary Law
Rules may develop from accepted customs and established community practices.
International organizations may therefore encounter significantly different legal environments.
5. Criminal Law
Criminal law addresses conduct considered an offense against society or the state.
Cybercrime examples may involve:
Unauthorized system access
Fraud
Theft
Computer misuse
Destruction of information
Certain forms of malicious software activity
Government authorities generally prosecute criminal cases.
The exact offense and required elements depend on applicable jurisdiction.
6. Civil Law
Civil matters generally involve disputes between individuals, organizations, or other parties.
Cybersecurity-related civil disputes may involve:
Negligence
Contract disputes
Privacy violations
Intellectual property
Employment matters
Failure to provide agreed security protections
Potential outcomes may include monetary damages, injunctions, or other civil remedies.
7. Administrative and Regulatory Law
Organizations may also be subject to rules enforced by government agencies or regulatory authorities.
These bodies may:
Establish requirements
Conduct investigations
Require corrective actions
Impose administrative penalties
Enforce sector-specific obligations
Security programs therefore need mechanisms to identify and monitor applicable regulatory requirements.
8. Due Care and Due Diligence
Legal and compliance discussions frequently intersect with due care and due diligence.
Due Care
Due care involves taking reasonable measures to protect organizational assets and meet responsibilities.
Examples include:
Establishing security policies
Implementing appropriate safeguards
Training employees
Addressing known vulnerabilities
Due Diligence
Due diligence involves the ongoing investigation, monitoring, and verification necessary to ensure appropriate safeguards remain effective.
Examples include:
Audits
Risk assessments
Vulnerability assessments
Control testing
Vendor reviews
Compliance monitoring
A useful distinction is:
Due care is doing what should reasonably be done. Due diligence is continually verifying that it is being done appropriately.
9. Negligence
Negligence generally involves failing to exercise the level of care reasonably expected under applicable circumstances.
From a security perspective, potential concerns arise when an organization:
Knows about serious vulnerabilities but ignores them
Fails to implement reasonable safeguards
Does not enforce established security requirements
Fails to respond appropriately to known risks
Security documentation can become important evidence that the organization identified risks and took reasonable action.
10. Liability
Liability refers to legal responsibility for acts, omissions, or resulting harm.
Security incidents may create potential liability involving:
Organizations
Service providers
Contractors
Business partners
Executives
Employees
Responsibility depends on the specific legal, contractual, factual, and jurisdictional circumstances.
CISSP Perspective
Security professionals should identify and communicate risks, maintain appropriate documentation, and escalate matters through established organizational channels rather than independently attempting to interpret complex legal questions.
11. Privacy
Privacy concerns the appropriate handling of information relating to individuals.
Privacy extends beyond simply keeping information secret.
It may involve:
Collection
Purpose
Processing
Access
Sharing
Retention
Accuracy
Security
Disclosure
Deletion
Individual rights
Privacy vs. Confidentiality
Confidentiality asks:
Who is authorized to access the information?
Privacy asks broader questions:
Why is personal information collected, how is it used, how long is it retained, and what rights does the individual have?
12. Personally Identifiable Information
Personally identifiable information, commonly called PII, generally refers to information that can identify or be linked to an individual.
Examples may include:
Names
Identification numbers
Contact information
Account information
Biometric identifiers
Location information
Online identifiers
Whether particular information legally qualifies as personal information depends on the applicable jurisdiction and regulatory framework.
Exam Principle
Do not assume that only obvious identifiers such as names or Social Security numbers require protection.
Information may become identifying when combined with other data.
13. Sensitive Personal Information
Certain personal information may require greater protection because compromise could create greater harm.
Depending on applicable requirements, examples can include:
Health information
Financial information
Biometric information
Government identifiers
Precise location information
Information about minors
Other specially protected personal attributes
Organizations should apply controls based on sensitivity, legal requirements, business need, and risk.
14. Data Controller and Data Processor
Privacy frameworks frequently distinguish between organizations that determine why and how personal information is processed and organizations that process information on their behalf.
Under GDPR terminology:
Controller
Determines the purposes and means of processing personal data.
Processor
Processes personal data on behalf of the controller.
These distinctions matter because legal and contractual responsibilities can differ.
15. Privacy Principles
Although requirements vary across jurisdictions, mature privacy programs commonly incorporate principles such as:
Lawfulness and Transparency
Personal information should be processed under an appropriate legal basis and with appropriate transparency.
Purpose Limitation
Information should be collected for specified purposes rather than unrestricted future use.
Data Minimization
Collect only information reasonably necessary for the intended purpose.
Accuracy
Personal information should be appropriately accurate and maintained where necessary.
Storage Limitation
Information should not be retained indefinitely without a legitimate reason.
Security
Appropriate safeguards should protect personal information.
Accountability
Organizations should be able to demonstrate appropriate privacy governance and compliance.
16. Data Minimization
Data minimization is particularly important for security professionals.
A simple risk principle applies:
Information that an organization does not collect cannot be exposed from that organization in a breach.
Organizations should avoid collecting or retaining personal information simply because it may become useful someday.
Reducing unnecessary data can reduce:
Privacy exposure
Breach impact
Storage costs
Discovery obligations
Compliance complexity
Attack value
17. Purpose Limitation
Organizations should identify legitimate purposes for collecting and processing personal information.
Using data for unrelated purposes can create privacy and compliance risk.
Security architecture should therefore consider not merely whether a user can access data, but whether that access and processing are appropriate for the authorized purpose.
18. Data Retention
Organizations need defined retention requirements.
Retention periods may be influenced by:
Laws
Regulations
Contracts
Litigation requirements
Business needs
Privacy requirements
Industry obligations
Keeping information indefinitely can increase security and privacy risk.
Deleting information too early can also violate legal, regulatory, contractual, or business obligations.
Therefore:
Retain information for as long as required and justified—not automatically forever.
19. Data Destruction
When information reaches the end of its authorized lifecycle, it should be disposed of appropriately.
Methods depend on:
Data sensitivity
Media type
Legal requirements
Reuse requirements
Risk
Secure disposal can include:
Clearing
Purging
Cryptographic erasure
Physical destruction
Data lifecycle management therefore extends from creation through destruction.
20. GDPR
The General Data Protection Regulation (GDPR) is a major European Union privacy framework with significant international impact.
CISSP candidates should understand its major concepts rather than attempting to memorize the entire regulation.
Important concepts include:
Personal data
Controllers and processors
Lawful processing
Data minimization
Purpose limitation
Data subject rights
Security of processing
Breach notification requirements
International transfers
Accountability
Privacy by design and by default
GDPR can apply beyond organizations physically headquartered in the European Union depending on their activities.
Exam Lesson
Always consider scope and jurisdiction, not merely corporate headquarters.
21. HIPAA
In the United States, the Health Insurance Portability and Accountability Act (HIPAA) and associated requirements are highly relevant to healthcare information.
Important concepts include protection of protected health information (PHI) and requirements affecting covered entities and certain business associates.
Security considerations can include:
Administrative safeguards
Physical safeguards
Technical safeguards
Access controls
Audit mechanisms
Transmission protection
Risk analysis
CISSP Perspective
Know the purpose and security implications rather than attempting to memorize every provision.
22. GLBA
The Gramm-Leach-Bliley Act (GLBA) affects certain financial institutions in the United States.
Its security and privacy implications include protecting customer information and maintaining appropriate safeguards.
For CISSP preparation, understand:
The sector involved
The type of information protected
The general security objective
23. SOX
The Sarbanes-Oxley Act (SOX) addresses corporate governance and financial reporting requirements for applicable organizations.
Security professionals may support SOX-related objectives through controls involving:
Access
Change management
Logging
Integrity
Segregation of duties
Auditability
The CISSP connection is primarily about protecting the integrity and reliability of systems supporting financial reporting.
24. PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) establishes security requirements for organizations handling payment card account data within its scope.
An important CISSP distinction:
PCI DSS is an industry standard, not a government statute.
It can nevertheless create significant contractual and business obligations.
This distinction illustrates why CISSP candidates must differentiate:
Law vs. regulation vs. standard vs. contract.
25. U.S. Computer Crime Law
CISSP candidates should understand that jurisdictions maintain laws addressing unauthorized computer access and related activities.
In the United States, the Computer Fraud and Abuse Act (CFAA) is an important federal statute associated with unauthorized computer access and related offenses.
For exam purposes, focus on its general relevance to computer misuse rather than memorizing statutory language.
26. Intellectual Property
Information security programs also protect intellectual property.
Major categories include:
Copyright
Patent
Trademark
Trade secret
These mechanisms protect different types of intellectual assets.
27. Copyright
Copyright generally protects original creative works.
Examples can include:
Written materials
Software
Images
Music
Documentation
Copyright does not generally protect ideas themselves in the same way it protects their original expression.
Security professionals may encounter copyright issues involving:
Software licensing
Unauthorized copying
Digital content
Proprietary documentation
28. Patents
Patents protect qualifying inventions for a defined period under applicable law in exchange for public disclosure.
Patents can protect certain:
Processes
Technologies
Methods
Inventions
The requirements and duration depend on jurisdiction.
29. Trademarks
Trademarks protect identifiers associated with the source of goods or services.
Examples include:
Brand names
Logos
Symbols
Certain slogans
Their purpose is fundamentally different from copyright and patent protection.
30. Trade Secrets
Trade secrets protect valuable confidential business information when appropriate measures are taken to maintain its secrecy.
Examples may include:
Proprietary formulas
Algorithms
Business methods
Manufacturing processes
Customer information
Internal strategies
Security is particularly important because disclosure can destroy the secrecy that provides the information with its protected value.
Controls may include:
NDAs
Access restrictions
Encryption
Monitoring
Classification
Need to know
31. Software Licensing
Software is subject to licensing terms defining permitted use.
Security professionals should recognize risks involving:
Unauthorized installation
License violations
Open-source obligations
Unauthorized copying
Unsupported software
Asset and software management programs can help organizations maintain compliance.
32. Contracts
Contracts can create security requirements even when no specific law mandates the same controls.
Security-related contractual provisions may address:
Confidentiality
Data protection
Encryption
Incident notification
Audit rights
Service availability
Data retention
Data destruction
Regulatory compliance
Subcontractors
Business continuity
Liability
Security professionals should ensure contractual requirements are identified and translated into appropriate controls.
33. Non-Disclosure Agreements
A Non-Disclosure Agreement (NDA) establishes contractual obligations regarding confidential information.
NDAs may be used with:
Employees
Contractors
Vendors
Partners
Consultants
An NDA does not replace technical security controls.
It is one component of a broader protection strategy.
34. Service-Level Agreements
A Service-Level Agreement (SLA) defines expected levels of service.
Security-related provisions may address:
Availability
Response time
Recovery objectives
Incident handling
Support
Performance
An SLA should contain measurable expectations whenever practical.
35. Right-to-Audit Clauses
Organizations often depend on third parties for critical systems and data.
A right-to-audit provision can establish the organization's contractual ability to assess whether a provider meets agreed security requirements.
Third-party contracts may also include requirements concerning:
Independent assessments
Security certifications
Evidence of controls
Breach reporting
Subprocessor management
36. Transborder Data Flow
Modern organizations routinely transfer information across national boundaries.
Examples include:
Cloud processing
Global employee systems
International customer databases
Offshore support
SaaS applications
Global analytics
Cross-border transfers can create complex legal and privacy requirements.
Security professionals should identify:
Where data originates
Where it is stored
Where it is processed
Who can access it
Which jurisdictions apply
What transfer mechanisms are required
37. Data Localization and Data Residency
These concepts are related but should not automatically be treated as identical.
Data Residency
Generally describes where data is physically or geographically stored.
Data Localization
Generally refers to legal or regulatory requirements requiring certain data to remain or be processed within a particular jurisdiction.
Understanding the distinction is increasingly important in global cloud architectures.
38. Cloud Computing and Legal Responsibility
Cloud adoption does not eliminate legal responsibility.
Organizations remain responsible for understanding:
Data location
Privacy obligations
Contractual requirements
Regulatory scope
Retention
Incident notification
Third-party risk
Shared security responsibilities
A cloud provider's compliance certification does not automatically make every customer workload compliant.
39. Third-Party Compliance
Organizations may outsource services, but they cannot simply ignore the resulting risk.
Third-party governance should consider:
Due diligence
Contractual safeguards
Security requirements
Privacy requirements
Audit rights
Incident reporting
Data return and destruction
Subcontractors
Business continuity
Ongoing monitoring
CISSP Principle
Outsourcing an activity does not necessarily outsource accountability.
40. Breach Notification
Security incidents involving protected information may trigger notification obligations.
Requirements vary by:
Jurisdiction
Type of data
Type of organization
Number or location of affected individuals
Nature of the incident
Applicable regulation or contract
Organizations should therefore have established incident response procedures involving appropriate:
Security
Legal
Privacy
Compliance
Management
Communications
stakeholders.
Security personnel should not independently make legal notification determinations unless that authority is explicitly assigned.
41. Evidence and Investigations
Security incidents can become legal matters.
Evidence must therefore be handled carefully.
Important concepts include:
Identification
Collection
Preservation
Documentation
Integrity
Secure storage
Chain of custody
Poor evidence handling can reduce its usefulness in investigations or legal proceedings.
42. Chain of Custody
Chain of custody documents the possession, handling, transfer, and control of evidence.
Documentation may include:
Who collected the evidence
When it was collected
Where it was stored
Who accessed it
When it was transferred
How integrity was maintained
The objective is to demonstrate that evidence has been appropriately controlled.
43. Legal Hold
A legal hold instructs an organization to preserve potentially relevant information when litigation, investigation, or another legal obligation requires preservation.
Normal deletion or retention schedules may need to be suspended for affected information.
CISSP Exam Principle
When a valid legal hold applies:
Preservation requirements override normal destruction schedules for the relevant information.
44. E-Discovery
Electronic discovery, or e-discovery, involves identifying, preserving, collecting, reviewing, and producing electronically stored information relevant to legal proceedings.
Security professionals may support e-discovery by maintaining:
Appropriate retention
Searchable records
Integrity
Access controls
Logging
Preservation processes
45. Privacy by Design
Privacy should be considered during system design rather than added after deployment.
Privacy-by-design approaches may include:
Data minimization
Purpose limitation
Access control
Encryption
Retention controls
Transparency
Privacy risk assessment
This parallels the broader security principle of secure by design.
46. Privacy by Default
Systems should use privacy-protective defaults where appropriate.
Examples include:
Collecting only required information
Limiting unnecessary sharing
Restricting access
Avoiding indefinite retention
Providing appropriate privacy settings
Privacy should not depend entirely on users discovering and changing insecure defaults.
47. Compliance Monitoring
Compliance is not a one-time exercise.
Organizations need mechanisms to determine whether requirements continue to be satisfied.
These may include:
Audits
Assessments
Control testing
Metrics
Policy reviews
Vulnerability assessments
Third-party reviews
Compliance reporting
Changes in technology, business operations, regulations, and threats can alter compliance requirements.
48. Compliance Does Not Equal Security
This is one of the most important concepts in this pillar.
An organization can satisfy a compliance requirement while still facing substantial cybersecurity risk.
Compliance establishes a required baseline or set of obligations.
Security requires broader risk management.
Therefore:
Compliance should support the security program—not define the maximum extent of security.
The CISSP professional looks beyond checking boxes to determine whether risk is actually being managed.
49. AI, Privacy & Compliance
Artificial intelligence introduces new legal, privacy, governance, and security challenges.
Organizations adopting AI should consider:
Personal data used for training
Sensitive information in prompts
Data retention
Model outputs
Intellectual property
Third-party AI providers
Cross-border processing
Transparency
Accountability
Human oversight
Emerging AI regulations
AI does not replace established security and privacy principles.
It creates additional contexts in which those principles must be applied.
50. Legal and Regulatory Change
Laws and regulations evolve.
Security professionals therefore need processes for identifying changes that affect:
Security controls
Privacy
Incident response
Data retention
Third-party contracts
Cloud services
International operations
Risk management
This typically requires cooperation among:
Security + Legal + Privacy + Compliance + Risk + Business Leadership
No single department should operate in isolation.
51. Common CISSP Legal, Privacy & Compliance Traps
Trap: The security professional should interpret complex law independently
Usually not. Involve qualified legal counsel and appropriate organizational stakeholders.
Trap: Compliance proves security
False. Compliance and effective risk management are related but distinct.
Trap: PCI DSS is a government law
False. It is an industry security standard with contractual significance.
Trap: Cloud providers assume all legal responsibility
False. Customers retain significant responsibilities.
Trap: Personal information means only obvious identifiers
False. Data can identify individuals directly or indirectly depending on context and applicable law.
Trap: Data should always be retained forever
False. Retention should reflect legal, regulatory, contractual, business, and privacy requirements.
Trap: Normal deletion continues during a legal hold
False. Relevant information must be preserved.
Trap: Headquarters determines every applicable privacy law
False. Jurisdiction and applicability can depend on many factors.
Trap: Outsourcing transfers accountability
Not necessarily. Organizations retain important governance responsibilities.
52. High-Yield CISSP Legal, Privacy & Compliance Concepts
Candidates should understand:
Laws vs. regulations
Standards vs. policies
Jurisdiction
Common and civil law concepts
Criminal law
Civil liability
Administrative law
Due care
Due diligence
Negligence
Privacy
PII
Sensitive personal information
Controllers and processors
Data minimization
Purpose limitation
Data retention
Secure destruction
GDPR
HIPAA
GLBA
SOX
PCI DSS
Computer crime laws
Intellectual property
Copyright
Patents
Trademarks
Trade secrets
Software licensing
Contracts
NDAs
SLAs
Right-to-audit
Transborder data flows
Data residency
Data localization
Third-party compliance
Breach notification
Evidence
Chain of custody
Legal holds
E-discovery
Privacy by design
Privacy by default
The exam generally emphasizes application and decision-making, not legal trivia.
53. Legal, Privacy & Compliance Topic Cluster
This pillar should serve as the central hub for deeper Domain 1 pages.
Legal Foundations
Legal and Regulatory Requirements
Jurisdiction and Cybersecurity
Due Care vs. Due Diligence
Negligence and Liability
Computer Crime Laws
Legal Responsibilities of Security Professionals
Privacy
Privacy Principles
Personally Identifiable Information
Data Minimization
Privacy by Design
Privacy by Default
Data Retention and Destruction
GDPR
HIPAA
Compliance
Security Compliance
Compliance vs. Security
PCI DSS
SOX
GLBA
Compliance Monitoring
Security Audits
Intellectual Property
Intellectual Property for CISSP
Copyright vs. Patent vs. Trademark
Trade Secrets
Software Licensing
Contracts & Third Parties
Security Contracts
NDA
SLA
Right-to-Audit
Third-Party Risk Management
Vendor Risk Management
Supply Chain Risk Management
International Data
Transborder Data Flow
Data Residency
Data Localization
International Privacy Requirements
Investigations & Evidence
Chain of Custody
Evidence Handling
Legal Hold
E-Discovery
54. Quick CISSP Knowledge Check
1. An organization processes personal data in several countries. What should the security professional determine first?
Answer: Which legal, regulatory, privacy, and jurisdictional requirements apply.
2. What privacy principle recommends collecting only the information required for a legitimate purpose?
Answer: Data minimization.
3. An organization must preserve records because litigation is anticipated. What mechanism should prevent normal deletion?
Answer: A legal hold.
4. What protects confidential business information that derives value from remaining secret?
Answer: Trade secret protection, provided applicable requirements for maintaining secrecy are met.
5. Is PCI DSS a government privacy law?
Answer: No. It is an industry security standard associated with payment card data and contractual requirements.
6. A company moves regulated data to a cloud provider. Who is responsible for determining whether the arrangement satisfies applicable requirements?
Answer: The organization retains responsibility for understanding and managing its applicable obligations, even though responsibilities may be contractually and operationally shared with the provider.
7. What should a security professional do when a complex legal question arises during an incident?
Answer: Preserve relevant information, follow established procedures, and involve qualified legal and appropriate organizational stakeholders.
55. Exam Thinking: The Legal & Compliance Decision Chain
When a CISSP scenario contains legal, privacy, or regulatory concerns, think:
Business Activity
↓
Information / Asset
↓
Jurisdiction
↓
Applicable Law / Regulation / Contract
↓
Privacy and Security Requirements
↓
Risk Assessment
↓
Management & Legal Guidance
↓
Appropriate Controls
↓
Documentation
↓
Monitoring & Compliance
Do not jump directly to a technical control before determining what obligation actually applies.
Final Takeaway
Legal, privacy, and compliance knowledge gives CISSP professionals the context needed to understand why security requirements exist and how organizational obligations influence risk decisions.
The most important concepts are not isolated law names.
They are the relationships among:
Jurisdiction → Legal obligation → Privacy requirement → Business requirement → Risk → Security control → Evidence → Accountability
CISSP candidates should know major frameworks such as GDPR, HIPAA, GLBA, SOX, and PCI DSS, but the exam is more likely to test whether you can recognize which type of requirement matters and what the security professional should do next.
Remember:
Do not practice law. Identify the issue, protect the organization and its information, preserve evidence when required, document appropriately, and involve the proper legal, privacy, compliance, risk, and management authorities.
That risk-based, governance-oriented approach is central to the CISSP mindset.
Related CISSP Topics
Continue your Domain 1 study with:


