# CISSP Domain 1 — think like a manager, then treat the risk

Source: https://ai.techclick.in/blog_cissp_d1_risk_management
Markdown: https://ai.techclick.in/blog_cissp_d1_risk_management.md
Publisher: Techclick Infosec Pvt Ltd

CISSP Domain 1 manager lesson: five security pillars, risk treatment (accept avoid mitigate share transfer), policy vs standard, due care vs due diligence. Official ISC2 outline + well-known CBK.

Quick answer

    FIRST  is almost never a purchase. Identify the asset and owner, assess threat × vulnerability × impact against risk appetite, then treat:  mitigate  (control),  transfer / share  (insurance or partner),  avoid  (stop the activity), or  accept  (owner signs residual risk). A  policy  is high-level and mandatory. A  standard  is mandatory and specific. A  procedure  is the how. A  guideline  is optional.  Due diligence  is the homework.  Due care  is acting on it. When ethics collide, ISC2 Canon I — society and the common good — wins.

   Say this out loud

   I do not buy a control first. I frame the risk, pick a treatment the business can live with, write the right document, and leave evidence that I both knew and acted.

## 1. Why the manager move comes first

 Interview, 40 minutes in. “We are onboarding a third-party credit-scoring model next sprint. What does the security professional do  first ?” The engineer answers “put a WAF in front and turn on MFA.” That is a control. It is not first.

 ISC2 Domain 1 — Security and Risk Management — is the heaviest domain on the official April 2024 exam outline (16%). The outline is not asking you to configure the WAF. It is asking whether security is aligned to the business, whether you can treat risk, and whether you can prove you were not negligent.

   Hero · pillars sit on the register, not on a product SKU

   Notice: the tablet is the work. Confidentiality, integrity, and availability are how you describe harm to an asset — they are not three products you buy.

 Three reasons this domain fails people who are otherwise strong operators:

- FIRST / BEST / PRIMARY are sequencing words. They pull you one layer above the technical fix — policy, risk assessment, owner decision.

- Security enables the mission. Blocking the business is rarely the BEST answer. Secure enablement is.

- Evidence beats intent. After an incident, counsel will ask what you knew (diligence) and what you did (care). A tool with no signed residual-risk memo is a gap.

   Hard words before the runbook

    Risk  — a function of threat, vulnerability, and impact on an asset. Not a synonym for “vulnerability.”

    Risk appetite  — how much risk the organization is willing to take to pursue its mission. Set by senior management / the board, not by the SOC.

    Residual risk  — what is left after treatment. Someone with authority must accept it in writing.

    Data / asset owner  — business role that classifies the asset and accepts residual risk. Security advises and implements.

    Due diligence  — research, assessment, vendor review, ongoing investigation. Knowing.

    Due care  — taking the reasonable actions a prudent professional would take. Doing.

## 2. Mental model · pillars, owners, documents

 Hold three parts. Interviews fail when people treat CIA as a slogan, treat “policy” as any PDF, or let security decide residual risk.

   Journey · identify, assess, treat, prove

   Read left to right. Prove is not optional decoration. If you cannot show the assessment and the owner’s sign-off, you did not finish the cycle.

### Part 1 · five pillars, not three slogans

 The official CISSP outline (objective 1.2) names  confidentiality, integrity, availability, authenticity, and non-repudiation  as the five pillars of information security. CIA is still the everyday triad. The 2024 wording adds the two proof pillars so you do not stop at “keep it secret, keep it intact, keep it up.”

#### Confidentiality

     Unauthorized disclosure. Encryption, classification, need-to-know. A leak of loan files is a C failure even if the system stayed up.

#### Integrity

     Unauthorized modification. Hashing, change control, input validation. A silently edited credit score is an I failure.

#### Availability

     Timely, reliable access. Redundancy, backups, DDoS defense. In a hospital or OT plant, A (and safety) can outrank C.

#### Authenticity + non-repudiation

     Authenticity proves origin or identity. Non-repudiation means the actor cannot later deny the action — typically digital signatures and audit trails, not “we have logs.”

   Common trap

   Do not force “confidentiality always wins.” That is a study-guide shortcut, not the outline. Safety-critical and availability-critical missions flip the default. Read the scenario, not the mnemonic.

### Part 2 · governance is top-down

 Objective 1.3: align security to business strategy, mission, and objectives. Board and senior management set appetite and sponsor policy. The CISO designs the program. Owners classify. Custodians implement. Users comply. Bottom-up “we wrote a standard in the SOC and emailed it” is not governance.

 Due care and due diligence sit in the same objective. Diligence is the investigation that tells you the plant still has unpatched HMIs. Care is the reasonable action you take once you know — patch, compensate, or get a signed exception. Knowing and doing nothing is the negligence story.

### Part 3 · the document stack is not four names for one PDF

 Objective 1.6 is four artifacts with different force. If the sentence is high-level and mandatory, it is a policy. If it names a specific required value, it is a standard. If it is a numbered how-to, it is a procedure. If it says “should” with no penalty, it is a guideline. A baseline is the minimum mandatory configuration — closer to a standard than to a wish.

   Flow 1 · document force, top down

       Policy, standard, procedure, and guideline stack

- Governance documents · who they bind Policy · mandatory · why and what Board / senior management. “Information shall be protected according to classification.” Standard · mandatory · specific criteria “Production data at rest SHALL use AES-256.” Baseline lives here. Procedure · mandatory · how, step by step “Open ticket → take snapshot → apply patch → verify CVE closed.” Guideline · recommended, not enforced “Teams should preferably rotate keys every 90 days.” Read top → bottom. Width = force. Magenta border = optional. If the exam sentence has SHALL plus a number, it is a standard, not a policy. Say this out loud Policy is the why. Standard is the required number. Procedure is the how. Guideline is advice. Owners classify. Security implements. Residual risk is not mine to accept silently. ## 3. Decision flow · treat the risk Decision · treat or accept is not the first diamond Caption, not the art: you only reach Treat vs Accept after the risk is identified and compared to appetite. Skipping the assessment is the engineer-brain miss. Flow 2 · from ticket to treatment Decision flow from new activity to risk treatment New system, vendor, or AI activity Identify asset + owner Assess threat × vuln × impact Above appetite or legal floor? no Accept owner signs yes · treat Can we stop the activity? Avoid do not do it yes no · stay in business Shift to a third party / insurer? Transfer / share insurance, partner yes Mitigate control, then residual Read top → bottom. Diamond = decision. Green border = you can stay in the activity. NIST’s risk-response language is accept, avoid, mitigate, share, or transfer — “ignore” is not on the list. NIST SP 800-39 / 800-30 / 800-37 use that five-verb list. CISSP stems still lean on the four-word CBK set mitigate, transfer, avoid, accept . Share is the close cousin of transfer (you keep some of the risk; a partner or captive takes the rest). Cybersecurity insurance is the outline’s own example under 1.9 risk response and treatment. ## 4. How to choose treatment and document type Use the tables, then the numbers. Qualitative ranking is fast and good enough for most FIRST questions. Quantitative numbers show up when the stem hands you rupees or dollars and asks whether the control is worth it. If the ticket looks like… Treatment Who signs We will keep doing this; a control will lower likelihood or impact. Mitigate (apply preventive / detective / corrective controls). Owner accepts leftover residual risk after the control. A contract or policy can move impact to an insurer or processor. Transfer or share . Legal + owner. Insurance does not transfer reputation or regulatory duty. The activity itself is the problem (shadow AI, unsanctioned region). Avoid — do not start, or shut it down. Business leadership. Security does not “avoid” by hiding the request. After treatment, leftover risk sits inside appetite. Accept . Asset / data owner, or the authorizing official in an RMF shop. Nobody wrote it down and the team “will watch it.” Not a treatment. This is ignore — the trap answer. Nobody valid. Exam: never pick ignore. Wording in the document Artifact Force “The organization shall protect customer data.” Policy Mandatory, high-level, management-approved. “Production systems SHALL use AES-256 / 14-character passwords.” Standard (or baseline) Mandatory, measurable. Audit can fail you. “Step 1 snapshot. Step 2 patch. Step 3 verify CVE.” Procedure Mandatory how-to. Operators follow it. “Teams should preferably rotate keys every 90 days.” Guideline Advice. No penalty if skipped. ### Qualitative vs quantitative — well-known CBK math When the stem gives money, use the classic formulas. They are well-known CBK, not an ISC2-invented “exam percentage.” Quantitative risk — remember the chain SLE = AV × EF ALE = SLE × ARO Compare: cost of control vs reduction in ALE AV is asset value. EF is the fraction lost in one event. SLE is one-event loss. ARO is how often per year. ALE is expected yearly loss. A control that costs more than the ALE it removes is usually a poor BEST answer unless a law or contract forces it. Qualitative work uses High / Medium / Low (or a 5×5 matrix) when you do not have clean numbers. Use it to rank. Do not pretend a red cell is a rupee figure. Frameworks the outline actually names Objective 1.3 and 1.9 list ISO, NIST, COBIT, SABSA, PCI, and FedRAMP as examples — plus cybersecurity insurance under treatment. Pick the framework the scenario already lives in (federal system → RMF / FedRAMP; card data → PCI as a contractual standard). Do not invent a “best framework for 40% of the exam.” ## 5. Runbook · Side A assess, B treat, C prove This is not a vendor console path. It is the Domain 1 operating path you walk on a new system, a new vendor, or a new AI use case. Each side cites one primary source. ### Side A · identify and assess (due diligence) Primary source: NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments . #### Name the asset and the owner What is at risk — data, process, model, plant, reputation? Who in the business classifies it? If nobody will claim ownership, stop. Security does not become the owner by default.

- #### Identify threats and vulnerabilities Threat is the actor or event. Vulnerability is the weakness. A CVE with no realistic threat against this asset is not automatically high risk. Include supply-chain items the outline calls out in 1.11: counterfeit, implant, weak third-party, missing SBOM, no silicon root of trust.

- #### Scope the assessment Which systems, which data types, which jurisdictions? GDPR is in the official privacy example list. PCI is contractual, not a statute. Investigation type (objective 1.5) matters later if this becomes an incident — administrative, criminal, civil, regulatory, or industry-standard — but you do not pick a lawyer before you have a risk picture.

- #### Estimate likelihood and impact Qualitative matrix unless the stem gives money. If it gives money, compute SLE and ALE. Record assumptions. That record is diligence evidence.

### Side B · treat and write the right document

 Primary source:  NIST CSRC glossary — risk response  (accept, avoid, mitigate, share, transfer) and ISC2 outline 1.6 / 1.9.

- #### Compare to appetite and to any legal floor Even a “cheap” risk can be unacceptable if a regulation forbids it. Legal floors are not optional appetite.

- #### Pick one primary treatment Mitigate with a control type the outline names — preventive, detective, or corrective — or transfer/share, or avoid. Then compute leftover residual risk. Do not stack four treatments as a way to avoid a decision.

- #### Write the matching artifact If leadership is stating intent, that is a policy update. If you are locking AES-256, that is a standard. If ops must patch in 14 days, that is a procedure. If you are offering a tip, that is a guideline — and a guideline will not save you in an audit of a SHALL.

- #### Handle people and vendors in the same cycle Outline 1.8: screening, agreements, onboarding, transfer, termination, contractor controls. Outline 1.11: minimum security requirements and service levels in the contract. A control that ignores the joiner-mover-leaver path is an incomplete treatment.

### Side C · prove due care

 Primary source: ISC2 outline 1.3 (due care / due diligence) and  NIST RMF Authorize + Monitor .

- #### Get the owner’s signature on residual risk In an RMF environment the authorizing official makes the risk-based decision to operate. In a commercial shop the data/asset owner (or a documented risk committee) signs. A Slack “looks fine” is not acceptance.

- #### Show the control is in place and working Assessment evidence: config, ticket, scan, tabletop, awareness metrics. Outline 1.12 wants awareness that is role-based and measured — phishing simulations, champions — not a once-a-year video.

- #### Put it on the register and keep watching Continuous monitoring and reporting (1.9) is how diligence stays current. A one-time review at go-live is a due-diligence miss.

   Green path — you finished Domain 1 work when

   Asset and owner are named. Assessment is on file. Treatment is explicit. The matching policy/standard/procedure exists. Residual risk has a dated owner signature. A monitor owner will look at it again.

## 6. Runtime path after the sign-off

 Go-live is the Authorize step, not the end. NIST RMF’s seven steps are Prepare → Categorize → Select → Implement → Assess → Authorize → Monitor. Domain 1 lives hardest in Prepare, Assess, Authorize, and Monitor. The other steps still happen; they just move toward Domains 2, 3, and 7.

   Proof · residual risk is a signed fact, not a vibe

   Notice: the stack of signed pages is the care. The green screen is only useful if it matches that file.

   Flow 3 · after authorization

       Runtime path after residual-risk acceptance

- Authorize owner / AO signs Operate controls stay on Monitor KRIs, audits, drift Re-assess change, incident, AI Retreatment or re-accept Read left → right. A new vendor model, a merger, or a failed control sends you back to Side A. Acceptance expires when the facts change. Business continuity sits in the same domain (objective 1.7). The business impact analysis comes before recovery-strategy shopping. Well-known CBK metrics: MTD (how long the business can stand the outage), RTO (how fast IT comes back), RPO (how much data you can lose). Recovery design that cannot meet the BIA is not a continuity plan — it is a hope. Full IR / DR mechanics live in Domain 7; Domain 1 only needs you to insist on the BIA first. ## 7. Traps + proof checklist Stem pattern What ISC2 is testing Engineer trap Manager move What do you do FIRST? Sequencing. Diligence before tooling. Buy / enable / block now. Identify asset + assess risk (and policy if none exists). What is BEST / MOST cost-effective? Risk economics and completeness. Cheapest SKU, or the fanciest SKU. Treatment whose leftover risk the owner can accept; control cost vs ALE. New vendor / AI / acquisition Third-party and organizational process (1.3, 1.11). Pilot in production, then write policy. Risk assessment and contract requirements first. Access or classification dispute Roles (1.3). Owner decides. CISO or admin decides. Data / asset owner classifies and approves. Public harm vs employer order Ethics canons (1.1). Protect the company quietly. Canon I: society, common good, infrastructure first. PCI vs GDPR vs “Indian law” Regulatory vs contractual (1.4). Only statutes count. PCI is contractual and still binding. Privacy laws named in the outline include GDPR and others; apply the ones the data subjects trigger. “Should preferably” document Policy vs standard vs guideline (1.6). Call it a standard because it has a number. Optional wording = guideline. We reviewed once at launch Due diligence is ongoing (1.3, 1.9). One review = care. Monitor, re-assess, report. Care is the action you keep taking. Ethics canons — official wording, official order From the ISC2 Code of Ethics : (1) Protect society, the common good, necessary public trust and confidence, and the infrastructure. (2) Act honorably, honestly, justly, responsibly, and legally. (3) Provide diligent and competent service to principals. (4) Advance and protect the profession. When they collide, start at Canon I. Complaints must name a canon; Canon III complaints come from principals, Canon IV from other professionals. Pilot / interview proof checklist I can say the five pillars without stopping at CIA.

- I can point to the owner on a real system I have touched.

- I can classify one document on my desk as policy, standard, procedure, or guideline from its verbs.

- I can pick a treatment and say who signs residual risk.

- I can explain diligence vs care in one sentence each.

- I can recite the four canons in order.

- I did not quote a made-up “this subtopic is X% of the exam.” Domain 1’s official weight is 16% of the whole exam — that is the only percentage this page uses.

   Interview angle

    Weak:  “Domain 1 is CIA and policies.”  Strong:  “I assess before I buy. Policy is mandatory intent, a standard is a mandatory number, a guideline is optional. Diligence is what I knew; care is what I did. Residual risk is an owner signature, not a SOC opinion. If public safety is on the table, Canon I beats the employer ticket.”

## Knowledge check

   Six judgment items. Map each one to a FIRST/BEST stem, not a definition. Check answers, then reset and retry the misses.

       Q1
       Leadership wants a third-party LLM scoring loans next sprint. An engineer opens a purchase request for a WAF and MFA licenses. What does the security professional do FIRST?

           Approve the WAF so the sprint is not blocked
           Write a procedure for prompt-injection response
           Perform a risk assessment of the activity, including third-party / supply-chain risk, before the tool
           Refuse the project until the firm holds an ISO 27001 certificate

       Correct:  c . FIRST on a new vendor or AI use case is assessment and governance, not a purchase. A procedure is later. ISO 27001 is not a prerequisite invented by the stem. Re-read  Decision flow  and Side A.

       Q2
       A document states: “All production systems SHALL encrypt data at rest with AES-256.” It is mandatory and names a specific algorithm. What is it?

           A policy, because management wants encryption
           A standard (or baseline) — mandatory and specific
           A guideline, because encryption is a best practice
           A procedure, because operators will configure it

       Correct:  b . SHALL plus a measurable value is a standard. A policy would stay high-level. A procedure would list steps. A guideline would say “should.” Re-read  Mental model  and the choose table.

       Q3
       After a breach, counsel asks whether the CISO “knew the plant still ran unpatched HMIs and failed to act.” Which distinction answers them?

           Due diligence is assessing and knowing; due care is taking reasonable action
           Due care is the vendor questionnaire; due diligence is the insurance policy
           The two terms are synonyms for “we have a policy”
           Due diligence applies only to new hires, not to systems

       Correct:  a . Outline 1.3 pairs the terms. Knowing without acting is a care failure; acting blindly without assessing is a diligence failure. Insurance and hiring screens are examples, not the definition. Re-read hard words and Side C.

       Q4
       A WAF cut ALE from $400,000 to $40,000. The leftover $40,000 is inside documented appetite. Leadership signs a memo to live with it and buys nothing else. What is that final decision, and who should sign?

           Avoidance, signed by the SOC analyst
           Acceptance of residual risk, signed by the asset / data owner
           Transfer, signed by the WAF vendor
           Ignore, because the number is small

       Correct:  b . Mitigation already happened. Living with leftover risk inside appetite is acceptance, and the owner (or authorizing official) signs. Ignore is never a treatment. Re-read  How to choose .

       Q5
       An employer tells a CISSP to hide a flaw that will almost certainly harm public infrastructure. The professional’s own job is at risk if they speak. Which ethics move is correct?

           Protect the employer first — Canon III always outranks the others
           Protect society, the common good, public trust, and the infrastructure — Canon I first
           Advance the profession by posting the exploit on a public forum tonight
           Stay silent; ethics canons are optional study material

       Correct:  b . Official canons are ordered. Society and infrastructure come before principals. Canon IV is not “dump an exploit.” The preamble also says strict adherence is a condition of certification. Re-read the ethics callout in  Traps .

       Q6
       A safety-critical plant asks which pillar to privilege if a control that encrypts an HMI also makes the emergency stop too slow. What is the Domain 1 judgment?

           Confidentiality always outranks the other pillars
           Non-repudiation, because every stop must be signed
           Availability and safety may outrank confidentiality in this mission — assess, then treat
           Integrity is irrelevant on OT networks

       Correct:  c . Do not apply a “C always wins” slogan. The mission (and Canon I) can flip the triad. You still assess; you do not blindly drop encryption without a treatment and an owner. Re-read  Mental model .

       Check answers
       Reset

## Sources

- ISC2 — CISSP Certification Exam Outline (effective 15 April 2024). Domain 1 weight 16%. Objectives 1.1–1.12 used as the spine of this lesson. No other exam percentages are claimed.

- ISC2 — Code of Ethics (preamble + four canons, official wording).

- NIST — SP 800-37 Rev. 2, Risk Management Framework (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor).

- NIST — SP 800-30 Rev. 1, Guide for Conducting Risk Assessments .

- NIST — CSRC glossary: risk response — accept, avoid, mitigate, share, or transfer (from SP 800-39 / 800-37 / 800-30).

- NIST — SP 800-34 Rev. 1, Contingency Planning Guide (BIA before recovery strategy; RTO / RPO as well-known CBK metrics).

- Well-known CBK (not an ISC2 percentage claim): SLE = AV × EF; ALE = SLE × ARO; policy / standard / procedure / guideline force; owner vs custodian.

 Related:  CISSP overview (all 8 domains)  ·  Domain 2: Asset Security  ·  Domain 1 assessment  ·  8-week roadmap

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
