Home › Domain 1: Security & Risk Management
CISSP · Domain 1

Security and Risk Management

Bảo mật & Quản lý Rủi ro · 15% of CISSP Exam

10 Lessons Highest Weight Domain ~22–25 Exam Questions

About This Domain

The largest domain at 15%. Covers professional ethics, governance, risk management frameworks, legal requirements, and business continuity. This domain sets the management mindset for the entire CISSP exam — think like a manager and security leader, not just a technician.

Domain 1 is tested heavily on "what would a CISSP do" scenarios. The correct answer prioritizes business context, governance, and risk management over pure technical solutions. Master this domain and it rewires your thinking for all other domains.

Exam Weight Domain 1 accounts for approximately 22–25 questions on the CISSP exam (15% of 150–175 questions). Risk management (ALE/SLE/ARO), BCP/BIA metrics (RTO/RPO/MTD), and governance policy hierarchy are the highest-frequency topics. Budget ~25% of your study time here.

10 Lessons in This Domain

01
ISC2 Professional Ethics
Đạo đức Nghề nghiệp ISC2
  • • 4 Canons in priority order
  • • Society > Clients > Profession
  • • Duty to report illegal activity
Start Lesson →
02
CIA Triad & Security Concepts
Tam giác CIA & Khái niệm Bảo mật
  • • Confidentiality, Integrity, Availability
  • • Non-repudiation & Authenticity
  • • AAA framework
Start Lesson →
03
Security Governance & Policy
Quản trị Bảo mật & Chính sách
  • • Policy → Standard → Guideline → Procedure
  • • Due Care vs Due Diligence
  • • NIST CSF 5 functions
Start Lesson →
04
Legal, Regulatory & Compliance
Pháp lý, Quy định & Tuân thủ
  • • Criminal vs Civil vs Regulatory law
  • • Decree 13/2023, PH DPA, PCI-DSS
  • • 72-hour breach notification rule
Start Lesson →
05
Quantitative & Qualitative Risk Analysis
Phân tích Rủi ro Định lượng & Định tính
  • • SLE = AV × EF; ALE = SLE × ARO
  • • Qualitative vs Quantitative methods
  • • Risk Appetite & Residual Risk
Start Lesson →
06
Risk Treatment, Frameworks & Residual Risk
Xử lý Rủi ro & Khung Quản lý
  • • Mitigate, Accept, Avoid, Transfer
  • • NIST RMF 7 steps
  • • Risk register & formal acceptance
Start Lesson →
07
Business Continuity & BIA
Liên tục Kinh doanh & Phân tích Tác động
  • • MTD, RTO, RPO, WRT definitions
  • • BCP vs DRP relationship
  • • Recovery site types & testing tiers
Start Lesson →
08
Personnel Security & Insider Threat
Bảo mật Nhân sự & Mối đe dọa Nội bộ
  • • Separation of Duties & Dual Control
  • • Mandatory vacation & job rotation
  • • Social engineering attack types
Start Lesson →
09
Threat Modeling & Threat Intelligence
Mô hình Mối đe dọa & Tình báo Bảo mật
  • • STRIDE: 6 threat categories
  • • IOC vs IOA distinction
  • • MITRE ATT&CK & APT concepts
Start Lesson →
10
Supply Chain Risk & Security Awareness
Rủi ro Chuỗi Cung ứng & Nâng cao Nhận thức
  • • Vendor due diligence & SOC 2 Type 2
  • • SBOM & software supply chain risks
  • • Awareness vs Training vs Education
Start Lesson →

Domain 1 Full Quiz

Complete all 10 lessons before attempting the full domain quiz. The quiz covers all concepts across all lessons with 25 mixed questions at exam difficulty.

Coming Soon — Complete all lessons first