CISSP · Domain 1 of 8 by weight
Security and Risk Management
By Falakhe Sivela · Updated 2026-07-13
Security and Risk Management accounts for 16% of the ISC2 CISSP — roughly 20 of the 125 questions you will see. It is the heaviest domain on the exam, so it decides more of your score than any other, and weakness here cannot be offset elsewhere.
What this domain actually tests
The heaviest domain on the CISSP, and the foundation of the entire exam. Its mindset infects every other question, which means weakness here does not stay contained — it costs you marks in domains you thought you knew.
Governance, risk, legal and regulatory concepts, and business continuity.
The risk maths, which appears as straight arithmetic:
- SLE = Asset Value × Exposure Factor
- ALE = SLE × ARO (Annual Rate of Occurrence)
If a control costs less per year than the ALE it eliminates, you implement it. That is the whole calculation, and it is free marks.
The four risk responses: accept, avoid, transfer (insurance), mitigate.
The traps
Due care versus due diligence
Tested directly, and confused constantly:
- Due care — doing what a reasonable person would do. The action. The "prudent person" standard.
- Due diligence — the ongoing research, investigation, and monitoring that informs it. The homework.
You do your due diligence (investigate the vendor) and then exercise due care (act on what you found). Diligence first, care second.
The document hierarchy
- Policy — mandatory, high-level, from senior management.
- Standard — mandatory, specific.
- Procedure — step-by-step, how.
- Guideline — optional, recommended.
Guidelines are the only optional one.
Business continuity, in order
The BIA (Business Impact Analysis) comes first. You cannot plan continuity until you know what matters and what it costs when it stops. If a question asks what the first step of BCP is, it is the BIA — not writing the plan, not buying a hot site.
Then the metrics: RTO (how long you can be down), RPO (how much data you can lose), MTD (maximum tolerable downtime — the ceiling that RTO must fit inside).
The managerial mindset lives here
This domain is where "think like a manager" is trained. Human safety always comes first. Then risk assessment. Then process. Only then the technical fix.
When a question asks what to do FIRST, the engineer's instinct — patch, block, isolate — is usually the distractor. The answer usually assesses, communicates, or follows the documented plan.
How to study it
Do the risk formulas once, properly, and they are yours permanently.
Then, for every practice question in every domain, ask before you look at the options: is there an answer at the policy, process, or risk level? Evaluate that one first, and make the technical option beat it. That habit is what this domain is really teaching, and it is worth more than any individual fact in it.
Sixteen percent by weight — and far more than that in influence.
What this domain covers
- Security governance and compliance frameworks
- Risk assessment, treatment, and metrics
- Business continuity and disaster recovery
- Legal, regulatory, and privacy requirements
These are the topics Prepa uses to generate CISSP practice questions for this domain, so your practice is weighted the way the exam is.
The other CISSP domains
- Security and Risk Management (this page)16%
- Asset Security10%
- Security Architecture and Engineering13%
- Communication and Network Security13%
- Identity and Access Management13%
- Security Assessment and Testing12%
- Security Operations13%
- Software Development Security10%
For the full exam format, scoring, and a study plan, read the CISSP Study Guide.