Overview
Exam Objectives
The following exam objectives will be discussed in this document:
- Understand and apply concepts of confidentiality, integrity, and availability.
- Apply security governance principles.
- Compliance
- Understand legal and regulatory issues that pertain to information security in a global context.
- Understand professional ethics.
- Develop and implement documented security policy, standards, procedures, and guidelines.
- Understand business continuity requirements.
- Contribute to personnel security policies.
- Understand and apply risk management concepts.
- Understand and apply threat modeling.
- Integrate security risk considerations into acquisition strategy and practice.
- Establish and manage information security education, training, and awareness.
This module refers to the CISSP Security and Risk Management domain. In order to fully understand this topic, please refer to your course material or use your favorite search engine to research this topic in more detail.