CISSP Certification Guide / Chapter 3
Governance, Compliance, and Legal Frameworks
The governance stack that decides who is accountable, the legal map of criminal, civil, and regulatory law, the regulations and standards that bind security programs, contracts and intellectual property, compliance as a program, and the ISC2 Code of Ethics.
The failures nobody blames on technology
Every significant security incident in the news has a technical chapter: the misconfigured server, the unpatched router, the credential that should have expired. But the part of the story that decides whether the same incident happens again is never technical. It is the part where somebody decided what the security program could spend, who was allowed to approve exceptions, what the organization was legally required to do with the data, and who had to answer to the board when it went wrong. Those decisions are governance, and the CISSP treats them as the heart of Domain 1 because they are the heart of the discipline.
Here is the uncomfortable fact that organizes this chapter: security professionals are rarely the ones who cause catastrophic failures, and they are rarely the ones who authorize them either. The failure happens when an accountable executive accepts a risk nobody wrote down, or when a compliance deadline and a real-world threat get treated as the same thing, or when an engineer finds something wrong and the organization has no defined path for what happens next. The exam knows this. That is why so many Domain 1 questions do not ask what control to install. They ask who owns the decision, what obligation binds the organization, and what a responsible professional does when the law, the contract, and the ethics code pull in different directions.
This chapter maps that territory in five movements: the governance stack and who answers for what, the legal map of criminal, civil, and regulatory law, the catalog of regulations that bind real organizations, the contract and intellectual property layer where obligations become negotiated terms, and the ISC2 Code of Ethics that binds you personally. The chapter closes with a decision ladder for governance questions and a practice set. Chapter 4 takes the risk mathematics that governance decisions consume, and Chapter 9 treats privacy regulation at the depth it deserves.
Governance is the system by which organizations are directed
The classic definition, from the 1992 Cadbury Report on corporate governance, is still the best one: corporate governance is the system by which companies are directed and controlled. Notice what that sentence does. It separates direction from execution before you even start. Governance is the layer that decides where the organization is going, how much risk it is willing to carry to get there, and who is accountable when things go wrong. Management is the layer that executes within those decisions. Security governance is simply that same system applied to security: the board and executives set the security direction, delegate authority, fund the program, and hold people accountable, while the security team designs and runs the controls.
The distinction matters for the exam more than any single regulation in this chapter, because governance questions are really accountability questions. When a scenario offers a CISO who “takes responsibility” for a business decision, or an analyst who “accepts” a risk on the board’s behalf, the exam is testing whether you know that accountability flows downward from the board, not upward from the technicians. Authority to accept risk belongs to whoever has the standing to bear its consequences, which is almost never the person who found the risk.
The governance stack, from the top, looks like this:
| Layer | Role | What they answer for |
|---|---|---|
| Board of directors | Direction, fiduciary duty, oversight | Strategy, risk appetite, executive accountability |
| Audit and risk committees | Deep-dive oversight | Financial reporting integrity, internal control, top risks |
| Chief executive and executive team | Run the enterprise within board direction | Execution, disclosure, culture |
| Chief information security officer | Run the security program | Program effectiveness, reporting to executives and board |
| Security steering committee | Cross-functional prioritization | Portfolio of security initiatives, funding decisions |
| Operational managers | Own and operate the controls | Day-to-day control effectiveness in their processes |
Two features of this stack deserve emphasis because exam scenarios lean on them. First, the CISO is a staff role with authority delegated from above. The CISO does not own the business; the CISO advises, designs, and reports, and the business line managers own the risk their processes create. A CISO who must “accept” a business unit’s residual risk without executive backing is a symptom of broken governance, not a correct answer. Second, the steering committee exists because security priorities are business priorities. When security and operations want different things, the resolution is not a shouting match between two departments, it is a documented decision made at the level that can weigh both.
The three lines of defense model, published by the Institute of Internal Auditors, is the cleanest expression of how modern organizations divide control responsibility, and it appears in exam questions almost verbatim. The first line is operational management: the teams that own processes and run the controls inside them, detect their own errors, and fix them. The second line is the risk and compliance function: it monitors, challenges, and supports the first line, sets the frameworks, and reports on risk posture. The third line is internal audit: independent assurance that the first two lines actually work, reporting to the audit committee, not to the functions it reviews. The exam question to expect is a description of a team doing one of these jobs and a prompt to name the line, or a description of an audit that reports to the people it audits, which is a governance violation you should recognize instantly.
Frameworks give this structure bones. COSO’s Internal Control-Integrated Framework (2013) defines the five components of internal control: control environment, risk assessment, control activities, information and communication, and monitoring, and it is the conceptual ancestor of most audit and control programs in the world. COBIT, published by ISACA and updated to COBIT 2019, frames governance of enterprise IT around stakeholder needs, value delivery, and risk optimization. ISO/IEC 27001:2022, the information security management system standard, makes governance an auditable requirement: clause 5 obliges top management to demonstrate leadership, establish the security policy, and assign roles, so an organization cannot claim ISO certification without a functioning governance layer. On the US federal side, NIST Special Publication 800-100, the Information Security Handbook, lays out the governance elements of an agency security program. You do not need to memorize clause numbers, but you do need the pattern: every serious framework makes governance mandatory, because controls without accountability decay.
Governance produces artifacts, and those artifacts are exam material. The charter of the security committee defines its authority and membership. The risk appetite statement, approved by the board, says how much risk the organization will tolerate, and it is the yardstick every risk decision is measured against. The security metrics program, reported upward, turns governance from vibes into numbers. And the documentation hierarchy of policy, standard, procedure, and guideline is the operational expression of governance, treated in full in Chapter 6. For now, hold the direction of authority: policy comes from the accountable executive layer, standards and procedures execute it, and guidelines advise.
The legal map: criminal, civil, and regulatory
Governance tells you who decides. Law tells you what the organization cannot decide away. The CISSP expects you to navigate four kinds of law, and the exam usually tests them by describing a proceeding and asking you to identify its kind, or by giving you a fact about a law and asking which legal domain it belongs to.
Criminal law is the state against the individual or corporation. The government prosecutes, the standard of proof is beyond a reasonable doubt, and the penalties include fines, imprisonment, and reputational destruction. Criminal law is where computer misuse lives in most jurisdictions: in the United States, the Computer Fraud and Abuse Act, 18 U.S.C. section 1030, is the primary federal statute against unauthorized access to computers, and it has been amended repeatedly since 1986 to keep pace with the ways access is abused. Note what the CFAA actually criminalizes: accessing a computer without authorization, or exceeding authorized access, to obtain information, cause damage, commit fraud, or traffic passwords, with severity tiers based on the harm done.
Civil law is between private parties. A company sues its former contractor, a customer sues a breached vendor, an employee sues a former employer. The standard of proof is preponderance of the evidence, roughly meaning more likely than not, the remedy is money damages or an injunction rather than prison, and the trigger is a wrong that harms a private interest: a broken contract, a tort such as negligence, or an interference with property rights. Civil law matters to security professionals because nearly every breach eventually produces civil litigation, and because contracts (covered below) are creatures of civil law.
Administrative and regulatory law is the layer where agencies act. Administrative law covers agency rulemaking and adjudication: the FTC bringing a deceptive-practices action, a state insurance commissioner fining a carrier, an agency enforcing its own regulations. The same conduct can produce criminal, civil, and regulatory proceedings in parallel, and a defense attorney’s nightmare is exactly that stack: a breach leads the FBI to investigate criminally, shareholders to sue civilly, and the FTC and state attorneys general to proceed administratively, all at once.
The four kinds of investigations mirror the four kinds of law, and Domain 1 expects you to keep them straight. A criminal investigation gathers evidence for prosecution, in which collection standards are strictest because liberty is at stake. A civil investigation supports a lawsuit, typically for damages or an injunction. An administrative investigation is internal: an employer’s HR review or a compliance office’s inquiry into a policy violation, governed by the employer’s own rules. A regulatory investigation is conducted by an agency exercising its statutory powers, with its own procedural rules and evidentiary standards. The CISSP scenario to expect: an incident happens and the question asks which kind of investigation it is, which standard of proof applies, or who gets what. If the facts mention police and possible imprisonment, it is criminal. If the facts mention a lawsuit for money, it is civil. If the facts mention an internal policy review, it is administrative. If the facts mention a regulator with a subpoena, it is regulatory.
Jurisdiction is the quiet trap in this map. Law is territorial in ways that data is not. An offense occurs where the act occurs, where the victim is, or where the effect is felt, and different rules apply on all three, which is why the same incident can be prosecuted in multiple countries. Transborder data flows collide with territorial law constantly, and this collision produced the two dominant legal facts of the modern privacy era: the European Union regulates data about people inside the EU regardless of where the processor sits, and every serious contract now answers two questions before any dispute exists: which law governs, and where will disputes be heard.
The compliance catalog: obligations, not trivia
Here is the organizing principle for every regulation in this chapter: obligations come from three sources only, and every control an organization implements can be traced to one or more of them. Law, which the state enforces. Contract, which the parties enforce. And policy, which the organization enforces on itself. A bank’s encryption control is simultaneously a legal requirement, a contractual promise to customers, and an internal standard. When you see a compliance question, first ask which of the three sources is being tested, because the exam deliberately confuses them.
The catalog below is the one a working security professional actually meets. It is organized by the business context that triggers each obligation, not by alphabet, because the trigger is what exam questions test.
| Regime | Who it binds | What it requires | Version anchor |
|---|---|---|---|
| GDPR | Organizations processing personal data of people in the EU/EEA | Lawful basis, data subject rights, breach notification, accountability, transfers | Regulation (EU) 2016/679 |
| HIPAA and HITECH | Covered entities and business associates in US healthcare | Privacy, security, and breach notification for protected health information | HIPAA 1996, HITECH 2009 |
| Sarbanes-Oxley | US public companies | CEO/CFO certification, internal control assessment, auditor independence, whistleblower protection | SOX 2002 |
| GLBA | Financial institutions | Privacy notices, consumer opt-out, safeguards for customer information | GLBA 1999 |
| CCPA and CPRA | Businesses serving California residents | Notice, access, deletion, opt-out of sale, non-discrimination | CCPA 2018, CPRA 2020 |
| FISMA | US federal agencies and their systems | Agency security programs, NIST standards, reporting | FISMA 2002, modernized 2014 |
| FERPA | Schools and universities | Privacy of education records | FERPA 1974 |
| COPPA | Websites and apps aimed at children under 13 | Verifiable parental consent before collecting personal information | COPPA 1998, rule 2000 |
| CFAA and ECPA | Anyone who accesses or intercepts | Unauthorized access and electronic surveillance prohibitions | 18 U.S.C. 1030; ECPA 1986 |
| State breach laws | Any business holding residents’ data | Breach notification, thresholds, timing per state | California SB 1386 (2002) was first; all 50 states now |
| PCI DSS | Every entity that stores, processes, or transmits cardholder data | Twelve requirements for cardholder data protection | PCI DSS 4.0, released March 2022 |
Read the catalog the way a compliance professional does: your obligations are a function of your business, not of your security budget. A healthcare insurer in California serving EU residents simultaneously holds HIPAA, CCPA, and GDPR obligations, plus the state’s breach notification law, plus whatever its payment contracts impose through PCI DSS, and the security program must satisfy all of them at once. That stacking is exactly what the exam’s most complex Domain 1 questions test, and the skill is not memorizing every statute, it is looking at a scenario and naming which obligations the facts trigger.
A few regimes deserve specific notes because the exam tests their details. FISMA, the Federal Information Security Modernization Act, does two things at once: it makes each federal agency run a documented information security program, and it hands the job of standards to NIST, which produces the Special Publication 800 series, including SP 800-53, the control catalog that federal systems and, increasingly, the whole industry use as a control checklist. GLBA, the Gramm-Leach-Bliley Act, requires financial institutions to protect customer information, and its Safeguards Rule, updated by the FTC in 2021, is a direct security requirement: administrative, technical, and physical safeguards, risk assessment, and board oversight. PCI DSS is the one non-law in the catalog, and the exam expects you to know it is not a law. It is an industry standard written by the PCI Security Standards Council and imposed on every entity in the payment chain through the card brands’ contracts. A merchant signs up for PCI DSS the way they sign up for the merchant agreement, and non-compliance is enforced by the banks, not by a government. Understanding that distinction is the entire question.
The newest layer deserves a sentence for currency. The European Union’s Artificial Intelligence Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 with obligations phasing in through 2026 and beyond, and it is already changing what counts as acceptable governance for algorithmic systems, particularly for high-risk use cases. If you are reading this book after its obligations are fully in force, the catalog above will have grown by one regime, and the skill of reading a statute’s scope and trigger will still be the skill that matters.
Privacy regulation in depth: the GDPR
Of all the regimes in the catalog, one dominates the CISSP: the General Data Protection Regulation, Regulation (EU) 2016/679, in force since 25 May 2018. It dominates because of its reach. Article 3 applies the regulation to any organization processing personal data of people located in the Union when the processing relates to offering goods or services to them, or to monitoring their behaviour, regardless of where the processor sits. A company in another continent with no EU office can still be fully inside the GDPR, and that extraterritoriality is the single most examined idea in Domain 1 privacy.
The GDPR’s seven principles, set out in Article 5, are the regulation in miniature: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability, which makes the controller responsible for demonstrating compliance with all the others. Every GDPR scenario in the exam is one of these principles being violated, and naming the principle usually settles the question.
The data subject rights, Articles 15 through 22, are the individual’s toolkit: the right to access copies of personal data, to rectify errors, to erasure (the right to be forgotten), to restriction of processing, to data portability in a machine-readable format, and to object to certain processing including direct marketing. A scenario where a customer demands a copy of their data, or asks a company to delete it, is testing these articles, and the correct answer almost always respects the right unless a legal obligation overrides it.
Two obligations get their own paragraphs because they are the most-quoted numbers in privacy law. Breach notification: under Article 33, when a personal data breach occurs, the controller must notify the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, and under Article 34, must notify affected individuals directly when the breach is likely to result in high risk to their rights and freedoms. Fines: under Article 83, the two severity tiers are up to 10 million euros or 2 percent of total worldwide annual turnover, whichever is higher, for the lesser violations, and up to 20 million euros or 4 percent, whichever is higher, for the serious ones such as violating the principles or the data subject rights. No other regime in this chapter quotes its fine math in the exam, because no other regime’s fine math is as famous.
The GDPR also installed a set of organizational roles and artifacts that the exam treats as vocabulary. A controller decides why and how data is processed; a processor handles data on the controller’s instructions. Both are liable, but the controller bears the primary obligation. A data protection officer, Articles 37 to 39, is required for public authorities, for organizations whose core activities involve large-scale systematic monitoring, and for large-scale processing of sensitive categories of data, and the DPO reports to the highest management level and must be given the independence to act. Article 25 makes data protection by design and default a legal requirement: privacy must be engineered into products, not bolted on, and the default settings must be the privacy-preserving ones. That article is why “privacy by design” stopped being a slogan.
Finally, the transfer rules, because they are the GDPR’s hardest operational problem. Personal data may move outside the EU/EEA only through approved mechanisms under Chapter V: an adequacy decision from the European Commission recognizing a country’s protections, standard contractual clauses under Article 46, binding corporate rules for multinational groups, or one of the other limited bases. The history here is exam-relevant because it shows the mechanism in motion. The Court of Justice of the European Union’s Schrems II judgment of 16 July 2020 invalidated the previous EU-US Privacy Shield, forcing a generation of transatlantic companies onto standard contractual clauses, which the Commission replaced in 2021 with updated clauses under Implementing Decision (EU) 2021/914, and on 10 July 2023 the Commission adopted a new adequacy decision establishing the EU-US Data Privacy Framework as a replacement transfer basis. The exam does not test the litigation history, but it does test the architecture: transfers need a lawful mechanism, adequacy decisions are country-level, clauses are contract-level, and the absence of either is a compliance gap.
Intellectual property and contracts: obligations you negotiate
Beyond the statutes, an enormous share of real security work lives in two bodies of private law that the exam treats as professional vocabulary: intellectual property and contracts.
Intellectual property law protects four different kinds of intangible value, and the exam’s favorite question shape is a description of an asset and a prompt to name the regime that protects it. Copyright protects original works of authorship, including software source code as a literary work, automatically upon fixation in a tangible medium, without registration, with the Berne Convention of 1886 as the international backbone. The US Digital Millennium Copyright Act of 1998 added two layers the exam likes: the anti-circumvention provisions of 17 U.S.C. section 1201, and the safe harbors of section 512 that protect online platforms that comply with takedown notices. Patents protect inventions, are granted only through a registration process that requires full disclosure of the invention, and run 20 years from the filing date under the first-to-file regime the America Invents Act of 2011 installed. Trademarks protect the identifiers of source, brand names, logos, and product marks, under the Lanham Act, with federal registration shown by the registered symbol and renewal required every 10 years. Trade secrets protect confidential business information, including algorithms, formulas, customer lists, and source code, under no registration at all: a trade secret is protected only as long as it stays secret, through reasonable confidentiality measures, and misappropriation is actionable under state law and, since the Defend Trade Secrets Act of 2016, in federal court.
The trade secret row is the one the exam returns to, because it is the regime where security practice is the law. A patent buys a monopoly for 20 years but publishes the invention to the world. A trade secret protects for as long as the secret lasts, which can be forever, but only if the holder actually keeps it secret: access controls, NDAs, need-to-know, and compartmentalization are not just good security, they are the legal condition of protection. An organization that lets its proprietary algorithm drift onto shared drives has started converting a trade secret into nothing at all. That is why exam scenarios about proprietary data almost always resolve to trade secret law plus the controls that preserve it.
Licensing is the legal layer under all software, and it comes in two broad families. Proprietary licenses grant limited rights by contract, often through an end user license agreement, and the source is owned. Open source licenses grant rights by license too, and the obligations vary with the license family, from permissive licenses that allow near-anything, to copyleft licenses such as the GPL that require derivative works to be released under the same license. The security professional’s practical rule, and a recurring exam theme, is that licensing is a legal obligation with compliance consequences: every open source component in a product carries license terms that must be tracked, which is why software composition analysis exists.
Contracts are where the organization turns obligations into negotiated terms, and a security professional reads contracts for a short list of clauses. The service level agreement sets measurable performance targets: uptime percentages, response times, and the credits for failing them. The data processing agreement, required by GDPR Article 28 between every controller and processor, must cover the controller’s documented instructions, confidentiality, security measures, assistance with data subject rights and breaches, engagement of sub-processors, audit rights, and the return or deletion of data when the service ends. Liability terms set the price of failure: limitation of liability clauses cap a vendor’s exposure, usually at the fees paid over a recent period, and indemnification clauses make one party responsible for specified categories of loss. Choice of law and forum clauses settle which jurisdiction’s courts and law apply to disputes. And audit rights give the customer the contractual power to verify the vendor’s controls, which is the difference between trusting a vendor and checking one.
Two clauses deserve the security professional’s special attention because they are where security value actually gets negotiated. A right to audit, exercised wisely, converts every third-party risk assessment from a request into a contract term, and modern cloud contracts increasingly substitute independent certifications such as SOC 2 or ISO/IEC 27001 attestations for direct audits, a substitution that is only sound if the certification is current, scoped to the service, and real. And breach notification provisions in contracts, which extend the statutory notification duties to the contractual relationship, answer the question every incident responder asks first: who has to tell whom, and how fast.
Compliance as a program
Compliance, as a discipline, is the management of obligations, and it fails in one predictable way: it gets reduced to a checklist against a single standard. The mature pattern, which the exam rewards and which the frameworks above all share, is a loop. First, map the obligations: identify every legal, regulatory, and contractual obligation that applies to the organization’s business, which is the step almost every scenario about “building a compliance program” is really testing. Second, assess the gap: compare current controls to the obligations and produce a gap analysis. Third, design and implement the controls that close the gaps. Fourth, collect evidence, because an obligation met without evidence is an obligation not met in any audit. Fifth, monitor the environment, because obligations change: statutes get amended, PCI DSS releases version 4.0, contracts get renegotiated. Sixth, report upward, which closes the loop back into governance.
Two habits separate a compliance program that works from one that generates paper. The first is treating internal audit as an independent line, not an internal policeman. An internal audit function that reports to the CFO it audits, or a second-line risk team that “audits” its own processes, is a governance failure no amount of documentation fixes, which is why SOX imposed auditor independence rules and why the three lines of defense model insists the third line sit apart. The second habit is refusing to confuse compliance with security. Compliance is the floor defined by obligations; security is the ceiling defined by risk. A control that satisfies a regulation may still be inadequate for the actual threat, and a risk-driven control may exceed what any law requires. Organizations get into trouble when they treat the two as synonyms, either by letting a compliance checklist stand in for risk management, or by dismissing obligations as “just compliance.”
The ISC2 Code of Ethics
The last binding on your behavior is the one you signed. Every ISC2 member and every candidate must abide by the ISC2 Code of Ethics, and the exam tests it in the same way it tests the decision hierarchy: not by asking you to recite the canons, but by presenting a conflict and asking what a member does.
The code’s preamble states the order of duty plainly: the safety and welfare of society and the common good, duty to our principals, and duty to each other require the highest ethical standards of behavior. The four canons follow. Canon I: protect society, the common good, necessary public trust and confidence, and the infrastructure. Canon II: act honorably, honestly, justly, responsibly, and legally. Canon III: provide diligent and competent service to principals. Canon IV: advance and protect the profession.
The load-bearing sentence of the entire code is the one that resolves conflicts, because conflicts are inevitable: the code states that when canons conflict, they are resolved in the order of the canons. Canon I comes first. An employer who asks a member to hide a vulnerability that endangers public safety has collided with Canon I, and Canon I wins. That ordering is the answer to the exam’s ethics scenarios: society and public trust outrank the employer, the client, and the profession. A member who discovers their organization is knowingly exposing customer data does not quietly comply to keep the job, and does not leak to the press first either; the member escalates through proper channels, documents, and where the organization refuses to act, takes the protection of the public as the governing duty. The same ladder resolves the quieter conflicts: honesty outranks loyalty in reporting a colleague’s misconduct to the ethics process, and competent service means declining work you cannot do, or admitting error rather than concealing it.
Three exam behaviors follow directly. First, ethics can require more than the law: “legal” and “ethical” are different questions, and the code’s first canon points at the higher bar. Second, when a scenario offers both a private benefit and a public obligation, choose the public obligation, and when it offers a choice between hiding a problem and escalating it, escalate. Third, the code binds candidates as well as members, so an ethics scenario is never answered by “that only applies to certified people.”
Thinking like the accountable manager
Governance, law, and ethics share one structure, which is why the exam bundles them in a single domain. All three are hierarchies of accountability, and the same four questions resolve most Domain 1 scenarios. Who is accountable? Name the layer: board, executive, risk owner, or the professional. What binds this organization? Name the source: law, contract, policy, or ethics. What is the floor versus the ceiling? The obligation is the floor; good judgment may require more. And when obligations conflict, which outranks? People over property, law over convenience, Canon I over the rest, and escalation over silence.
Run the ladder on the exam’s hardest governance questions and it resolves them. A question that asks what the board must approve, where the facts show a risk appetite or a certification decision, answers with the board. A question that asks what a CISO should do when the business declines a control answers with documentation, escalation, and risk acceptance at the accountable level, not with a technical workaround. A question that asks what a member does when their employer orders silence answers with the code’s first canon. The manager the exam rewards is not the one who knows every statute, it is the one who can say, in any situation, who owns the decision, what the obligation is, and where the conflict gets escalated.
Practice questions
-
The accounts payable team writes its own payment procedures, runs the controls inside them, catches its own errors, and corrects them before payments leave the team. In the three lines of defense model, which line is this?
A. First line: operational management owning and operating its own controls. B. Second line: the compliance function monitoring operational risk. C. Third line: internal audit providing independent assurance. D. Board-level oversight exercising fiduciary duty.
-
The head of marketing declines to remediate a flaw in a customer-facing tool, saying the exposure is acceptable for her department. What does sound governance require?
A. Her verbal decision is sufficient, because she is the accountable business owner. B. The CISO must override her and mandate the remediation. C. The acceptance should be documented, approved at an appropriate level, and revisited periodically. D. The risk must automatically be transferred to insurance.
-
An organization processes the personal data of EU residents and suffers a breach in which customer data is exfiltrated. Under the GDPR, what is the controller’s first notification obligation?
A. Notify affected individuals within 24 hours of discovery. B. Notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware. C. Notify every supervisory authority in every EU member state simultaneously. D. Notify law enforcement before any other party.
-
A customer sues a vendor for negligence after a data breach, seeking monetary damages. Which standard of proof applies to this civil claim?
A. Beyond a reasonable doubt. B. Clear and convincing evidence. C. Preponderance of the evidence. D. No standard applies, because the burden shifts entirely to the defendant.
-
A manufacturer protects its proprietary formula through restricted access, NDAs, and compartmentalization, with no government registration. Which legal regime protects the formula?
A. Copyright, because the formula is expressed in documents. B. Patent, because the formula is an invention. C. Trade secret, because protection depends on maintaining confidentiality. D. Trademark, because the formula identifies the product’s source.
-
Which statement about PCI DSS is accurate?
A. It is a federal regulation enforced by the FTC. B. It is an industry standard administered by the PCI Security Standards Council and imposed through the payment card brands’ contracts. C. It is a European regulation derived from GDPR Article 32. D. It applies only to merchants, not to processors or acquirers.
-
A US public company’s CEO certifies the accuracy of the company’s financial statements and the effectiveness of its disclosure controls each quarter. Which statute requires this certification?
A. The Gramm-Leach-Bliley Act. B. The Federal Information Security Modernization Act. C. The Sarbanes-Oxley Act of 2002. D. The Computer Fraud and Abuse Act.
-
Under GDPR Article 28, which element must a controller-processor contract include?
A. A forum-selection clause naming the controller’s home country courts. B. The controller’s documented instructions, required security measures, confidentiality, assistance with data subject rights, and return or deletion of data on termination. C. A liability cap no higher than the fees paid in the prior 12 months. D. Prior approval of the contract by the supervisory authority.
-
An ISC2 member discovers that software they maintain exposes the health records of thousands of people, and their employer orders them to keep the finding quiet. According to the ISC2 Code of Ethics, what prevails?
A. Duty to the employer, because principals direct the work. B. The obligation to advance the profession, which requires avoiding public embarrassment. C. Protecting society, the common good, and necessary public trust and confidence. D. The strict letter of applicable law, and nothing beyond it.
-
An organization wants to build its first compliance program. What is the soundest first step?
A. Purchase a governance, risk, and compliance tool to track controls. B. Identify the legal, regulatory, and contractual obligations that apply to its business. C. Run a penetration test to find current security gaps. D. Draft an information security policy and obtain sign-off.
-
A contractor continues accessing a company’s systems after her contract ends, using credentials that were never revoked, and the company refers the matter to federal prosecutors. Which US statute is the primary vehicle for prosecuting this unauthorized access?
A. The Electronic Communications Privacy Act. B. The Computer Fraud and Abuse Act, 18 U.S.C. section 1030. C. The Defend Trade Secrets Act. D. The Lanham Act.
Answers and rationales
-
A. The three lines of defense model, published by the Institute of Internal Auditors, puts operational management in the first line: it owns and operates the controls inside its own processes and self-corrects. The second line monitors and challenges the first line, the third line is independent internal audit, and the board oversees rather than operates. The team’s self-monitoring and self-correction is the defining behavior of the first line.
-
C. A risk acceptance is not a conversation, it is a decision artifact: documented, approved at the level accountable for the exposure, and revisited when conditions change. An undocumented verbal acceptance evaporates when the decision-maker changes jobs. The CISO advises but does not unilaterally override an accountable business owner, automatic insurance transfer is a treatment, not an acceptance, and even an accountable owner’s decision needs the governance trail.
-
B. GDPR Article 33(1) requires the controller to notify the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of a personal data breach. Article 34 requires notification to affected individuals when the breach creates high risk to their rights and freedoms, but the authority notification comes first. There is no 24-hour rule, no simultaneous notification of all authorities, and no police-first priority in the regulation.
-
C. Civil claims are decided under the preponderance of the evidence standard: liability if the evidence shows the claim is more likely true than not. Beyond a reasonable doubt is the criminal standard, clear and convincing evidence is an intermediate standard used in certain specific civil matters, and the burden never simply shifts to the defendant wholesale.
-
C. A trade secret is protected only as long as it remains secret through reasonable confidentiality measures, requires no registration, and can last indefinitely. A patent requires public disclosure and expires 20 years from filing. Copyright protects expression, not the underlying idea or formula, and trademarks protect source identifiers, not formulas. The security controls described are precisely the measures that preserve trade secret protection.
-
B. PCI DSS is a set of requirements written by the PCI Security Standards Council and enforced through the contracts of the payment card brands, not by government. It is not an FTC regulation, it is not derived from the GDPR, and it applies to every entity that stores, processes, or transmits cardholder data, including processors and acquirers, not just merchants.
-
C. Section 302 of the Sarbanes-Oxley Act of 2002 requires the CEO and CFO of a public company to certify the accuracy of financial statements and the effectiveness of disclosure controls and procedures. GLBA governs financial institutions’ handling of customer information, FISMA governs federal agency security programs, and the CFAA covers unauthorized computer access. The certification scenario is a pure SOX marker.
-
B. GDPR Article 28(3) lists the mandatory content of a controller-processor contract, including the controller’s documented instructions, confidentiality obligations, the security measures required by Article 32, assistance with data subject rights, sub-processor conditions, and the return or deletion of data at the end of the services. Liability caps, forum selection, and regulatory approval are not Article 28 requirements.
-
C. The ISC2 Code of Ethics resolves conflicts between canons in canon order, and Canon I, protecting society, the common good, and necessary public trust and confidence, precedes duty to principals. A member in this position escalates through proper channels and treats public protection as the governing duty. Ethics can exceed the strict letter of the law, and the code binds candidates as well as members.
-
B. Every mature compliance program starts by identifying the obligations that actually apply to the organization: the statutes, regulations, and contracts triggered by its business. Tools, tests, and policies are all downstream of knowing what the program must satisfy, and a tool without an obligation map is a spreadsheet with no input. Gap analysis follows mapping, which is why mapping is the soundest first step.
-
B. The Computer Fraud and Abuse Act, 18 U.S.C. section 1030, is the primary federal statute criminalizing unauthorized access to protected computers, including access that exceeds authorization, and it is the standard vehicle for prosecuting this pattern. The ECPA governs interception of communications, the Defend Trade Secrets Act protects confidential business information, and the Lanham Act governs trademarks.
Governance on one page
When the details blur, hold the shape. Governance is the system by which organizations are directed and controlled: the board sets direction and risk appetite, executives execute, the CISO runs the program, and accountability flows down, never up. The three lines of defense put controls with operations, oversight with risk and compliance, and assurance with independent audit. Law binds the organization in four registers, criminal, civil, administrative, and regulatory, each with its own standard and its own investigation, and jurisdiction is where law and data collide. Obligations come from three sources, law, contract, and policy, and the catalog of regimes, GDPR, HIPAA, SOX, GLBA, CCPA, FISMA, FERPA, COPPA, CFAA, the state breach laws, and PCI DSS, applies by business context, not by security budget. Intellectual property runs from copyright through patents to trademarks, with the trade secret as the regime where your controls are the law, and contracts turn the rest into negotiated terms: SLAs, data processing agreements, liability caps, audit rights, and choice of law.
Above all of it sits the code you signed. Society first, then your principals, then the profession, and when the canons conflict, they resolve in that order. The manager the exam rewards can look at any scenario and answer four questions: who is accountable, what binds the organization, what is the floor versus the ceiling, and where does the conflict get escalated. Governance, compliance, and law are not the paperwork layer. They are the decision layer that makes every technical control in the other seven domains legal, funded, and defensible, and the rest of this book spends one part on each of those domains.
Continue reading
Full table of contents