Official (ISC)² CISSP - Domain 1 Security and Risk
Management Exam 2024-2025
Acceptable risk - An appropriate level of risk consistent with the potential benefits of the
operations of an organization as decided by the management.
Audit/auditing - Tools, techniques and procedures applied in order to conduct the
compliance reviews
Availability - Providing timely, assured access to and use of information by authorized
users.
Business continuity (BC) - Activities, processes, and tools for ensuring that an
organization can sustain its critical operations during a disruption.
Business continuity and disaster recovery (BCDR) - Answer A term to describe business
continuity and disaster recovery efforts jointly.
Business impact analysis (BIA) - Answer A list of the organization's assets, annotated to
reflect the criticality of each asset to the organization.
Compliance - Answer Adherence to a mandate; both the actions demonstrating
adherence and the tools, processes, and documentation that are used in adherence.
Confidentiality - Answer Protecting authorized restrictions on information access and
disclosure, including means for protecting personal privacy and proprietary
information.
Data custodian - Answer The person/role within the organization who usually manages
the data on a day-to-day basis on behalf of the data owner/controller.
Data owner/controller - Answer An entity that collects or creates PII.
Management Exam 2024-2025
Acceptable risk - An appropriate level of risk consistent with the potential benefits of the
operations of an organization as decided by the management.
Audit/auditing - Tools, techniques and procedures applied in order to conduct the
compliance reviews
Availability - Providing timely, assured access to and use of information by authorized
users.
Business continuity (BC) - Activities, processes, and tools for ensuring that an
organization can sustain its critical operations during a disruption.
Business continuity and disaster recovery (BCDR) - Answer A term to describe business
continuity and disaster recovery efforts jointly.
Business impact analysis (BIA) - Answer A list of the organization's assets, annotated to
reflect the criticality of each asset to the organization.
Compliance - Answer Adherence to a mandate; both the actions demonstrating
adherence and the tools, processes, and documentation that are used in adherence.
Confidentiality - Answer Protecting authorized restrictions on information access and
disclosure, including means for protecting personal privacy and proprietary
information.
Data custodian - Answer The person/role within the organization who usually manages
the data on a day-to-day basis on behalf of the data owner/controller.
Data owner/controller - Answer An entity that collects or creates PII.