1.0Security Principles
26%52 practice questions in this domain
- 1.1Understand the security concepts of information assurance (confidentiality, integrity, availability, authentication including MFA, non-repudiation, privacy)
- 1.2Understand the risk management process (risk identification/assessment/treatment, qualitative vs. quantitative analysis, risk treatment options: accept/transfer/avoid/mitigate, inherent vs. residual risk)
- 1.3Understand security controls (categories: technical/administrative/physical; types: preventative/detective/corrective/deterrent/compensating)
- 1.4Understand the (ISC)² Code of Ethics (the four canons and their purpose)
- 1.5Understand governance processes (regulations, policies, procedures, standards, guidelines, and how they relate)