Domain 1: Security Principles

Information assurance concepts, risk management, security controls, ethics, and governance processes.

This domain covers 26% of the exam. It focuses on understanding the security concepts of information assurance (confidentiality, integrity, availability, authentication, non-repudiation, and privacy), the risk management process (identification, assessment, treatment, priorities, and tolerance), types of security controls (physical, administrative, and technical), the ISC2 Code of Ethics and professional conduct, and governance processes including regulations, laws, standards, procedures, and policies.
5 minutes 5 Questions

Domain 1: Security Principles forms the foundational cornerstone of the ISC2 Certified in Cybersecurity (CC) certification. This domain covers the essential concepts that every cybersecurity professional must understand. At its core, this domain introduces the CIA Triad — Confidentiality, Integrit…

Concepts covered: Technical Security Controls, Privacy Concepts in Information Assurance, Risk Treatment and Response Strategies, Physical Security Controls, ISC2 Code of Ethics and Professional Conduct, Security Policies and Procedures, Confidentiality, Integrity, and Availability (CIA Triad), Authentication Methods and Multi-Factor Authentication, Non-Repudiation, Risk Identification and Assessment, Risk Priorities and Risk Tolerance, Administrative Security Controls, Regulations and Laws, Security Standards and Frameworks, Defense in Depth

Test mode:
More Domain 1: Security Principles questions
675 questions (total)