certslothcertsloth
CISSP/Topic 11

ISC2 / Professional

Security Leadership, Ethics and Business Risk

3 min read5 recall promptsReviewed 2026-10-10

Memory hook: Protect people; understand the business; assign the risk owner.

Must remember

For management scenarios, establish the business objective, scope, authority and acceptable risk before selecting a product. That does not mean delaying urgent safety or containment actions while conducting a lengthy committee review. Read whether the question asks for the first action, strongest control or long-term program improvement.

Professional ethics prioritize the public interest and trust, lawful and honest conduct, competent service to principals and the profession's development. Conflicting instructions require escalation through appropriate authority; employment does not justify unlawful conduct. Due care is reasonable protective action; due diligence is the continuing investigation and verification supporting that care.

Business owners accept residual risk; security specialists analyze and advise. Governance sets direction and accountability; management implements it. Frameworks serve different purposes: NIST CSF organizes outcomes, ISO 27001 specifies an information-security management system, COBIT addresses enterprise governance of information/technology, and SABSA connects security architecture to business attributes. PCI DSS addresses its defined payment-data environment; FedRAMP concerns assessment/authorization of relevant US federal cloud offerings. Choose by scope and need rather than assuming one framework replaces law.

Personnel controls span lawful screening, agreements, onboarding, transfer, monitoring and termination. Separation of duties reduces single-person abuse; job rotation and mandatory absence can expose concealed activity. Contractors, acquisitions and divestitures require the same deliberate review of inherited identities, data and obligations.

Threat modeling starts with assets, data flows and trust boundaries. STRIDE helps examine spoofing, tampering, repudiation, disclosure, denial of service and privilege escalation; attack trees break a goal into paths. Models guide controls and abuse tests, then evolve with the system.

AI adoption adds data provenance, privacy, output verification and delegated-action risks. Decide who owns model/use-case risk and how outcomes will be monitored, rather than treating a vendor promise as assurance.

Choose under exam pressure

Requirement Choice and reason
Executive asks what security to buy Clarify business risk and requirements before choosing controls.
Residual risk exceeds tolerance Escalate to the accountable owner with treatment options.
New supplier or acquisition Assess inherited exposure, obligations and integration before trust is extended.

Traps

  • “Think like a manager” does not mean ignore immediate human safety.
  • Compliance certification does not transfer the organization’s accountability.

Active recall

1. Who accepts business risk?

The authorized accountable owner, informed by security and other specialists.

2. Due care versus due diligence?

Care is reasonable protection; diligence is sustained investigation and verification.

3. What is the first input to threat modeling?

The system’s assets, design/data flows and trust boundaries.

4. Why does a merger need identity review?

Inherited accounts, trust relationships and privileges may violate the combined organization’s controls.

5. Does an employer’s request override professional ethics?

No. Conflicts require lawful, appropriate escalation and action.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.