← CISSP: security, risk, and operations
01 / 10 · 30 MIN

Governance, ethics, and risk decisions

Connect controls to objectives, impact, and decision authority.

Concept and mechanism

A security decision starts with the business outcome needing protection. Identify the asset, threat event, enabling conditions, and consequences for confidentiality, integrity, and availability. Technical severity does not replace that analysis. Two equally scored findings may have different exposure and impact. Make explicit who is authorized to accept residual risk under organizational policy. The technical manager gathers evidence, compares options, and coordinates execution; managing the plan does not automatically authorize business risk acceptance. Retain the distinction between observed fact, hypothesis, and estimate, including uncertainty in figures presented to the committee.

Guided application

In a simple model, €80,000 impact multiplied by an expected frequency of 0.25 per year produces €20,000 expected annual loss. It does not guarantee that amount of loss every year. Also compare hard-to-quantify effects and applicable obligations. BIA helps order recovery by impact and dependencies. A contract can transfer costs without eliminating outages. When a supplier adopts AI, assess data purpose, provenance, and use before permitting training on real tickets. Communicate gaps accurately even when the sponsor pressures the date. Policies need verifiable standards and procedures; training and documents help when they guide effectively implemented controls.

IN PRACTICE

A supplier wants to train a model on support tickets: existing support authorization does not establish authorization for that new purpose.

Common pitfalls

Severity treated as complete risk; acceptance without authority; contract treated as risk elimination; expected benefit treated as approval.

Related topics: Assets, data, and decommissioning · Architecture, cryptography, and common failures

Take this idea with you

A defensible decision connects evidence, impact, alternatives, and an authorized owner.

Create account

Reference: Cybersecurity Framework 2.0 · CISSP outline effective April 15, 2024; current AI guidance consulted 2026-09-29