← CISSP: security, risk, and operations
20 / 23 · 110 MIN

Risk decisions and the data lifecycle

Interpret dependencies, distributions, sensitivity and data-use conditions in a deterministic laboratory with explicit limits.

Prepare a model with an evidence contract

This lesson’s laboratory runs three original deterministic models: economic comparison under uncertainty, task completion with dependencies and data-request eligibility under a fictional policy. It uses only Python and synthetic in-memory inputs. The result file records environment, time, program hash, checks and limits. Two stored runs each contain 37 passing checks and no failures. This demonstrates program behavior for chosen inputs, not the security of a bank or production platform. Before interpreting output, identify each function’s contract. The loss distribution assumes mutually exclusive and exhaustive outcomes. The graph assumes independent resources except where an additional precedence represents a constraint. The eligibility gate compares explicit request and approval fields; it observes no traffic, exports no data and validates no legal obligations. These limitations are part of the lesson and should remain visible when results are presented to a committee. Run the program into your own evidence file and read individual checks. A summary saying 37 passed does not explain what was exercised. Compare boundaries, invalid inputs and counterfactual changes. If you change code or inputs, retain new evidence and identify the difference. A hash can connect a result with the file used; it does not establish independent authorship, immutable custody or correctness of every assumption.

Walk through the continuity graph

The model begins with 20 minutes of data intake. Validation requires that intake and takes another 25. In parallel, FX processing finishes at minute 15. Calculation begins only when validation and FX finish, then takes 35 minutes. Publication adds 10. The function calculates each task’s finish as its latest predecessor finish plus its duration: validation at 45, calculation at 80 and publication at 90 minutes. This rule explains why accelerating FX from 15 to 5 minutes does not change publication. Validation at 45 remains the limiting predecessor. Reducing validation from 25 to 15 minutes moves publication to minute 80. These are model changes, not platform measurements. The exercise uses an inclusive limit: completion at 90 meets less than or equal to 90, but leaves zero slack. No variability is automatically added. The laboratory also represents a staffing constraint: FX now waits for validation because the same operator cannot perform both simultaneously. Publication then moves to minute 105. The function rejects unknown dependencies, negative durations and cycles rather than inventing zero time. When applying this reasoning to a project, validate resources, timings, business phases and access conditions with responsible teams before promising the outcome.

Interpret distributions without losing the tail

A mean summarizes a distribution but does not describe every outcome. Scenario A uses a 75% probability of zero loss, 20% of €20,000 loss and 5% of €500,000 loss. Expectation is €4,000 + €25,000 = €29,000. Scenario B uses 95% zero loss and 5% €580,000 loss, producing the same €29,000. These are fictional exhaustive distributions for one annual opportunity, not observed service frequencies. The laboratory also compares probability of exceeding €500,000. It is zero in A within the supplied outcomes and 5% in B. A rule disallowing scenarios above that amount distinguishes the options despite equal means. Equality with €500,000 does not count as excess because the comparison was defined strictly. Another policy could treat equality differently and would need to say so. The function rejects negative probabilities or a sum other than one. It does not automatically fill missing probability mass with zero loss, which would invent a favorable assumption. Also distinguish conditional probability: if attempt probability is 20% and success given an attempt is 30%, path probability is 6% in the model. Multiplication uses the supplied condition; it neither assumes independence nor demonstrates absence of other paths.

Calculate recommendation sensitivity

The laboratory’s economic function uses p × impact × reduction − annual cost. With €200,000 impact, 75% reduction and €12,000 cost, expected gross benefit is p × €150,000. Break-even occurs when that product equals cost: p = 12,000 / 150,000 = 0.08. At 3%, net benefit is −€7,500; at 12%, it is €6,000. The economic choice is therefore sensitive to assumed probability. Break-even does not estimate actual probability. It also does not establish the 75% reduction, which would need appropriate supporting evidence. The model helps ask which information could change the choice: exposure, effectiveness, impact or cost. With limited investigation time, it may be useful to prioritize uncertainty that reverses the recommendation over uncertainty that does not change preference across its plausible range. Information value still depends on collection cost and feasibility. Some constraints are outside the calculation. A mandatory requirement with no available exception may exclude the economically cheapest option. Two measures preventing the same loss can have overlapping benefits; adding their individual benefits exaggerates the combined gain. Present the economic analysis with units, assumptions and limitations alongside admissibility conditions and required decision authority. With a €20,000 budget, A costs €12,000 for expected gross benefit of €24,000, while C costs €10,000 for €21,000. A offers €12,000 net, C offers €11,000, and buying both exceeds budget. A third option violating a mandatory constraint remains outside the feasible set even if it appears financially attractive.

An explicit decision gate for data

The laboratory’s eligibility gate receives a request, approval, catalog and fictional time. The request contains fields, purpose, destination and policy version. Approval includes corresponding scope, covered owners, expiry and an explicit restricted-data permission. The catalog assigns ownership and classification to fields. The function checks these conditions in a documented order and returns a specific reason when it finds a mismatch. In the example, fund and amount belong to operations, while contact belongs to client service. Approval for internal reconciliation does not automatically cover model training or delivery to a supplier. Adding contact may require expanding both the field set and the relevant owner decision. An unknown field such as a new score returns unknown-data; the program does not presume the derived output is public. Approval expiring at 200 is ineligible at exactly 200 because the rule treats the expiry instant as expired. The laboratory also observes policy-version changes: a p3 approval does not automatically satisfy a p4 request. This teaches making authorization assumptions checkable. The function does not authenticate approvers, enforce DRM or DLP, or stop a real export. Eligible-in-model means only that the encoded conditions passed. A real implementation would next connect decisions to identity, enforcement and observation mechanisms while validating their concrete limitations.

Turn results into a decision with follow-through

A decision meeting needs more than the program’s final output. Start with the objective and admissible options. Explain which inputs were observed, estimated or derived from the exercise’s fictional policy. Then show what distinguishes alternatives: a 105-minute path missing a 90-minute limit, uncertain probability crossing 8%, or a data request exceeding approved recipients. These are different conclusions and should not be compressed into one percentage without a method. Record the decision, owner, conditions and review triggers. If approval depends on a trained second operator, training and demonstrated capability become material conditions. If an exception depends on daily review, loss of that capability should prompt reassessment before formal expiry. History remains useful when it preserves versions and reasons; it should not turn an earlier state into proof of current validity. The two laboratory runs produce the same checks with distinct timestamps and a hash linking them to the program. This repeatability helps reproduce deterministic analysis. It does not measure adaptation to every incident, statistical quality of estimates or operational capability of real teams. Use it to discuss assumptions precisely and plan additional evidence. Accountable closure distinguishes what has been demonstrated, what has been decided and what remains to be checked.

python3 content/labs/cissp-governance-contracts/run.py --output /tmp/cissp-governance-local-evidence.json
IN PRACTICE

In the model, accelerating FX from 15 to 5 minutes does not reduce 90-minute publication; changing validation or the operator constraint changes the limiting path.

Common pitfalls

Mean treated as loss limit; break-even treated as observed probability; model treated as production testing; technical approval treated as authorization for any purpose.

Related topics: Acceptance criteria and risk tolerance · Sensitivity, uncertainty and control selection · Continuity dependencies and capacity · Data purpose, lineage and authorization · Usable supplier exit

Take this idea with you

A sound decision separates calculation, evidence and authority and retains the conditions that may require review.

Create account

Reference: Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management · CISSP outline effective April 15, 2024; current AI guidance consulted 2026-09-29

CISSP® is a registered trademark of ISC2, Inc. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by ISC2. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.