Ethics, Security Concepts, and Governance Principles
Being a Certified Information Systems Security Professional (CISSP) carries several responsibilities, including adhering to professional ethics, applying security governance to organizations, understanding the requirements for investigations, enforcing security policies and procedures, applying risk management principles, and maintaining security awareness and training programs.
This chapter begins with the CISSP’s understanding of professional ethics, which is a requirement of the International Information System Security Certification Consortium (ISC2). Next, you will learn about the basic concepts of security, such as data confidentiality, data integrity, and data availability.
Finally, a CISSP must be able to apply security governance principles such as aligning security functions to an organization’s policies, strategies, and goals. By the end of this chapter, you will be able to answer questions on the following...