1

Ethics, Security Concepts, and Governance Principles

Being a Certified Information Systems Security Professional (CISSP) carries several responsibilities, including adhering to professional ethics, applying security governance to organizations, understanding the requirements for investigations, enforcing security policies and procedures, applying risk management principles, and maintaining security awareness and training programs.

This chapter begins with the CISSP’s understanding of professional ethics, which is a requirement of the International Information System Security Certification Consortium (ISC2). Next, you will learn about the basic concepts of security, such as data confidentiality, data integrity, and data availability.

Finally, ...

Get Certified Information Systems Security Professional (CISSP) Exam Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.