OFFICIAL (ISC)² CISSP -
DOMAIN 1: SECURITY AND
RISK MANAGEMENT
QUESTIONS AND ANSWERS
2024/2025
Business continuity (BC) - ANS >>Actions, processes, and tools for ensuring an organization can continue
critical operations during a contingency.
Business continuity and disaster recovery (BCDR) - ANS >>A term used to jointly describe business
continuity and disaster recovery efforts.
Business impact analysis (BIA) - ANS >>A list of the organization's assets, annotated to reflect the
criticality of each asset to the organization.
Compliance - ANS >>Adherence to a mandate; both the actions demonstrating adherence and the tools,
processes, and documentation that are used in adherence.
Confidentiality - ANS >>Preserving authorized restrictions on information access and disclosure,
including means for protecting personal privacy and proprietary information.
Acceptable risk - ANS >>A suitable level of risk commensurate with the potential benefits of the
organization's operations as determined by senior management.
Data owner/controller - ANS >>An entity that collects or creates PII.
Data subject - ANS >>The individual human related to a set of personal data.
1