Study ISC2 CC risk management, control types, ISC2 Code of Ethics, policies, procedures, standards, laws, and governance.
CC questions often look technical but are really asking whether you understand risk and governance. A strong answer reduces risk in a way the organization can explain, repeat, and audit.
| Term | Exam meaning |
|---|---|
| Asset | something valuable that needs protection |
| Threat | potential cause of harm |
| Vulnerability | weakness that could be exploited |
| Likelihood | chance that the risk event happens |
| Impact | business or security damage if it happens |
| Risk tolerance | how much risk the organization is willing to accept |
| Treatment | avoid, mitigate, transfer, or accept the risk |
| Control type | What it does | Example |
|---|---|---|
| Administrative | sets expectations or governance | policy, standard, training |
| Technical | enforces or detects through technology | MFA, firewall, encryption |
| Physical | protects facilities and equipment | badges, locks, guards |
| Preventive | reduces chance of an event | least privilege, patching |
| Detective | identifies an event | alert, log review, camera |
| Corrective | restores a safer state | restore backup, reimage host |
| Compensating | substitutes when preferred control is not feasible | extra monitoring while patch is delayed |
| Layer | Role |
|---|---|
| Policy | management-approved rule or intent |
| Standard | specific mandatory requirement |
| Procedure | step-by-step work instruction |
| Guideline | recommended practice |
| Regulation or law | external requirement the organization must address |
The ISC2 Code of Ethics angle is usually practical: protect society and the public good, act honorably, provide competent service, and support the profession. Reject answers that hide incidents, falsify evidence, misuse access, or ignore legal/organizational duties.