Overview

Domain 5 addresses the management, governance, and oversight aspects of a security program. At 20% of the exam, it covers risk management, compliance, policies, awareness training, privacy, and business continuity. This domain focuses on the organizational side of security — how programs are designed, measured, and maintained.

Exam Weight

20% — approximately 18 questions out of 90.

Topics

TopicNoteKey Focus
GovernancegovernanceSecurity frameworks, oversight, roles
Risk Managementrisk-managementRisk identification, mitigation, transfer, acceptance
Business Impact Analysisbusiness-impact-analysisMTD, RTO, RPO, critical function identification
Risk Assessmentrisk-assessmentQualitative, quantitative, likelihood, impact
Third-Party Riskthird-party-riskVendor assessment, SLA, supply chain, SOC reports
CompliancecomplianceRegulatory requirements, audit readiness
Regulations & Frameworksregulations-and-frameworksGDPR, HIPAA, PCI-DSS, NIST, ISO 27001
Security Policiessecurity-policiesAUP, password policy, data handling, standards
Security Awareness Trainingsecurity-awareness-trainingPhishing simulations, role-based training
Data Classificationdata-classificationPublic, internal, confidential, restricted, labeling
PrivacyprivacyPII, PHI, data minimization, consent, GDPR rights
Audits & Assessmentsaudits-and-assessmentsInternal/external audits, SOC 2, attestation
Business Continuitybusiness-continuityBCP, continuity of operations, succession planning
Disaster Recoverydisaster-recoveryDRP, hot/warm/cold sites, backup strategies

Cross-Domain Connections