CISSP - Security and Risk Management (16% of the exam) - Section 1.5

Understand requirements for different investigation types including administrative, criminal, civil, regulatory, and industry standards.

Distinguish between administrative, criminal, civil, regulatory, and industry-standards investigations in terms of their evidence standards, legal thresholds, and the roles security professionals play in each. Apply the correct evidence-handling requirements and reporting obligations for a given investigation type.

administrative investigationcriminal investigationcivil investigationregulatory investigation

Practice question for this objective

Free sampleSecurity and Risk Managementmedium

A national data protection authority has opened a formal inquiry into a healthcare provider following a reported breach of patient records. The provider's security team is asked to support the response. Which statement most accurately describes how a regulatory investigation differs from an administrative investigation in this context?

  • AA regulatory investigation always requires a search warrant before any evidence can be collected, whereas an administrative investigation never does.
  • BA regulatory investigation uses the criminal beyond reasonable doubt standard, whereas an administrative investigation uses the civil preponderance of evidence standard.
  • CA regulatory investigation is initiated and bounded by an external supervisory authority, whereas an administrative investigation is initiated and bounded by the organisation itself. Correct
  • DA regulatory investigation focuses on the rights of the suspect employee, whereas an administrative investigation focuses on the rights of affected data subjects.
Distinguish a regulatory investigation by external supervisory authority from an administrative investigation as an internal employer exercise. Regulatory investigations are driven by an external supervisory authority acting under statutory powers and scoped to the law it enforces. Administrative investigations are internal exercises of organisational policy and employment authority. Misidentifying who controls scope leads to mishandled evidence requests and reporting timelines.

Why A is wrong: Regulators usually have statutory powers to compel production of records without a court warrant in the criminal sense, and they typically work through statutory notices and on-site inspections. The blanket warrant claim misstates how supervisory authorities operate.

Why B is wrong: Regulatory matters generally rely on standards lower than criminal proof, often a balance of probabilities or a regulator-specific test, with criminal referral being a separate path. Mapping regulatory to the criminal burden conflates two distinct tracks.

Why C is correct: The defining difference is who drives the investigation and sets its scope. A regulator opens, directs, and concludes a regulatory inquiry under statutory powers. An administrative investigation is the organisation's own internal exercise of its policies and employment authority, even if its findings later inform external action.

Why D is wrong: This inverts the focus. Regulatory investigations protect the broader public or data subjects through enforcement of statutes, while administrative investigations concern the employer-employee relationship and internal policy. The framing is plausible only at a glance.

See more CISSP practice questions, answers explained.

Exam traps in Security and Risk Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • A criminal investigation conducted to the beyond reasonable doubt standard, preserving evidence under formal chain of custody for prosecutors.

    Why it is wrong: Criminal investigations are appropriate when law enforcement is engaged and the goal is prosecution by the state. At this stage the organisation has not decided to involve police, so framing the work as criminal commits the team to the strictest evidentiary burden prematurely and is not the best initial scoping.

  • The criminal investigation is conducted to the preponderance of evidence standard and relies on voluntary production of documents by the suspect.

    Why it is wrong: Preponderance of evidence is the civil standard, not the criminal one, and criminal matters rely on compelled production through warrants and subpoenas rather than voluntary exchange. This option swaps the two standards, which is a common candidate confusion.

  • A guideline, because it offers configuration suggestions that administrators may adapt to local circumstances.

    Why it is wrong: Guidelines are advisory and discretionary; this document is mandatory and prescriptive, so classifying it as a guideline would understate its authority.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.