CISSP - Security and Risk Management - Section 1.5

Understand requirements for different investigation types including administrative, criminal, civil, regulatory, and industry standards.

Distinguish between administrative, criminal, civil, regulatory, and industry-standards investigations in terms of their evidence standards, legal thresholds, and the roles security professionals play in each. Apply the correct evidence-handling requirements and reporting obligations for a given investigation type.

administrative investigationcriminal investigationcivil investigationregulatory investigation

Practice question for this objective

Free sampleSecurity and Risk Managementmedium

A national data protection authority has opened a formal inquiry into a healthcare provider following a reported breach of patient records. The provider's security team is asked to support the response. Which statement most accurately describes how a regulatory investigation differs from an administrative investigation in this context?

  • AA regulatory investigation always requires a search warrant before any evidence can be collected, whereas an administrative investigation never does.
  • BA regulatory investigation uses the criminal beyond reasonable doubt standard, whereas an administrative investigation uses the civil preponderance of evidence standard.
  • CA regulatory investigation is initiated and bounded by an external supervisory authority, whereas an administrative investigation is initiated and bounded by the organisation itself. Correct
  • DA regulatory investigation focuses on the rights of the suspect employee, whereas an administrative investigation focuses on the rights of affected data subjects.
Distinguish a regulatory investigation by external supervisory authority from an administrative investigation as an internal employer exercise. Regulatory investigations are driven by an external supervisory authority acting under statutory powers and scoped to the law it enforces. Administrative investigations are internal exercises of organisational policy and employment authority. Misidentifying who controls scope leads to mishandled evidence requests and reporting timelines.

Why A is wrong: Regulators usually have statutory powers to compel production of records without a court warrant in the criminal sense, and they typically work through statutory notices and on-site inspections. The blanket warrant claim misstates how supervisory authorities operate.

Why B is wrong: Regulatory matters generally rely on standards lower than criminal proof, often a balance of probabilities or a regulator-specific test, with criminal referral being a separate path. Mapping regulatory to the criminal burden conflates two distinct tracks.

Why C is correct: The defining difference is who drives the investigation and sets its scope. A regulator opens, directs, and concludes a regulatory inquiry under statutory powers. An administrative investigation is the organisation's own internal exercise of its policies and employment authority, even if its findings later inform external action.

Why D is wrong: This inverts the focus. Regulatory investigations protect the broader public or data subjects through enforcement of statutes, while administrative investigations concern the employer-employee relationship and internal policy. The framing is plausible only at a glance.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Security and Risk Management objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.