CISSP - Security and Risk Management - Section 1.4

Understand legal, regulatory, and compliance issues pertaining to information security in a holistic context, including cybercrime, privacy, and contractual requirements.

Recognise the legal landscape covering cybercrime law, GDPR, data breach notification obligations, intellectual property rights, and transborder data flow restrictions. Weigh how conflicting jurisdictional requirements affect an organisation's security programme and contractual obligations.

cybercrime lawGDPRdata breachesintellectual propertytransborder data flow

Practice question for this objective

Free sampleSecurity and Risk Managementhard

A software vendor in Dublin licenses its proprietary platform to a German bank under a perpetual licence with a confidentiality clause and a clause prohibiting reverse engineering. A penetration test commissioned by the bank uncovers a critical flaw in the vendor's encryption library. The bank's CISO wants to publish a detailed write-up at a security conference and ship a runtime patch developed by reverse engineering the affected DLL. Which course of action should the CISO take FIRST?

  • AShip the in-house reverse-engineered patch to production immediately, relying on the EU Software Directive's interoperability exception to defeat the no-reverse-engineering clause.
  • BPublish the full technical write-up at the conference because responsible disclosure norms override contractual restrictions in the security community.
  • CNotify the vendor under the licence's confidentiality and coordinated disclosure terms, provide proof of the vulnerability, and agree a remediation timetable before any disclosure or self-patching. Correct
  • DTreat the discovery as proprietary intelligence, withhold it from the vendor, and use it as leverage in the next licence renegotiation.
Resolve tension between contractual licence restrictions, intellectual property law, and coordinated vulnerability disclosure obligations. Licence agreements bind the parties unless overridden by statute; the Software Directive interoperability exception is narrow, and trade secret law continues to protect proprietary code. Coordinated disclosure standards such as ISO/IEC 29147 and 30111 codify a vendor-first workflow that protects both the discoverer and end users while preserving contractual standing.

Why A is wrong: The Directive 2009/24/EC interoperability carve-out is narrow and applies only where information is indispensable for interoperability and not readily available; security patching of a vendor library does not fit this exception.

Why B is wrong: Community norms are not a defence to breach of contract or trade secret misappropriation; publishing without vendor coordination exposes the bank to litigation and reputational damage with regulators.

Why C is correct: Contractual obligations of confidentiality and any coordinated vulnerability disclosure clauses bind the bank; engaging the vendor first preserves the bank's legal position, lets the vendor issue an authorised patch, and aligns with ISO/IEC 29147 disclosure practice.

Why D is wrong: Withholding a known critical vulnerability conflicts with the bank's prudential obligations under DORA and with fiduciary duties to customers; it also risks breach of the duty of good faith implied in many contracts.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Security and Risk Management objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.