CISSP - Security and Risk Management (16% of the exam) - Section 1.1

Understand, adhere to, and promote professional ethics including the ISC2 Code of Professional Ethics and organisational codes of ethics.

Describe the (ISC)2 Code of Professional Ethics and explain how it governs professional conduct through principles of due care and acting honourably, honestly, and responsibly. Apply the code to workplace scenarios where personal interests conflict with client, employer, or societal obligations.

ISC2 Code of Ethicsorganisational ethicsprofessional conductdue care

Practice question for this objective

Free sampleSecurity and Risk Managementeasy

Which statement BEST describes the relationship between the ISC2 Code of Professional Ethics canons and an employer's internal code of conduct for a CISSP-certified employee?

  • AThe ISC2 canons apply to certified professionals at all times and complement, rather than replace, lawful employer codes of conduct. Correct
  • BThe employer's code of conduct overrides the ISC2 canons whenever the two appear to conflict in the workplace.
  • CThe ISC2 canons only apply when the CISSP is performing security work outside of normal employment duties.
  • DEither code can be ignored provided the professional acts in line with applicable national law and contractual obligations.
Recognise that the ISC2 Code of Ethics binds the certified professional continuously and operates alongside, not in place of, lawful organisational codes. Holding the CISSP is a personal undertaking to abide by the ISC2 canons in every professional act, while an employer's code defines workplace duties owed to a principal. Both apply concurrently, and where a lawful employer rule and a canon point the same way the professional follows both; the canons set the floor and an organisational code can add stricter expectations on top.

Why A is correct: The canons bind the certificant personally and continuously, while a lawful employer code governs workplace duties; the two are designed to coexist, with the canons providing the professional baseline.

Why B is wrong: Tempting because employees normally follow employer policy, but a CISSP holder agreed to uphold the ISC2 canons as a condition of certification, so the canons are not displaced by internal policy.

Why C is wrong: Plausible to a candidate who thinks ethics codes only cover voluntary or external activity, but the canons attach to the certificant in every professional context, not only off-hours engagements.

Why D is wrong: Compliance with law is necessary but not sufficient; the ISC2 canons impose duties beyond legal minimums, and ignoring an employer's lawful code breaches duty owed to principals.

See more CISSP practice questions, answers explained.

Exam traps in Security and Risk Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • Take no action, because professional ethics complaints between colleagues are a private matter handled only by the employer.

    Why it is wrong: Plausible to a candidate who treats ethics as an internal HR matter, but the canons impose duties to the client and the profession that cannot be discharged by the employer alone.

  • Investigating threats and control options thoroughly before recommending or approving any safeguard for the organisation.

    Why it is wrong: Strong investigation before recommending controls is due diligence, the research that supports a decision, rather than due care, which is the prudent action that follows it.

  • Act honourably first, then advance the profession, then provide diligent service, then protect society.

    Why it is wrong: Tempting because personal honour feels foundational, but ISC2 lists protection of society and the common good as the first canon, ahead of personal honour.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.