CISSP Laws & Regulations — Practical Domain 1.4 Guide
A Practical, Exam-Focused Guide to Laws, Regulations, Intellectual Property & Compliance
The CISSP (Certified Information Systems Security Professional) exam does not expect you to become a lawyer.
However, a security professional must understand how laws, regulations, contracts, industry standards, privacy requirements, and intellectual-property rights affect information security.
The important skill is scenario recognition.
When you see a CISSP question, ask:
What is being protected?
Then:
What legal, regulatory, contractual, or compliance requirement applies?
This guide focuses on the concepts useful for CISSP Domain 1 — Security and Risk Management, particularly the legal, regulatory, and compliance topics in Domain 1.4.
1. The CISSP Legal & Regulatory Mental Model
CISSP LEGAL & REGULATORY
│
┌──────────────────────┼──────────────────────┐
│ │ │
Intellectual Property Privacy Cybercrime
│ │ │
Copyright GDPR CFAA
DMCA CCPA/CPRA ITADA
Patent HIPAA ECPA
Trademark FERPA
Trade Secret COPPA
Licensing
│ │ │
└──────────────────────┼──────────────────────┘
│
┌───────────────┼────────────────┐
│ │ │
Cross-Border Contracts Industry /
Issues Regulatory
│ │ │
Transborder Data Security PCI DSS
Flow obligations
Import/Export Liability
Controls
The goal is not to memorize hundreds of laws.
The goal is to recognize:
Information
↓
Security / Legal Issue
↓
Applicable Requirement
↓
Security / Compliance Action
2. Intellectual Property
What is Intellectual Property?
Intellectual Property (IP) refers to creations of the human mind that can receive legal protection.
For CISSP, know these major categories:
Copyright → Creative work
Patent → Invention
Trademark → Brand
Trade Secret → Confidential business information
3. Copyright
What is Copyright?
Copyright protects original creative works.
Examples:
Software source code
Documentation
Books
Music
Videos
Images
Practical Security Example
A company develops a proprietary application.
An employee copies the company's source code and publishes it online without authorization.
The organization may have copyright and intellectual-property concerns.
CISSP Perspective
When the question says:
"Original work"
Think:
Copyright
Memory Point
Copyright = CREATE
4. DMCA — Digital Millennium Copyright Act
Full Form
DMCA = Digital Millennium Copyright Act
DMCA is a U.S. law dealing with copyright protection in the digital environment.
For CISSP, the most important concept is:
Digital copyrighted content + technological protection measures
What is DRM?
DRM = Digital Rights Management
DRM refers to technologies used to control access to or use of digital content.
Examples:
Streaming-video copy protection
E-book restrictions
Software activation
Digital music protection
Encryption-based content controls
Simple Example
Streaming Service
↓
Encrypted Movie
↓
DRM Protection
↓
Authorized User
DRM may help prevent:
Unauthorized copying
Unauthorized playback
Redistribution
Circumvention
DMCA + DRM Example
A streaming company uses DRM to prevent unauthorized copying of copyrighted movies.
An attacker develops a tool specifically designed to bypass the DRM and then distributes the protected content.
The situation raises:
DMCA / digital copyright concerns
For CISSP, understand the relationship:
DMCA can address circumvention of technological measures protecting copyrighted digital material.
When is DMCA relevant?
Think about DMCA when a scenario involves:
Digital copyrighted material
Unauthorized copying
Copyright protection technology
Circumvention of technological protection
DRM
Digital content distribution
Memory Point
DMCA = DIGITAL COPYRIGHT
And:
DRM = TECHNOLOGY USED TO CONTROL ACCESS/USE OF DIGITAL CONTENT
CISSP Exam Trap
Don't think:
❌ DMCA = cybersecurity law
Think:
✅ DMCA = copyright law with important digital-security implications
5. Patent
A patent provides legal protection for qualifying inventions.
Examples:
New encryption mechanism
Novel hardware technology
New technical process
Practical Example
A company invents a new hardware-based security mechanism and seeks legal protection for the invention.
CISSP Memory Point
Patent = INVENT
6. Trademark
A trademark protects brand identifiers.
Examples:
Company name
Logo
Brand name
Symbol
Certain slogans
Practical Example
An attacker creates a fake website using a company's logo and brand name to deceive customers.
This can involve:
Trademark issues
Brand abuse
Phishing
Fraud
CISSP Memory Point
Trademark = BRAND
7. Trade Secret
A trade secret is valuable business information that derives value from being kept secret.
Examples:
Proprietary algorithms
Source code
Secret formulas
Customer lists
Manufacturing processes
Business strategies
Practical Security Example
A company has a proprietary AI algorithm.
Instead of publishing it or seeking patent protection, it:
Restricts access
Uses NDAs
Encrypts the source code
Monitors access
Uses DLP
Applies least privilege
This supports maintaining the information as a trade secret.
CISSP Insight
Security controls can help maintain trade-secret protection.
Trade Secret
↓
Must remain confidential
↓
Security Controls
↓
Access Control
Encryption
DLP
Least Privilege
Monitoring
NDA
Memory Point
Trade Secret = KEEP SECRET
8. Intellectual Property — Ultimate Map
Copyright → CREATE
Patent → INVENT
Trademark → BRAND
Trade Secret → KEEP SECRET
DMCA → DIGITAL COPYRIGHT
9. Software Licensing
A software license defines how software may legally be:
Used
Copied
Modified
Distributed
Examples:
Commercial licenses
Proprietary licenses
Open-source licenses
Subscription licenses
Practical Example
A developer downloads a commercial security library and integrates it into a product.
Before doing so, the organization should verify:
Is commercial use permitted?
Can it be modified?
Can it be redistributed?
Are attribution requirements applicable?
Are there license restrictions?
CISSP Perspective
This can become:
Legal + contractual + intellectual-property compliance
Memory Point
License = PERMISSION TO USE
10. Privacy
Privacy is a major CISSP concept.
Think about:
Personal data
Personally identifiable information
Collection
Processing
Storage
Sharing
Retention
Deletion
Data subject rights
Breach notification
11. GDPR
Full Form
GDPR = General Data Protection Regulation
GDPR is the European Union's major data-protection regulation.
For CISSP, understand:
Personal data
Data protection
Data minimization
Purpose limitation
Accountability
Data subject rights
Controllers
Processors
Breach obligations
Practical Example
A company collects:
Name
Email
IP Address
Location
Customer ID
The organization needs to consider:
Why is the data being collected?
Is the collection necessary?
How is it protected?
Who can access it?
How long is it retained?
What rights do individuals have?
What happens if it is breached?
CISSP Memory Point
GDPR = PERSONAL DATA
12. CCPA / CPRA
Full Forms
CCPA = California Consumer Privacy Act
CPRA = California Privacy Rights Act
For CISSP, think:
Consumer privacy
Practical Example
A company collects personal information from consumers in California.
The company needs to understand applicable consumer privacy requirements concerning collection, use, sharing, and consumer rights.
Memory Point
CCPA/CPRA = CONSUMER PRIVACY
13. HIPAA
Full Form
HIPAA = Health Insurance Portability and Accountability Act
For CISSP, the most important concept is:
PHI = Protected Health Information
Practical Example
A hospital stores:
Patient Name
Medical History
Diagnosis
Treatment
Insurance Information
Security controls may include:
Access control
Encryption
Audit logging
Authentication
Physical safeguards
Technical safeguards
Memory Point
HIPAA = HEALTHCARE / PHI
14. FERPA
Full Form
FERPA = Family Educational Rights and Privacy Act
FERPA concerns privacy of certain student education records in the U.S.
Practical Example
A university stores:
Student grades
Academic records
Student identification information
Memory Point
FERPA = EDUCATION RECORDS
15. COPPA
Full Form
COPPA = Children's Online Privacy Protection Act
It addresses online privacy protections for children under 13 in the U.S. context.
Practical Example
A website directed toward young children collects personal information.
The organization must consider applicable COPPA requirements.
Memory Point
COPPA = CHILDREN
16. Privacy Memorize Map
GDPR → PERSONAL DATA
CCPA/CPRA → CONSUMER PRIVACY
HIPAA → HEALTHCARE / PHI
FERPA → EDUCATION RECORDS
COPPA → CHILDREN
17. Financial Regulations
GLBA
Full Form
GLBA = Gramm-Leach-Bliley Act
GLBA is associated with protecting the privacy and security of customer financial information held by financial institutions.
Practical Example
A bank stores:
Account Numbers
Transaction History
Loan Information
Customer Financial Information
The bank needs appropriate privacy and security safeguards.
CISSP Memory Point
GLBA = CUSTOMER FINANCIAL INFORMATION
18. SOX
Full Form
SOX = Sarbanes-Oxley Act
SOX is strongly associated with:
Corporate financial reporting
Internal controls
Accountability
Integrity of financial information
Practical Example
A publicly traded company maintains financial records in a database.
An administrator can modify financial records without proper authorization or auditability.
This creates concerns involving:
Internal controls
Accountability
Integrity
Financial reporting
CISSP Memory Point
SOX = CORPORATE FINANCIAL REPORTING
19. FCRA
Full Form
FCRA = Fair Credit Reporting Act
FCRA concerns consumer reporting and credit information.
Practical Example
A credit-reporting organization maintains consumer credit information.
Accuracy, privacy, and proper handling of that information become important.
Memory Point
FCRA = CREDIT REPORTING
20. FACTA
Full Form
FACTA = Fair and Accurate Credit Transactions Act
FACTA amended FCRA and includes provisions related to consumer information and identity theft.
Memory Point
FACTA = CREDIT + IDENTITY THEFT
21. PCI DSS
Full Form
PCI DSS = Payment Card Industry Data Security Standard
PCI DSS focuses on protecting payment-card data.
Practical Example
An e-commerce company processes credit-card payments.
Security controls may include:
Network segmentation
Access control
Encryption
Logging
Vulnerability management
Secure configuration
Monitoring
VERY IMPORTANT
PCI DSS is:
An industry security standard, NOT a law.
It can nevertheless become a business requirement through contracts, payment networks, or other obligations.
Memory Point
PCI DSS = PAYMENT CARDS
22. Financial Memorize Map
GLBA → CUSTOMER FINANCIAL INFORMATION
SOX → CORPORATE FINANCIAL REPORTING
FCRA → CREDIT REPORTING
FACTA → CREDIT + IDENTITY THEFT
PCI DSS → PAYMENT CARDS
23. Cybercrime & Computer Misuse
Cybercrime involves illegal activity involving computers, networks, systems, or data.
Examples:
Unauthorized access
Computer fraud
Credential theft
Malware
Data theft
Destruction of systems
For CISSP, recognize that a cyber incident can have technical, legal, regulatory, and contractual consequences.
24. CFAA
Full Form
CFAA = Computer Fraud and Abuse Act
The CFAA is a U.S. federal law associated with certain forms of unauthorized access and misuse of computers.
Practical Example
An attacker obtains credentials and accesses a corporate server without authorization.
The security issue is:
Unauthorized computer access
Memory Point
CFAA = COMPUTER ACCESS
25. ITADA
Full Form
ITADA = Illinois Computer Crime Act / Illinois computer-related criminal law is an example of U.S. state-level legislation addressing computer-related offenses and unauthorized use/access.
For CISSP, the important point is not the detailed Illinois statute.
The important concept is:
State-level computer crime laws can also apply to unauthorized computer access or misuse.
Practical Example
A person intentionally accesses a computer system without authorization or misuses computer resources in violation of applicable state law.
This can create:
Criminal liability
Civil consequences
Organizational incident-response obligations
Evidence-preservation requirements
CISSP Memory Point
ITADA → STATE-LEVEL COMPUTER CRIME
Important CISSP Perspective
Don't spend significant study time memorizing ITADA's specific sections or penalties.
Understand the broader concept:
Federal Computer Crime
↓
CFAA
State Computer Crime
↓
State-specific laws
↓
Example: ITADA / Illinois
The exam value is the computer-crime concept, not Illinois statutory details.
26. ECPA
Full Form
ECPA = Electronic Communications Privacy Act
ECPA addresses privacy protections involving electronic communications.
Practical Example
An organization wants to monitor employee electronic communications.
The security team should consider:
Applicable laws
Organizational policy
Consent
Contracts
Jurisdiction
Privacy requirements
Memory Point
ECPA = ELECTRONIC COMMUNICATIONS
27. Cybercrime Memorize Map
CFAA
→ UNAUTHORIZED COMPUTER ACCESS
→ U.S. FEDERAL COMPUTER CRIME
ITADA
→ STATE-LEVEL COMPUTER CRIME
→ Example: Illinois
ECPA
→ ELECTRONIC COMMUNICATIONS
→ PRIVACY
Important CISSP Study Tip
CFAA and ITADA are not two laws you need to memorize in equal depth.
For CISSP:
CFAA → Know the federal computer-crime concept
ITADA → Recognize that state-level computer-crime laws also exist
ECPA → Know electronic-communication privacy
28. Data Breach — CISSP Perspective
A data breach is not simply a technical incident.
It can create:
Legal obligations
Regulatory obligations
Contractual obligations
Notification requirements
Privacy obligations
Evidence-preservation requirements
Practical Example
A company discovers that an attacker accessed a database containing customer personal information.
The security team should ask:
What data?
↓
Whose data?
↓
Which jurisdictions?
↓
Which laws apply?
↓
Is notification required?
↓
Who must be notified?
↓
What contractual obligations exist?
CISSP Memory Point
BREACH = TECHNICAL + LEGAL + REGULATORY + CONTRACTUAL
29. Transborder Data Flow
What does it mean?
Transborder data flow means data is transferred or processed across national or jurisdictional boundaries.
Practical Example
Customer
Germany
↓
Application
India
↓
Cloud
United States
The organization needs to consider:
Privacy laws
Data-transfer requirements
Data residency
Contractual restrictions
Regulatory requirements
Jurisdiction
CISSP Memory Point
Transborder Data Flow = DATA CROSSING JURISDICTIONS
30. Import / Export Controls
Certain technologies may be subject to restrictions when transferred across borders.
For CISSP, think particularly about:
Encryption technology
Security technologies
Sensitive hardware/software
Controlled technologies
Practical Example
A company wants to export a product containing advanced cryptographic functionality.
Before exporting, the organization should determine whether applicable export-control requirements apply.
Memory Point
Import/Export Controls = TECHNOLOGY CROSSING BORDERS
31. Contracts
Security requirements don't always come from laws.
They can come from contracts.
Examples:
NDA — Non-Disclosure Agreement
SLA — Service Level Agreement
DPA — Data Processing Agreement
Security addendum
Vendor agreement
Cloud service agreement
Practical Example
A cloud provider contract requires:
Security incidents involving customer data must be reported within 24 hours.
Even if a specific law doesn't impose that exact contractual deadline, the organization may still have a contractual obligation to comply.
CISSP Memory Point
Contract = LEGAL OBLIGATION BETWEEN PARTIES
32. Industry Standards vs Laws
A CISSP question may deliberately distinguish between these.
LAW
↓
Government requirement
REGULATION
↓
Government / regulatory requirement
CONTRACT
↓
Agreement between parties
INDUSTRY STANDARD
↓
Industry-defined requirement
Examples
HIPAA → U.S. healthcare law/regulatory framework
GDPR → European data-protection regulation
PCI DSS → Industry standard
NDA → Contract
Don't automatically assume that every security requirement is a law.
33. Due Care vs Due Diligence
These are very important CISSP concepts.
Due Care
Taking reasonable actions to protect the organization.
Examples:
Establish policies
Implement security controls
Protect sensitive information
Establish procedures
Memory Point
Due Care = DO
34. Due Diligence
Due diligence means investigating, evaluating, and verifying that security measures are appropriate and effective.
Examples:
Security assessments
Vulnerability assessments
Vendor assessments
Reviewing controls
Monitoring compliance
Memory Point
Due Diligence = CHECK
Easy Trick
Due Care
↓
DO
Due Diligence
↓
CHECK
35. Data Owner vs Data Custodian
Data Owner
The person/business function responsible for determining:
Classification
Access requirements
Protection requirements
Retention requirements
Owner = DECIDES
Data Custodian
The party responsible for implementing and maintaining the required controls.
Examples:
IT administrators
Cloud administrators
Database administrators
Custodian = IMPLEMENTS
Memory Map
OWNER
↓
DECIDES
CUSTODIAN
↓
IMPLEMENTS
36. Jurisdiction
What is Jurisdiction?
Jurisdiction is the authority of a particular legal system to govern or adjudicate a matter.
Practical Example
A company is headquartered in India.
Its customers are in Europe.
Its cloud infrastructure is in the United States.
A security incident exposes customer data.
The organization may need to consider multiple jurisdictions.
CISSP Memory Point
Jurisdiction = WHO HAS LEGAL AUTHORITY?
37. Civil vs Criminal Law
Civil Law
Generally concerns disputes between parties.
Examples:
Contract disputes
Damages
Injunctions
Memory Point
Civil = DISPUTE
Criminal Law
Concerns offenses prosecuted by the government.
Examples:
Certain forms of unauthorized access
Fraud
Theft
Destruction of systems
Memory Point
Criminal = OFFENSE
38. CISSP Real-World Scenario
Consider a global financial company:
Customer
↓
Germany
↓
Personal Data
↓
Application
↓
India
↓
Cloud Infrastructure
↓
United States
Now suppose an attacker compromises the application.
A CISSP should think:
Personal Data
↓
Privacy Requirements
Multiple Countries
↓
Jurisdiction
Data Crossing Countries
↓
Transborder Data Flow
Security Incident
↓
Breach Requirements
Cloud Provider
↓
Contractual Requirements
Financial Institution
↓
Applicable Financial Regulations
Proprietary Software
↓
Intellectual Property
Unauthorized Access
↓
Cybercrime Requirements
This is the holistic security-management mindset CISSP is looking for.
39. CISSP Practice Questions
Question 1 — DMCA
A streaming company uses DRM to prevent unauthorized copying of copyrighted movies. An attacker develops a tool specifically designed to bypass the DRM protection.
Which legal concept is MOST relevant?
A. SOX
B. DMCA
C. HIPAA
D. FCRA
Answer: B — DMCA
The scenario involves:
Digital copyrighted material
DRM
Circumvention of technological protection
Memory Point
DMCA = DIGITAL COPYRIGHT + ANTI-CIRCUMVENTION
Question 2 — DRM
What is the primary purpose of Digital Rights Management (DRM)?
A. Detect network intrusions
B. Control access to and use of digital content
C. Encrypt network traffic
D. Manage security vulnerabilities
Answer: B
DRM is a technology used to control how digital content is accessed, copied, used, or distributed.
Memory Point
DRM = CONTROL DIGITAL CONTENT USE
Question 3 — Intellectual Property
A company develops a novel encryption mechanism and wants legal protection for the invention.
Which is MOST appropriate?
A. Copyright
B. Trademark
C. Patent
D. Trade secret
Answer: C — Patent
Patent = INVENT
Question 4 — Trade Secret
A company protects its proprietary algorithm by restricting access, using encryption, and requiring employees to sign NDAs.
Which IP concept is MOST relevant?
A. Trademark
B. Trade secret
C. Copyright
D. Patent
Answer: B
The organization is attempting to maintain the information as secret and confidential.
Trade Secret = KEEP SECRET
Question 5 — GLBA
A bank needs to protect customer financial information.
Which regulation is MOST directly relevant?
A. GLBA
B. DMCA
C. FERPA
D. CFAA
Answer: A — GLBA
GLBA = CUSTOMER FINANCIAL INFORMATION
Question 6 — SOX
A publicly traded company needs strong controls over the integrity and accountability of corporate financial reporting.
Which regulation is MOST relevant?
A. HIPAA
B. SOX
C. GDPR
D. DMCA
Answer: B — SOX
SOX = CORPORATE FINANCIAL REPORTING
Question 7 — Privacy
An organization processes personal data of individuals covered by GDPR.
What should the security professional primarily consider?
A. Copyright protection
B. Personal-data protection and privacy requirements
C. Payment-card requirements
D. Software licensing
Answer: B
GDPR = PERSONAL DATA
Question 8 — Cybercrime
An attacker accesses a company's server without authorization.
Which U.S. federal law is most closely associated with unauthorized computer access?
A. CFAA
B. HIPAA
C. FERPA
D. DMCA
Answer: A — CFAA
CFAA = COMPUTER ACCESS
Question 9 — State Computer Crime
A security professional is investigating unauthorized computer access and discovers that the incident may also violate applicable state computer-crime legislation.
Which concept should the security professional understand?
A. Only federal law can apply to computer crime
B. State computer-crime laws may also apply
C. Copyright law automatically applies
D. PCI DSS determines criminal liability
Answer: B
State-level computer-crime laws can apply in addition to applicable federal laws.
Memory Point
ITADA → STATE-LEVEL COMPUTER CRIME
Question 10 — Transborder Data Flow
A company stores customer data in the United States while processing the data in India.
Which concept should the security professional consider?
A. Trademark
B. Transborder data flow
C. Copyright
D. Patent
Answer: B
Transborder Data Flow = DATA CROSSING JURISDICTIONS
Question 11 — Due Care
An organization establishes security policies and implements appropriate security controls.
What does this BEST represent?
A. Due diligence
B. Due care
C. Jurisdiction
D. Liability
Answer: B — Due Care
Due Care = DO
Question 12 — Due Diligence
An organization regularly evaluates its security controls and performs security assessments to determine whether they remain effective.
What does this BEST represent?
A. Due care
B. Due diligence
C. Data ownership
D. Licensing
Answer: B — Due Diligence
Due Diligence = CHECK
Question 13 — Industry Standard
An organization accepts payment cards and must follow requirements established by the payment-card industry.
What is MOST relevant?
A. PCI DSS
B. DMCA
C. CFAA
D. FERPA
Answer: A — PCI DSS
Important:
PCI DSS is an industry standard, NOT a law.
40. The Ultimate CISSP Laws & Regulations Memorize Map
╔════════════════════════════════════════════════════╗
║ CISSP LAWS & REGULATIONS — MEMORIZE MAP ║
╚════════════════════════════════════════════════════╝
INTELLECTUAL PROPERTY
────────────────────────────────────────────────────
Copyright
→ CREATE / Creative Work
DMCA
→ DIGITAL COPYRIGHT
→ DRM / Anti-Circumvention
Patent
→ INVENT
Trademark
→ BRAND
Trade Secret
→ KEEP SECRET
Licensing
→ PERMISSION TO USE
PRIVACY
────────────────────────────────────────────────────
GDPR
→ PERSONAL DATA
CCPA / CPRA
→ CONSUMER PRIVACY
HIPAA
→ HEALTHCARE / PHI
FERPA
→ EDUCATION RECORDS
COPPA
→ CHILDREN
FINANCIAL
────────────────────────────────────────────────────
GLBA
→ CUSTOMER FINANCIAL INFORMATION
SOX
→ CORPORATE FINANCIAL REPORTING
FCRA
→ CREDIT REPORTING
FACTA
→ CREDIT + IDENTITY THEFT
PCI DSS
→ PAYMENT CARDS
→ INDUSTRY STANDARD, NOT LAW
CYBERCRIME / COMPUTER MISUSE
────────────────────────────────────────────────────
CFAA
→ UNAUTHORIZED COMPUTER ACCESS
→ U.S. FEDERAL COMPUTER CRIME
ITADA
→ STATE-LEVEL COMPUTER CRIME
→ ILLINOIS EXAMPLE
ECPA
→ ELECTRONIC COMMUNICATIONS
→ PRIVACY
CROSS-BORDER
────────────────────────────────────────────────────
Transborder Data Flow
→ DATA CROSSING JURISDICTIONS
Import / Export Controls
→ TECHNOLOGY CROSSING BORDERS
LEGAL / GOVERNANCE
────────────────────────────────────────────────────
Contracts
→ LEGAL OBLIGATIONS BETWEEN PARTIES
Jurisdiction
→ WHO HAS LEGAL AUTHORITY?
Civil
→ DISPUTE
Criminal
→ OFFENSE
Due Care
→ DO
Due Diligence
→ CHECK
Data Owner
→ DECIDES
Data Custodian
→ IMPLEMENTS
41. The 30-Second CISSP Revision
If you have only 30 seconds before the exam, remember:
DMCA = DIGITAL COPYRIGHT
GLBA = FINANCIAL INFORMATION
SOX = FINANCIAL REPORTING
GDPR = PERSONAL DATA
HIPAA = HEALTHCARE / PHI
CFAA = COMPUTER ACCESS
ITADA = STATE COMPUTER CRIME
ECPA = ELECTRONIC COMMUNICATIONS
PCI DSS = PAYMENT CARDS
Copyright = CREATE
Patent = INVENT
Trademark = BRAND
Trade Secret = KEEP SECRET
License = PERMISSION TO USE
Transborder Data Flow
= DATA CROSSING JURISDICTIONS
Import/Export
= TECHNOLOGY CROSSING BORDERS
Due Care = DO
Due Diligence = CHECK
Owner = DECIDES
Custodian = IMPLEMENTS
Civil = DISPUTE
Criminal = OFFENSE
Jurisdiction = LEGAL AUTHORITY
42. Final CISSP Exam Strategy
Don't memorize laws as isolated facts.
Train yourself to recognize the scenario.
CISSP SCENARIO
│
▼
What is being protected?
│
┌──────────┼──────────┐
▼ ▼ ▼
Data IP System
│ │ │
▼ ▼ ▼
Privacy Copyright Cybercrime
GDPR Patent CFAA
HIPAA Trademark ITADA
Trade Secret ECPA
│
▼
Which jurisdiction?
│
▼
Which law / regulation /
contract / standard?
│
▼
What security obligation?
The CISSP mindset is:
Identify the asset → identify the legal issue → identify the applicable requirement → determine the security obligation.
You are not expected to practice law.
You are expected to understand how legal and regulatory requirements affect information-security decisions.
Final Memory Formula
IP
→ Create / Invent / Brand / Secret
PRIVACY
→ Personal / Health / Education / Children
FINANCE
→ Customer Finance / Financial Reporting / Credit / Cards
CYBERCRIME
→ Unauthorized Access / Communications
CROSS-BORDER
→ Data / Technology Crossing Borders
GOVERNANCE
→ Contract / Jurisdiction / Due Care / Due Diligence
OWNER
→ DECIDES
CUSTODIAN
→ IMPLEMENTS
CISSP Golden Rule
Don't memorize the law. Understand the security scenario that makes the law relevant.

