Skip to content

ITIS-468-47605: Certified Information Systems Security Professional (CISSP) Cert Exam Prep

Fall 2026

Law, Ethics, and Business Continuity

Legal systems and liability

Civil (code) law relies on codified statutes; common law relies on judicial precedent and splits into criminal, civil/tort, and administrative categories. Customary and religious law systems exist too, and many countries use mixed systems. Intellectual property protections include trade secret, copyright, trademark, and patent.

  • Criminal law — punishment includes imprisonment; burden of proof is 'beyond a reasonable doubt'.
  • Civil law — remedies are financial; burden is 'preponderance of the evidence'.
  • Privacy regimes: GDPR-style data protection, HIPAA for health data, GLBA for financial, PCI DSS as an industry standard.
  • Prudent-person rule: management must show due care or face downstream liability.

The (ISC)² Code of Ethics — canons in order

  • Protect society, the common good, necessary public trust and confidence, and the infrastructure.
  • Act honorably, honestly, justly, responsibly, and legally.
  • Provide diligent and competent service to principals.
  • Advance and protect the profession.

Business continuity

The Business Impact Analysis (BIA) is the heart of business continuity planning. It identifies critical functions, the maximum tolerable downtime (MTD) for each, and the resources those functions depend on. Recovery targets are then set inside the MTD.

  • MTD — maximum tolerable downtime before the business is critically harmed.
  • RTO — recovery time objective; how fast a function must be restored (must be < MTD).
  • RPO — recovery point objective; how much data loss is tolerable.
  • Plans must be tested: checklist, tabletop/structured walk-through, simulation, parallel, full-interruption.

Exam tip

Human safety always comes first. If any answer choice protects human life, it is the right answer.