Domain 2 accounts for 17.3% of the ISC2 Certified in Cybersecurity (CC) outline effective September 1, 2026. It asks how an organization directs cybersecurity work, keeps important functions resilient, builds security-aware behavior, and decides whether the security program is producing useful results.

The four objectives fit together. Governance, Risk, and Compliance (GRC) establishes structure and accountability. Redundancy supports resilience. Awareness and leadership influence everyday behavior. Metrics and reporting provide evidence that leaders can use to adjust priorities.

1. Domain 2 map

ObjectiveOfficial focusUseful question
2.1Purpose and importance of Governance, Risk, and Compliance (GRC); frameworks; toolsHow does the organization organize security decisions, obligations, risk, evidence, and accountability?
2.2Redundancy supporting business continuity and disaster recoveryWhat dependency could fail, and what alternate capability keeps the important function available or recoverable?
2.3Security awareness, security culture, leadership, social engineering, password protection, phishingWhat behavior, leadership support, or learning activity reduces human-centered security risk?
2.4Cybersecurity effectiveness using metrics, Key Risk Indicators (KRI), dashboards, scorecards, and reportsWhat evidence would help the intended audience understand risk, performance, or needed action?

2. Governance, Risk, and Compliance (GRC)

GRC is a way to coordinate three related responsibilities instead of managing them as disconnected activities.

  • Governance sets direction, accountability, expectations, and oversight.
  • Risk management identifies uncertainty and potential harm, evaluates priorities, and supports treatment decisions.
  • Compliance addresses obligations from laws, regulations, contracts, policies, standards, or other requirements.

The value of GRC is coordination. A new regulation may create a compliance requirement, but the organization still needs governance to assign responsibility and risk management to understand where the requirement matters most. A risk assessment may identify a serious exposure, but governance determines who can approve the response and how it fits organizational priorities.

GRC does not mean compliance equals security. Compliance can establish required minimums or evidence, while risk management asks whether the organization’s actual risks are understood and treated appropriately.

3. Keep governance, risk, and compliance distinct

AreaMain concernExample decision
GovernanceDirection, accountability, authority, oversightWho owns the risk and what reporting does leadership require?
RiskLikelihood, impact, uncertainty, priorities, treatmentWhich exposure needs action first and what residual risk remains?
ComplianceMeeting and demonstrating applicable requirementsWhat evidence shows the required control or process is in place?

One event can involve all three. Suppose a business launches a service that handles regulated information. Governance assigns ownership and establishes policy. Risk management evaluates threats and business impact. Compliance maps applicable obligations and evidence. Treating any one of those activities as the entire security program leaves gaps.

4. Frameworks and GRC tools

A cybersecurity framework helps organize outcomes, practices, responsibilities, or controls into a repeatable structure. NIST Cybersecurity Framework (CSF) 2.0, for example, provides high-level cybersecurity outcomes that organizations can use to understand, assess, prioritize, and communicate cybersecurity work. Its Govern function emphasizes strategy, roles, responsibilities, policy, oversight, and cybersecurity risk as part of enterprise risk.

For CC, focus on why an organization uses a framework:

  • create common language;
  • organize security outcomes or controls;
  • compare current and desired practices;
  • support prioritization;
  • connect cybersecurity work to business and risk decisions;
  • improve communication between technical teams and leadership.

GRC tools can help maintain risk registers, control mappings, policies, evidence, findings, exceptions, ownership, and reporting. The tool supports the process. It does not replace accountable people or make a risk decision automatically.

Framework versus tool

A framework tells an organization how to structure or think about cybersecurity outcomes. A GRC platform or tracking system helps manage the records and workflow used to apply that structure.

If an exam scenario asks what establishes a common structure for managing cybersecurity outcomes, think framework. If it asks what helps track evidence, owners, findings, and status across many requirements, a GRC tool may fit better.

5. Redundancy supports resilience

Redundancy means providing alternate components, paths, resources, or capabilities so one failure does not automatically stop an important function.

Examples can include:

  • multiple power sources;
  • redundant network paths;
  • clustered or failover systems;
  • alternate storage or processing capacity;
  • geographically separated facilities or services;
  • more than one critical provider where the business risk justifies it.

The important idea is dependency failure. Ask what could fail and whether another capability is ready to take over.

Redundancy is not the same as backup

A backup creates another copy of data for restoration. Redundancy can keep a service operating or make failover faster when a component fails. The two can support the same resilience goal but solve different problems.

A replicated system can also copy corruption or malicious changes, so redundancy does not eliminate the need for protected backups and recovery planning.

6. Business continuity and disaster recovery

Business Continuity (BC) and Disaster Recovery (DR) are closely related but have different centers of gravity.

AreaPrimary focusExample question
Business continuityKeep critical business or mission functions operating through disruption.How will the organization continue the essential service if a normal dependency is unavailable?
Disaster recoveryRestore technology, data, facilities, or supporting capabilities after major disruption.How will the failed technology capability be recovered or rebuilt?

NIST contingency-planning guidance connects planning with a Business Impact Analysis (BIA), preventive controls, recovery strategies, plan development, exercises, and maintenance. The CC-level lesson is that resilience should be based on business priorities and dependencies, not on treating every system as equally critical.

Testing matters

A redundant component or recovery plan that has never been tested creates uncertainty. Exercises reveal missing dependencies, expired contact information, unclear authority, capacity problems, and procedures that work on paper but fail under real conditions.

For deeper review of recovery measurements such as Recovery Time Objective (RTO) and Recovery Point Objective (RPO), use the Recovery Metrics Quick Review.

7. Security awareness is about behavior

Security awareness helps people recognize security responsibilities and common threats so they can make safer decisions during normal work.

A useful program is not just a once-a-year presentation. NIST SP 800-50 Rev. 1 describes a lifecycle approach to cybersecurity and privacy learning that supports behavior change, security culture, evaluation, and continued improvement.

Awareness activities can help people:

  • recognize suspicious messages and requests;
  • protect authentication secrets and passwords;
  • use approved reporting channels;
  • handle information according to policy;
  • understand why security requirements matter;
  • recognize when an unusual request should be verified before action.

Training can become more specific when someone needs a particular skill for a role. Awareness provides broad recognition and expected behavior; training develops more targeted ability.

8. Security culture needs visible leadership

A security culture develops when secure behavior is expected, supported, and reinforced through everyday decisions.

Leadership matters because people notice what managers reward, ignore, fund, and model. A policy that says “report suspicious activity” is weaker if employees are punished for slowing down to verify a request. Security culture improves when leaders make safe behavior practical.

Useful leadership behaviors include:

  • communicating that cybersecurity is part of normal business responsibility;
  • providing time and resources for required learning;
  • making reporting channels easy to use;
  • avoiding incentives that encourage people to bypass controls;
  • responding constructively to reported mistakes or suspicious activity;
  • reviewing program results and adjusting priorities.

Culture is not measured by whether everyone completed a course. Completion is evidence of participation, not proof that behavior changed.

9. Social engineering, phishing, and password protection

Social engineering targets people by manipulating trust, urgency, authority, curiosity, fear, helpfulness, or routine behavior.

Phishing

Phishing uses deceptive messages or interactions to persuade someone to reveal information, follow a malicious link, open harmful content, approve an action, or bypass normal verification.

The strongest defensive habit is not memorizing what a “bad email” looks like. It is recognizing when a request deserves independent verification.

Questions to ask:

  • Is the request unusual for this sender or role?
  • Does it create artificial urgency or secrecy?
  • Is it asking for credentials, payment, sensitive data, or a security bypass?
  • Can the request be verified through a known, separate channel?
  • Should it be reported even if no harmful action was taken?

Password protection

Password protection includes choosing and handling authentication secrets according to organizational policy. Users should not share passwords, expose them in insecure locations, or reuse them in ways that increase organizational risk.

The CC objective is not a password-composition trivia contest. The security goal is to keep authentication secrets from becoming an easy path to unauthorized access and to encourage reporting when compromise is suspected.

10. Measure cybersecurity effectiveness for a decision

Measurement is useful when it helps someone understand performance, risk, trends, or required action.

A number without context can be misleading. “500 blocked attacks” sounds important, but it does not tell leadership whether material risk increased, controls performed as expected, or important systems remain exposed.

Start with the decision:

  1. Who is the audience?
  2. What do they need to understand?
  3. Which measure is relevant to that decision?
  4. What threshold, target, trend, or comparison gives the number meaning?
  5. What action should follow if the result is outside expectations?

Different audiences need different levels of detail. An operations team may need daily technical measurements. Senior leadership usually needs a smaller set tied to business risk, major obligations, important trends, and decisions.

11. Metrics and Key Risk Indicators (KRI)

A metric is a measurement used to describe activity, performance, condition, or result. A Key Risk Indicator (KRI) is a selected measure that provides useful warning or visibility into important risk.

MeasurePossible use
Percentage of critical recovery plans exercised on scheduleShows whether resilience plans are being validated rather than merely documented.
Rate of suspicious-message reporting after awareness activitiesCan help evaluate whether people recognize and report potential social engineering.
Number of high-risk exceptions past their approved review dateMay serve as a KRI showing growing unresolved exposure.
Critical dependencies without a tested alternate capabilityCan highlight concentration and resilience risk.

A KRI should be tied to a risk that matters. Calling every operational count a KRI makes the term less useful.

Measures can create bad incentives

If a program measures only “training completion,” people may optimize for finishing quickly rather than learning. If a help desk is measured only on speed, employees may feel pressure to skip identity verification. Good measures consider the behavior they encourage.

12. Dashboards, scorecards, and reports

These formats organize information for different purposes.

FormatUseful role
DashboardProvides an at-a-glance view of selected current measures, status, or trends.
ScorecardCompares performance or risk measures with targets, thresholds, objectives, or categories.
ReportProvides more context, analysis, evidence, findings, conclusions, or recommended actions.

The best format depends on the audience and question. A dashboard is useful for quick status. A report is better when leadership needs explanation, causes, assumptions, and a decision recommendation.

Do not confuse presentation with evidence. A polished dashboard cannot make weak or irrelevant data meaningful.

13. Common Domain 2 exam traps

Compliance is not the whole security program

Meeting a requirement may be necessary, but the organization still has to understand risks that the requirement does not fully address.

A GRC tool does not own risk

A system can store the risk register, evidence, findings, and approvals. Accountable people still make decisions.

Backup and redundancy solve different problems

A backup supports restoration. Redundancy can maintain or quickly restore capability when a component fails. Good resilience may require both.

Business continuity is not just disaster recovery

Continuity focuses on keeping important business functions operating. Disaster recovery focuses more directly on restoring disrupted technology and supporting capabilities.

Awareness completion does not prove behavior changed

Course completion is one metric. Reporting behavior, simulation results, incidents, observations, and other evidence may provide a broader view of effectiveness.

Leadership cannot outsource security culture to the training team

Learning programs matter, but daily priorities, incentives, decisions, and example-setting shape culture.

More metrics do not automatically mean better governance

Choose measures that help the intended audience understand risk, performance, or needed action.

A dashboard is not automatically better than a report

Use the format that fits the decision. Quick status and detailed analysis are different needs.

14. Rapid review checklist

Before leaving Domain 2, make sure you can explain:

  • [ ] Why Governance, Risk, and Compliance (GRC) activities are coordinated
  • [ ] Governance versus risk management versus compliance
  • [ ] What a cybersecurity framework contributes
  • [ ] What a GRC tool can track and what it cannot decide
  • [ ] Redundancy versus backup
  • [ ] Business continuity versus disaster recovery
  • [ ] Why recovery strategies and alternate capabilities should be exercised
  • [ ] Security awareness versus more targeted training
  • [ ] How leadership affects security culture
  • [ ] Common social-engineering and phishing warning signs
  • [ ] The purpose of password protection and independent verification
  • [ ] Metric versus Key Risk Indicator (KRI)
  • [ ] Dashboard versus scorecard versus report
  • [ ] Why a measure needs an audience, context, and decision

If a measure cannot be connected to a meaningful security or business question, ask whether it belongs in the report at all.

15. Official and primary references

Use the ISC2 outline as the authoritative scope for this domain:

Primary references that add context:

These sources add depth for governance, resilience, awareness, culture, and measurement. They do not replace the ISC2 exam outline as the coverage checklist.

CertHappens is an independent study resource and is not affiliated with or endorsed by ISC2.

ISC2 CC September 2026 Study Guide Return to the five-domain roadmap and nineteen-objective study plan. Domain 1: Security Principles Review risk, governance concepts, control categories, ethics, due care, and due diligence. Domain 3: Identity And Access Management (IAM) Concepts Continue with identity lifecycle management, logical access controls, least privilege, separation of duties, and access-control models. Recovery Metrics Quick Review Compare recovery time, recovery point, repair, and failure measurements when continuity scenarios need more detail. Security+ or ISC2 CC Compare the certifications by starting point, breadth, and technical context.