Domain 5 accounts for 20 percent of the SY0-701 exam. It explains how an organization decides what security should accomplish, who owns each decision, how risk is tracked, and how requirements are proven to customers, regulators, auditors, and leadership.
The questions often begin with a technical problem but end with an organizational choice. A vulnerability may need a risk owner. A vendor may need contract language. A policy violation may require an exception process. Look for the person with authority, the document that sets expectations, and the evidence that shows the work occurred.
Domain 5 map
The official objectives divide Security Program Management and Oversight into six areas:
| Objective | Main focus | Questions to ask |
|---|---|---|
| 5.1 | Security governance | Which document, structure, or role sets direction and accountability? |
| 5.2 | Risk management | How is risk identified, analyzed, assigned, treated, and reported? |
| 5.3 | Third-party risk | What should be checked before selection, written into agreements, and monitored afterward? |
| 5.4 | Compliance and privacy | Which obligation applies, what evidence is required, and whose data or rights are involved? |
| 5.5 | Audits and assessments | Who is evaluating the environment, for what purpose, and with what level of independence? |
| 5.6 | Security awareness | What behavior should people recognize, report, and improve through training? |
A single scenario can touch several rows. A new cloud provider may require due diligence, a contract, privacy review, risk acceptance, employee guidance, and an independent assessment. Follow the decision path instead of assigning the entire scenario to one objective number.
Security governance
Governance translates business priorities and obligations into direction for the security program. Leadership establishes expectations, assigns authority, and reviews whether the program is producing acceptable results.
Policies, standards, procedures, and guidelines
These documents differ by purpose:
| Document | Purpose | Example |
|---|---|---|
| Policy | States management direction and required outcomes. | Company data must be classified and protected according to sensitivity. |
| Standard | Defines a mandatory, measurable requirement that supports policy. | Administrative accounts must use phishing-resistant multifactor authentication. |
| Procedure | Lists the steps for completing a task consistently. | Disable accounts, recover devices, transfer files, and record approval during offboarding. |
| Guideline | Provides recommended practices when judgment or flexibility is appropriate. | Prefer approved collaboration tools when sharing large internal files. |
A policy should remain broad enough to survive routine technology changes. Standards and procedures usually need more frequent revision because they contain specific controls, thresholds, tools, or steps.
Common policy subjects include acceptable use, information security, business continuity, disaster recovery, incident response, software development, and change management. Standards may define password, access-control, physical-security, and encryption requirements. Procedures cover repeatable work such as onboarding, offboarding, change approval, and incident playbooks.
External considerations
Governance must account for requirements beyond the organization. These may come from:
- Laws and regulations
- Contracts and customer commitments
- Industry standards
- Local or regional rules
- National requirements
- Global obligations that follow the organization, service, or data
The same activity can be subject to several requirements. A healthcare provider using an international cloud service may have contractual, sector, national, and cross-border obligations at the same time. The exam usually asks which source creates the requirement or which action best demonstrates compliance.
Monitoring and revision
Policies lose value when they no longer match the environment. Review can be triggered by:
- A scheduled review date
- A major incident
- A new law or contractual obligation
- A merger, acquisition, or organizational change
- New technology or a changed threat
- Audit findings
- Repeated exceptions or violations
Revision should include ownership, approval, version control, communication, and acknowledgement where appropriate. An updated document sitting quietly in a repository has not changed anyone's behavior.
Governance structures
Governance may be centralized, decentralized, or a mixture of both.
| Structure | Typical role | Consideration |
|---|---|---|
| Board | Provides oversight, approves risk direction, and holds leadership accountable. | Receives concise reporting focused on business exposure and decisions. |
| Committee | Coordinates stakeholders, reviews policy, risk, exceptions, or program performance. | Membership should match the decisions the committee is expected to make. |
| Government entity | Creates, enforces, or examines legal and regulatory requirements. | Authority depends on jurisdiction and subject matter. |
| Centralized model | Places policy and major decisions under one security function. | Promotes consistency but can become distant from local operational needs. |
| Decentralized model | Distributes authority among business units or locations. | Supports local decisions but requires coordination and common minimum requirements. |
Roles for systems and data
The exact titles vary among organizations and laws, but the responsibilities remain useful:
| Role | Primary responsibility |
|---|---|
| Owner | Accepts accountability, sets classification or access expectations, and approves major decisions for the system or data. |
| Controller | Determines why and how personal data is processed in a privacy context. |
| Processor | Processes personal data on behalf of a controller and within the agreed instructions. |
| Custodian | Implements and operates the technical or administrative protections selected by the owner. |
| Steward | Supports data quality, definitions, handling, and consistent use across a business area. |
Read the task in the scenario. The owner generally makes or approves the business decision. The custodian performs day-to-day protection. A controller selects the purpose and means of personal-data processing, while a processor acts for the controller.
Risk management
Risk management helps an organization make consistent decisions under uncertainty. The process usually includes identification, assessment, response, communication, and continued monitoring.
Risk identification and assessment timing
Risks can arise from threats, vulnerabilities, business dependencies, people, suppliers, facilities, technology, and changes in the operating environment.
Assessments may be:
- Ad hoc: initiated by an event, request, or unexpected concern
- One-time: completed for a specific decision or project
- Recurring: repeated on a schedule
- Continuous: updated as conditions and evidence change
The best timing depends on the decision. A yearly review may suit a stable process, while internet exposure, active exploitation, or a rapidly changing cloud environment may require continuous monitoring.
Qualitative and quantitative analysis
Qualitative analysis uses descriptive ratings such as low, moderate, and high. It works well when precise financial data is unavailable or the organization needs a fast, consistent ranking.
Quantitative analysis uses numbers to estimate frequency and loss. Common Security+ formulas are:
- Single loss expectancy (SLE) = asset value × exposure factor
- Annualized loss expectancy (ALE) = SLE × annualized rate of occurrence (ARO)
Example: A system valued at $200,000 could lose 25 percent of its value during one event. The SLE is $50,000. If the event is expected once every four years, the ARO is 0.25 and the ALE is $12,500.
Those numbers support comparison. They do not remove uncertainty. Asset value, probability, exposure, and impact estimates all depend on assumptions that should be documented.
| Term | Meaning |
|---|---|
| Probability | A numerical expression of how likely an event is to occur. |
| Likelihood | A judgment or rating describing the chance of occurrence. |
| Exposure factor | The percentage of asset value expected to be lost from one event. |
| Impact | The harm to operations, finances, safety, customers, reputation, obligations, or other objectives. |
| SLE | The estimated loss from one occurrence. |
| ARO | The expected number of occurrences during one year. |
| ALE | The estimated annual loss from the risk. |
Risk register and ownership
A risk register records the information needed to manage known risks. Common fields include:
- Description and affected assets or processes
- Threat, vulnerability, and potential impact
- Likelihood and severity
- Existing controls
- Planned response
- Risk owner
- Target dates and current status
- Residual risk after treatment
- Key risk indicators and thresholds
A risk owner has authority and accountability for the response. The security team may identify and explain a risk, but a business owner often decides whether to accept disruption, spend money, change a process, or stop an activity.
A key risk indicator (KRI) provides an early warning that exposure is changing. Examples include unpatched critical systems, excessive privileged accounts, failed backups, overdue vendor reviews, or rising phishing-report rates.
A risk threshold marks a point that triggers action or escalation. It might be a number of overdue critical findings, a maximum outage duration, or a financial exposure limit.
Appetite and tolerance
- Risk appetite describes the amount and type of risk an organization is willing to pursue or retain while meeting its objectives.
- Risk tolerance describes the acceptable variation around a specific objective or risk.
An expansionary appetite accepts more uncertainty in exchange for growth or opportunity. A conservative appetite favors protection and predictability. A neutral posture balances opportunity and exposure without leaning strongly in either direction.
Risk responses
| Response | Meaning | Example |
|---|---|---|
| Mitigate | Reduce likelihood, impact, or both through controls. | Add segmentation, stronger authentication, monitoring, and tested recovery. |
| Transfer | Shift part of the financial or operational consequence to another party. | Purchase insurance or use a contract that assigns defined responsibilities. |
| Avoid | Stop the activity that creates the risk. | Do not launch a service that cannot meet a required legal or safety condition. |
| Accept | Acknowledge the remaining risk and continue with authorized approval. | Keep a low-impact legacy dependency until its scheduled replacement. |
An exception authorizes a documented deviation from a requirement, often for a limited time and with compensating controls. An exemption releases a defined system, group, or situation from a requirement when the requirement does not apply or cannot reasonably be imposed. Both should have approval, scope, rationale, review, and expiration or reassessment conditions.
Risk reporting and business impact analysis
Reports should match the audience. Engineers may need affected systems and remediation detail. Executives need business exposure, trend, ownership, cost, and decisions requiring approval.
A business impact analysis identifies critical activities, dependencies, and the effects of disruption. Key measurements include:
| Measurement | Question it answers |
|---|---|
| RTO | How quickly must the service be restored after disruption? |
| RPO | How much data loss, measured in time, can the organization tolerate? |
| MTTR | How long does repair or recovery usually take? |
| MTBF | How long does the system usually operate between failures? |
RTO and RPO are objectives chosen by the organization. MTTR and MTBF are measurements based on performance and reliability history.
Third-party risk
Vendors, suppliers, managed service providers, contractors, cloud providers, and software dependencies can introduce access, availability, privacy, and supply-chain risk. Oversight continues after a contract is signed.
Assessment and selection
Vendor due diligence may review:
- Security questionnaires and supporting evidence
- Independent assessments or certifications
- Internal audit evidence
- Penetration-test summaries
- Architecture, data flows, and access requirements
- Incident history and response capability
- Business continuity and recovery arrangements
- Subcontractors and supply-chain dependencies
- Financial stability and staffing
- Data location, retention, return, and destruction
- Conflicts of interest
A right-to-audit clause preserves the customer's ability to inspect or obtain evidence under defined conditions. It does not replace normal monitoring. An annual report can become outdated after a major platform, ownership, or control change.
Agreement types
| Agreement | Typical purpose |
|---|---|
| SLA | Defines measurable service expectations such as uptime, response, recovery, support, and remedies. |
| MOA | Describes a formal agreement and responsibilities between parties working toward a shared objective. |
| MOU | Records mutual understanding and intended cooperation, often with less contractual detail. |
| MSA | Establishes the general legal and commercial terms governing an ongoing relationship. |
| SOW or work order | Defines the specific work, deliverables, schedule, scope, and acceptance criteria. |
| NDA | Restricts use and disclosure of confidential information. |
| BPA | Defines obligations between business partners, including information sharing and protection. |
The name offers a clue, but the scenario's purpose decides the answer. A service uptime target belongs in an SLA. Project deliverables belong in an SOW. Confidentiality obligations belong in an NDA.
Monitoring and rules of engagement
Ongoing vendor monitoring may track service performance, incidents, control changes, audit reports, insurance, financial condition, vulnerabilities, subcontractors, and compliance obligations.
Rules of engagement define the boundaries for testing or other sensitive activity. They may specify:
- Authorized systems and dates
- Allowed and prohibited methods
- Contacts and escalation paths
- Data-handling requirements
- Conditions for stopping the activity
- Reporting and evidence expectations
Clear scope protects both parties. A penetration tester with vague authorization can create an incident while trying to evaluate one.
Exit planning
Vendor risk also appears at termination. The organization may need to revoke access, recover assets, transfer data, verify deletion, preserve records, replace dependencies, and continue critical services. Exit requirements belong in planning and contracts before the relationship becomes difficult to unwind.
Compliance and privacy
Compliance work connects obligations to controls, evidence, monitoring, and reporting. Requirements may be legal, regulatory, contractual, industry-based, or internally adopted.
Reporting and consequences
Internal reporting supports leadership, governance committees, audit teams, risk owners, and operational management. External reporting may go to regulators, customers, partners, insurers, or independent assessors.
Consequences of non-compliance can include:
- Fines and sanctions
- Contract penalties or termination
- Loss of license or authorization
- Required remediation or increased oversight
- Reputational damage
- Operational restrictions
The correct response depends on the source of the obligation. A contract breach and a regulatory violation can involve different notice, evidence, and escalation paths even when the underlying control failed in the same way.
Due care and due diligence
Due care is the reasonable protection and action expected under the circumstances. Due diligence is the continuing effort to investigate, verify, and monitor whether those protections remain appropriate and effective.
Installing a required control can demonstrate care. Reviewing alerts, testing effectiveness, updating the control, and responding to findings demonstrate diligence over time.
Attestation and acknowledgement
An attestation is a formal assertion that specified conditions or controls are true. Acknowledgement records that a person received, read, or accepted an expectation such as a policy or code of conduct.
Neither should be treated as automatic proof of effective behavior. Evidence still needs suitable scope, timing, authority, and supporting detail.
Automated compliance monitoring
Automation can compare configurations against benchmarks, collect evidence, track exceptions, identify drift, and generate reports. It improves consistency and speed, but the organization still needs to validate data sources, tune rules, protect the monitoring system, and investigate results.
Privacy roles and data lifecycle
Privacy obligations vary by jurisdiction. For the exam, focus on the roles and management concepts rather than memorizing every law.
- A data subject is the person associated with personal data.
- A controller determines the purpose and means of processing.
- A processor handles data for the controller.
- Data ownership and stewardship establish organizational accountability.
- A data inventory records what personal data exists, where it resides, why it is used, who receives it, and how long it is retained.
- Retention schedules keep data for a defined business or legal period and support disposal afterward.
- A right to be forgotten or erasure request may require deletion when applicable requirements and exceptions allow it.
Data location matters because processing may cross local, regional, national, and global boundaries. Before moving data, identify the people involved, the purpose, the systems, the recipients, the retention period, and the legal or contractual conditions.
Audits and assessments
Audits and assessments examine security from different angles. The exam often distinguishes them by purpose, independence, and method.
| Activity | Primary purpose |
|---|---|
| Attestation | Provides a formal assertion about controls, conditions, or compliance. |
| Internal audit | Evaluates governance, controls, and compliance for the organization using an internal audit function. |
| Self-assessment | Allows a team or organization to compare its own practices with requirements or criteria. |
| External audit | Provides independent review for regulators, customers, certifications, or other stakeholders. |
| Regulatory examination | Uses the authority of a regulator or examiner to review compliance and risk. |
| Security assessment | Evaluates whether controls are present, suitable, and operating as intended. |
| Penetration test | Attempts to exploit weaknesses within an authorized scope to demonstrate attack paths and impact. |
An audit committee helps oversee independence, findings, remediation, and reporting. Independence matters because the team responsible for a control may have difficulty providing an objective evaluation of its own work.
Penetration-test approaches
Testing can be physical, offensive, defensive, or integrated. An integrated exercise combines attacker and defender activity to improve both detection and response.
Knowledge of the environment also varies:
| Approach | Tester knowledge | Useful for |
|---|---|---|
| Known environment | Detailed information, credentials, architecture, or source material is provided. | Deep coverage and efficient testing of specific controls or components. |
| Partially known environment | Some information or access is provided. | Balancing realistic discovery with targeted evaluation. |
| Unknown environment | Little or no internal information is provided. | Testing what an outside attacker could discover and reach. |
Passive reconnaissance gathers information without directly interacting with the target systems when possible. Active reconnaissance sends traffic or queries to learn about hosts, services, and defenses. Active methods are more visible and may create operational risk, which is why authorization and rules of engagement matter.
Security awareness
Awareness programs help people recognize risk, make safer decisions, and report concerns quickly. A yearly presentation alone cannot address new threats, role changes, remote work, and repeated risky behavior.
Phishing campaigns
A useful phishing program teaches people how to:
- Check the sender, destination, request, urgency, and surrounding context
- Avoid using links or phone numbers supplied in a suspicious message
- Verify unusual requests through a trusted channel
- Report the message through the approved process
- Preserve useful information for investigation
- Respond appropriately after clicking, replying, or entering credentials
Simulated campaigns can measure reporting, interaction, and improvement. Metrics should support learning rather than encourage employees to hide mistakes. Fast reporting after a click may reduce harm more than silence from someone worried about being blamed.
Anomalous behavior
People should recognize behavior that is:
- Risky: knowingly bypassing controls or taking unnecessary exposure
- Unexpected: activity that differs from normal role, location, timing, or process
- Unintentional: mistakes caused by misunderstanding, distraction, poor design, or missing guidance
An anomaly is a reason to verify, not an automatic verdict about intent. Reporting should give security teams enough information to investigate without encouraging rumors or retaliation.
User guidance and role-based training
Training should address the work people actually perform. Common subjects include:
- Policies and employee handbooks
- Password and authentication practices
- Social engineering
- Insider-threat indicators and reporting
- Removable media and cables
- Operational security
- Hybrid and remote work
- Data handling and privacy
- Secure development or administration for technical roles
- Incident and escalation responsibilities
General awareness gives everyone a baseline. Role-based training goes deeper for administrators, developers, executives, help-desk staff, finance teams, investigators, and others with distinct access or decisions.
Development, execution, and monitoring
A learning program should identify audiences, desired behavior, content, delivery methods, schedule, ownership, and measures of effectiveness.
Initial training establishes expectations for new personnel or new roles. Recurring training refreshes knowledge and addresses changed threats, policies, and tools. Additional training may follow an incident, audit finding, or pattern of risky behavior.
Useful measures include reporting rates, response time, repeated errors, completion, assessment results, help-desk trends, and incident data. A high completion rate proves attendance. Stronger decisions and earlier reporting show whether the material is working.
Common Domain 5 exam traps
Choosing the wrong governance document
Use the purpose. Management direction belongs in policy. Mandatory detail belongs in a standard. Ordered steps belong in a procedure. Recommended practice belongs in a guideline.
Assigning every security decision to the security team
Security staff advise, monitor, and operate controls. Owners and leadership often hold authority to accept business risk, fund remediation, or change an activity.
Confusing appetite, tolerance, and threshold
Appetite describes the broad willingness to pursue or retain risk. Tolerance defines acceptable variation for a specific objective. A threshold triggers action or escalation.
Treating transfer as removal
Insurance and contracts can shift part of the financial or operational consequence. The organization can still face outages, legal duties, customer harm, and reputation loss.
Using the agreement name without reading the need
An SLA sets service targets. An SOW defines specific work. An NDA protects confidential information. Select the document that solves the stated requirement.
Confusing an audit with a penetration test
An audit compares evidence with criteria. A penetration test attempts authorized exploitation. Both may find weaknesses, but they answer different questions.
Measuring awareness only by completion
Completion records show who attended. Reporting behavior, response quality, and incident trends provide stronger evidence of learning.
Domain 5 review checklist
Before finishing the domain, confirm that you can:
- Compare policies, standards, procedures, and guidelines.
- Match governance structures and data roles to their responsibilities.
- Explain why policies require monitoring, revision, approval, and communication.
- Distinguish qualitative and quantitative risk analysis.
- Calculate SLE and ALE from asset value, exposure factor, and ARO.
- Describe a risk register, risk owner, KRI, threshold, appetite, and tolerance.
- Compare mitigation, transfer, avoidance, acceptance, exceptions, and exemptions.
- Separate RTO, RPO, MTTR, and MTBF.
- Choose among SLA, MOA, MOU, MSA, SOW, NDA, and BPA.
- Explain vendor assessment, selection, monitoring, rules of engagement, and exit planning.
- Compare due care, due diligence, attestation, and acknowledgement.
- Identify data-subject, controller, processor, owner, custodian, and steward responsibilities.
- Compare internal audits, external audits, self-assessments, regulatory examinations, and penetration tests.
- Distinguish known, partially known, and unknown testing environments.
- Explain passive and active reconnaissance.
- Design awareness activities that support recognition, reporting, and improved behavior.
Use the randomized SY0-701 practice test to mix Domain 5 decisions with architecture, operations, and threat scenarios. Governance questions become easier when you identify the authority, requirement, evidence, and business effect before comparing the choices.
Official references
The domain scope and weighting are based on the published SY0-701 objectives. The supporting sources below provide primary guidance for governance, risk, supply-chain management, privacy, and learning programs:
- CompTIA Security+ certification page
- CompTIA Security+ SY0-701 exam objectives PDF
- NIST Cybersecurity Framework 2.0
- NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments
- NIST SP 800-161 Rev. 1: Cybersecurity Supply Chain Risk Management Practices
- NIST Privacy Framework
- NIST SP 800-50 Rev. 1: Building a Cybersecurity and Privacy Learning Program
- CISA: Recognize and Report Phishing