Practice Exams:

Governance & Compliance

IAPP AIGP: AI Governance Roles and Accountability

AI governance fails when responsibility is distributed so widely that nobody can explain who is accountable for a decision. Modern AI systems cross product, engineering, data, security, privacy, legal, procurement, risk, audit, and business operations. Each function owns part of the problem, but the organization still needs clear decision rights for approval, deployment, monitoring, incidents, exceptions, and retirement. The current AIGP body of knowledge treats AI governance as an organizational capability that spans expectations, policies, development, deployment, risk management, and lifecycle oversight. That framing is important: governance is not a…

Read More

ISC2 CISSP: Software Supply Chain Risk for CISSPs

This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on terminology, responsibilities, tradeoffs, governance, and review questions.Use it as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.

Read More

ISC2 CISSP: Security Models Beyond Memorization

Security models matter when they help engineers and leaders reason about what information is allowed to flow, which subject may act on which object, and what property the system is trying to preserve. Memorizing labels such as Bell-LaPadula or Biba without understanding the problem each model addresses misses their practical value. The models are abstractions that make security assumptions explicit. The current CISSP exam outline includes fundamental security models in Security Architecture and Engineering, alongside secure design principles and system security requirements. Within Security Governance & Assurance, the useful question…

Read More

ISC2 CISSP: Security Leadership Across Eight Domains

This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on terminology, responsibilities, tradeoffs, governance, and review questions.Use it as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.

Read More

ISC2 CISSP: Privacy Engineering for Security Leaders

Privacy engineering for security leaders turns privacy requirements into technical and operational decisions that can be implemented, tested, and monitored. Privacy and security overlap, but they are not identical. A system can be well protected from attackers and still collect too much data, retain it too long, use it for an unexpected purpose, or make it difficult to honor an individual’s rights. The current CISSP exam outline includes privacy-related legal and regulatory issues, data lifecycle, data roles, privacy by design, and security controls. Within Security Governance & Assurance, privacy engineering…

Read More

ISC2 CISSP: Physical Security in Hybrid Workplaces

This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on terminology, responsibilities, tradeoffs, governance, and review questions.Use it as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.

Read More

ISC2 CISSP: Cryptographic Key Management at Scale

This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on terminology, responsibilities, tradeoffs, governance, and review questions.Use it as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.

Read More

ISC2 CISSP: Business Continuity Without Paper Plans

This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on terminology, responsibilities, tradeoffs, governance, and review questions.Use it as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.

Read More

ISACA AAISM: Governing AI Security Risk

Governing AI security risk means deciding which AI-related exposures matter to the enterprise, how much risk the organization is willing to accept, which controls are proportionate, and who has authority to make those decisions. It is broader than securing a model. The risk can come from data, identity, providers, human use, autonomy, business process design, regulatory obligations, or concentration on a small number of external platforms. The topic is the risk-management core of Enterprise AI Governance. In the current AAISM exam outline, AI risk management covers assessment, thresholds, treatment, threats,…

Read More

ISACA AAISM: Controls for Enterprise AI Systems

Controls for enterprise AI systems should protect the entire application path, not only the model endpoint. A production AI service combines identity, data, prompts, retrieval, model providers, tools, memory, APIs, deployment pipelines, monitoring, and human decisions. Each layer can introduce risk, and a safeguard in one layer cannot compensate for every weakness in another. The control model belongs inside Enterprise AI Governance and maps directly to the current AAISM exam emphasis on AI security architecture, lifecycle controls, data management, privacy, trust and safety, monitoring, and risk-based human oversight. The practical…

Read More

ISACA AAISM: AI Model Risk for Security Leaders

This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on understanding terminology, responsibilities, tradeoffs, and review questions.Use the article as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.

Read More

ISACA AAISM: AI Incident Response Governance

AI incident response governance defines how an organization makes accountable decisions when an artificial-intelligence system creates, amplifies, or participates in a security incident. The technical response may involve disabling an endpoint or revoking a credential, but governance determines who can take that action, which evidence must be preserved, when customers or regulators are notified, how business continuity is protected, and what must be proven before the system returns to service. The topic sits naturally inside Enterprise AI Governance. ISACA’s current AAISM exam outline explicitly includes AI-specific incident investigation, documentation, reporting,…

Read More

ISACA CISM: Security Governance That Drives Decisions

This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on understanding terminology, responsibilities, tradeoffs, and review questions.Use the article as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.

Read More

ISACA CISM: Risk Appetite and Security Priorities

This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on understanding terminology, responsibilities, tradeoffs, and review questions.Use the article as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.

Read More

ISACA CISM: Measuring Security Program Performance

This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on understanding terminology, responsibilities, tradeoffs, and review questions.Use the article as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.

Read More