TB.

Security+ SY0-701 · Domain 5

Domain 5: Security Program Management & Oversight

Why This Domain Matters

Domain 5 is one-fifth of the final score and almost none of it is technical — it's vocabulary, frameworks, and business process, tested at the same density as everything else.

A policy is a policy regardless of who wrote it, and the exam expects the exact word CompTIA uses for each layer of governance, each risk term, each agreement type.

That makes this domain unusually well-suited to flashcards — it rewards raw recall more than any other domain, and it punishes "I sort of know what that means" harder, because half the difficulty on exam day is picking the right synonym out of four plausible-sounding options.

It's also the domain interviewers use to probe whether a candidate understands the business side of security, not just the technical side — "how would you explain risk appetite to a manager who wants to skip a control" is a Domain 5 question in disguise.

Target 85%+ here — it's entirely achievable through memorization, and the ROI on flashcard time is higher in this domain than anywhere else in the exam.

Objective-by-Objective Breakdown

5.1 Elements of Effective Security Governance

Governance hierarchy: broad intent narrows into specific, actionable steps

Governance documents form a hierarchy from vague to specific — guidelines, policies, standards, procedures — see Confusables for how to keep these straight under exam pressure.

Named policy types you must recognize by function:

  • an AUP: acceptable use policy
  • the umbrella information security policy
  • business continuity policy: keeping essential operations running through disruption — broader than IT
  • disaster recovery policy: restoring IT systems specifically after a disruption
  • incident response policy
  • SDLC policy: building security into development rather than bolting it on after
  • change management policy: controlling how changes are proposed, approved, and rolled back

Standards translate policy intent into specific, testable requirements for passwords, access control, physical security, and encryption (e.g., "12+ character minimum" is a password standard implementing the umbrella security policy).

Procedures cover change management, onboarding/offboarding, and playbooks (step-by-step guides for specific incident types). External considerations — regulatory, legal, industry, and geographic scope (local/regional, national, global) — constrain what a policy is even allowed to say.

Governance is never "set and forget": monitoring and revision checks that policies are still followed and still fit a changed threat or business environment.

Governance structures vary:

  • a board of directors: ultimate strategic authority
  • a dedicated committee: delegated oversight, e.g., a risk committee
  • a government entity: a public-sector body operating within a legislative/statutory framework rather than a corporate charter
  • the centralized-vs-decentralized question of whether one body sets policy for the whole organization or individual units set their own

A government agency, as a statutory authority, is a textbook example of the "government entity" governance structure the objective names directly — a useful mental anchor in place of a generic corporate board.

Roles and responsibilities for systems and data assign accountability:

  • owners: accountable for an asset's protection and classification — a business role, not IT
  • controllers: decide the purposes and means of processing data
  • processors: process data on a controller's behalf, per their instructions
  • custodians/stewards: day-to-day technical implementation — patching, backups, access provisioning — without owning the underlying business decision

See Confusables for the full role breakdown.

5.2 Risk Management

The loss-expectancy cascade: AV × EF = SLE, then SLE × ARO = ALE

Risk management starts with identification (finding what could go wrong) and moves into assessment, run on different cadences: ad hoc (unscheduled, event-triggered), recurring (regularly scheduled, e.g., annual), one-time (a single assessment for a specific project), and continuous (ongoing, near-real-time).

Analysis splits into qualitative (relative labels — low/medium/high, a red-amber-green heat map — fast and subjective) and quantitative, which assigns dollar figures and is the sub-block the exam loves to test with arithmetic.

Four terms build the formula: exposure factor (EF) — the percentage of an asset's value lost if the risk materializes once; single loss expectancy (SLE), calculated as SLE = AV × EF; annualized rate of occurrence (ARO) — expected occurrences per year (can be a fraction — once every four years is an ARO of 0.25); and annualized loss expectancy (ALE), calculated as ALE = SLE × ARO. Probability/likelihood are the qualitative cousins of ARO; impact is the qualitative cousin of EF/SLE. Worked example: the organization's regional file server is valued at AV = $40,000. A ransomware incident is assessed as likely to destroy or corrupt 50% of that value in downtime, recovery labor, and data loss before backups fully restore service — EF = 0.5. So SLE = $40,000 × 0.5 = $20,000 per incident.

History suggests an incident like this hits roughly once every four years — ARO = 0.25. So ALE = $20,000 × 0.25 = $5,000 per year — the figure that justifies (or fails to justify) the annual cost of a mitigating control.

A risk register tracks key risk indicators (KRIs — metrics giving early warning a risk is trending toward materializing), a named risk owner per entry, and a risk threshold (the point requiring escalation).

Risk tolerance is the organization's general capacity to absorb variation from an expected outcome; risk appetite is the more deliberate, strategic statement of how much risk it's willing to pursue — expansionary (embraces risk for growth), conservative (minimizes exposure), or neutral — see Confusables for how tolerance and appetite differ despite sounding synonymous.

Four strategies cover every response:

  • transfer: shift the financial consequence to a third party — the same logic as buying insurance: you can't eliminate the risk of an accident, but you can make someone else absorb the cost, exactly how cyber-insurance and outsourcing work at the organizational level
  • accept: retain the risk, formalized as an exemption — a permanent approved deviation — or an exception — a temporary, time-boxed one
  • avoid: eliminate the activity creating the exposure entirely
  • mitigate: reduce likelihood or impact via controls

Risk reporting communicates all of this upward in a form decision-makers can act on. A business impact analysis (BIA) quantifies the operational cost of downtime and drives four recovery metrics — RTO, RPO, MTTR, MTBF — see Confusables.

5.3 Third-Party Risk Assessment and Management

Vendor assessment tools include penetration testing results, a right-to-audit clause (a contractual term letting you inspect the vendor's security practices directly), evidence of internal audits (the vendor's own self-checks), independent assessments (a neutral third party's evaluation, carrying more weight than self-reporting), and supply chain analysis (risk introduced by the vendor's own upstream suppliers, not just the vendor itself).

Vendor selection rests on due diligence (thoroughly investigating a vendor before signing) and screening for conflict of interest.

Once selected, the relationship is governed by a range of agreement types — SLA, MOU, MOA, MSA, SOW/WO, NDA, BPA — each with different formality and legal weight; see Confusables, since the exam frequently gives a scenario and asks which single type fits it.

Vendor monitoring doesn't stop at signing — ongoing questionnaires (structured, repeatable security self-assessments sent periodically) keep the risk picture current. Rules of engagement define the agreed boundaries, scope, and methods before any vendor-facing security testing begins.

5.4 Security Compliance

Compliance reporting can be internal (to leadership, a board, or an audit committee) or external (to a regulator, customer, or certifying body).

Non-compliance carries real consequences:

  • fines
  • sanctions
  • reputational damage
  • loss of license
  • contractual impacts: breach clauses, lost business, terminated agreements

Compliance monitoring covers due diligence (the reasonable investigation done before an action or relationship — a point-in-time check) and, related but distinct, due care (the ongoing standard of reasonable caution maintained afterward) — plus attestation (a formal, often executive-level declaration that requirements are met) and acknowledgement (an individual's sign-off that they've read and agree to a policy, e.g., an AUP), split across internal/external monitoring and increasingly delivered through automation (continuous, tool-driven checking rather than a manual annual review).

Privacy folds in the legal dimension: legal implications vary by scope (local/regional, national, global — the same jurisdictional ladder as 5.1's external considerations, applied to data protection law). A data subject is the individual a piece of personal data is about.

A controller decides why and how data is processed; a processor processes it on the controller's behalf, per the controller's instructions — a distinction the exam tests relentlessly because the two roles carry different legal accountability even when handling identical data.

Ownership assigns accountability for a dataset. A data inventory catalogs what personal data exists and where; retention defines how long it can or must be kept, balancing legal obligation against minimization principles.

The right to be forgotten is a data subject's right to request deletion of their personal data, subject to legal exceptions (e.g., a case file under an active legal hold couldn't simply be deleted on request) — directly relevant to any organization, like a legal aid commission, holding case-related personal data under its own retention obligations.

5.5 Audits and Assessments

Attestation (a formal statement that a control or requirement has been verified) underlies both audit categories.

Internal audits include compliance audits (adherence to internal policy), an audit committee (a governance body, often board-level, overseeing audit activity), and self-assessments (the organization checking its own posture, no outside party).

External audits include regulatory audits (mandated by a regulator), examinations (a formal regulatory review), assessments (a broader external evaluation), and independent third-party audits (a neutral outside firm, carrying the most credibility precisely because it isn't the organization checking its own work).

Penetration testing is tested along two dimensions.

By posture:

  • physical: badge readers, locks, tailgating resistance
  • offensive: red team — simulating an attacker
  • defensive: blue team — testing detection and response
  • integrated: purple team — red and blue collaborating in real time rather than working in isolation

By information given to the tester beforehand:

  • known environment: full information in advance — diagrams, source code, credentials; formerly white box
  • partially known environment: some information; formerly gray box
  • unknown environment (none, simulating a real external attacker from zero; formerly black box) — see Confusables

Reconnaissance splits into passive (gathering information without touching the target — public records, OSINT, WHOIS) and active (directly interacting with the target — port scanning, banner grabbing — carrying a real detection risk passive recon doesn't).

5.6 Security Awareness Practices

Phishing defense runs as an ongoing campaign, not a one-time event: simulated phishing sent to staff, training them to recognize a real attempt (mismatched sender domains, urgency, unexpected attachments/links, requests bypassing normal process), and a defined workflow for responding to reported suspicious messages (a user reports it, the SOC investigates, confirmed threats get blocked and fed back into detection rules).

Anomalous behavior recognition trains staff to notice three categories:

  • risky: against policy but not malicious, e.g., a personal USB drive
  • unexpected: a deviation from someone's normal pattern worth a second look
  • unintentional: accidental human error, like a misdirected email

User guidance and training covers policy/handbook awareness, situational awareness, insider threat awareness (the threat can come from inside, not only outside), password management, safe handling of removable media and cables (an unknown USB drive or malicious charging cable are real delivery vectors, not just an old warning), social engineering resistance, operational security (OPSEC — not letting small, individually-harmless details add up to something an adversary can exploit), and hybrid/remote work considerations (home network security, public Wi-Fi exposure, physical device security outside a controlled office).

Reporting and monitoring runs on two cadences — initial (onboarding, before touching production systems) and recurring (ongoing refreshers and repeat simulations, since awareness decays without reinforcement) — and the program has a development phase (designing content/cadence) and an execution phase (delivering it), treated as distinct lifecycle steps.

Confusables — Don't Mix These Up

Policy vs. Standard vs. Procedure vs. Guideline

TermMandatory?Level of detailExam tell
PolicyYesHigh-level statement of intent"Defines what the organization requires and why"
StandardYesSpecific, measurable requirement implementing a policy"Passwords must be a minimum of 12 characters"
ProcedureYesStep-by-step instructions for one task"Step 1: verify identity. Step 2: disable the account…"
GuidelineNo — recommendedBest-practice advice, flexible"Consider using a passphrase"

Risk Tolerance vs. Risk Appetite

TermWhat it describesNatureExam tell
Risk toleranceHow much deviation from an expected outcome the organization can absorbOften narrower, operational/tactical"The acceptable variance before a risk requires escalation"
Risk appetiteHow much risk the organization is strategically willing to pursue in the first place, categorized as expansionary/conservative/neutralBroader, strategic, often board-set"Leadership decided the organization would pursue an expansionary posture toward new market risk"

SLE vs. ALE vs. ARO (+ Exposure Factor)

TermWhat it isFormulaUnits
Exposure factor (EF)% of asset value lost in one occurrenceInput valuePercentage
SLECost of a single occurrenceAV × EFDollars
AROExpected occurrences per yearInput value (can be < 1)Times/year
ALEExpected cost per yearSLE × ARODollars/year

RTO vs. RPO vs. MTTR vs. MTBF

TermQuestion it answersType of metric
RTOHow long can this system be down before it's unacceptable?Recovery target (time)
RPOHow much data can we afford to lose, measured backward in time?Recovery target (data loss window)
MTTRHow long does it actually take, on average, to repair this?Observed/actual repair performance
MTBFHow long does this component run, on average, before it fails?Reliability (not a recovery metric at all)

SLA vs. MOU vs. MOA vs. MSA vs. SOW vs. NDA vs. BPA

TermPurposeBinding?Exam tell
SLADefines measurable performance commitments (uptime, response time)Yes"99.9% uptime guaranteed, with penalties for breach"
MOUStates mutual understanding/intent between partiesTypically no"Both parties agree in principle to cooperate on…"
MOAStates specific agreed obligations/responsibilities between partiesOften yes, more detailed than an MOU"Each party will provide X by Y date"
MSASets baseline terms governing all future work between the partiesYes"Governs all future statements of work under this master contract"
SOW / WODefines scope, deliverables, timeline, and cost for one specific engagementYes"This engagement covers a 6-week assessment for $X"
NDAProtects confidential information shared between partiesYes"Neither party will disclose the other's proprietary information"
BPADefines the structure of a business partnership (responsibilities, profit share)Yes"Partners will split revenue according to…"

Data Owner vs. Controller vs. Processor vs. Custodian/Steward

RoleAccountable forExam tell
OwnerThe asset/dataset's classification and overall protection (business role)"Approves who is allowed to access this dataset"
ControllerDeciding the purpose and means of processing personal data"Determined why and how the data would be collected and used"
ProcessorProcessing data on the controller's behalf, per their instructions"A vendor stores and processes the data exactly as instructed by the organization that collected it"
Custodian/StewardDay-to-day technical implementation — backups, patching, access provisioning"Performs the daily backup and access-review tasks for the dataset"

Known vs. Partially Known vs. Unknown Pen Test Environments

TermInformation given to testerOld nameExam tell
Known environmentFull — network diagrams, source code, credentialsWhite box"The tester was given complete architecture documentation in advance"
Partially known environmentSome — limited documentation or partial accessGray box"The tester was given user-level credentials but no internal diagrams"
Unknown environmentNone — starts from zero, like a real external attackerBlack box"The tester had no prior information about the target"

Exam Traps

  • The exam loves ALE math questions — expect at least one scenario requiring you to compute SLE, then ALE, from given AV/EF/ARO figures. The most common trap answers are the SLE value alone (forgetting to multiply by ARO) and AV × ARO (skipping EF entirely, as if the whole asset were lost every time).
  • Controller vs. processor trips everyone — the controller decides why and how data is processed; the processor only processes it on the controller's instructions. A vendor storing data exactly as told is a processor, even if they physically hold all of it.
  • Right to be forgotten is not absolute — it's subject to legal exceptions (litigation holds, statutory retention requirements). A stem describing data that legally cannot be deleted on request hasn't disproven the concept — it's describing the exception, not an exam contradiction.
  • Risk tolerance and risk appetite are not synonyms — appetite is the strategic "how much are we willing to pursue," set top-down; tolerance is the narrower "how much variance can we absorb" before escalation kicks in.
  • Due diligence happens before; due care continues after — due diligence is the investigation done before entering a relationship or taking an action; due care is the ongoing reasonable standard maintained afterward. A stem about vetting a new vendor is due diligence; a stem about maintaining safeguards on an existing system is due care.
  • MOU and MOA are the closest pair on the exam and the easiest to swap — an MOU states mutual intent without binding obligations; an MOA specifies actual agreed responsibilities and is more likely to carry legal weight. If the stem names specific deliverables each party owes the other, lean MOA over MOU.
  • Known/partially known/unknown replaced white/gray/black box on SY0-701 — both naming conventions describe the same three tiers of information given to a tester in advance; expect either name in a stem.
  • Business continuity and disaster recovery are related but not identical — business continuity is the broader umbrella (keeping the business running, including non-IT functions); disaster recovery is specifically about restoring IT systems after a disruption. A DR plan is typically one component that supports the larger BC plan.
  • MTBF is not a recovery metric — it measures how long a component runs before failing (reliability), while RTO/RPO/MTTR all describe recovery targets or performance after failure has already occurred. A stem about "expected operating life before failure" is MTBF, not MTTR.

Acronym Table

AcronymExpansionOne-line meaning
AUPAcceptable Use PolicyDefines permitted use of organizational systems
SDLCSoftware Development Life CycleFramework for building security into software development from the start
BCPBusiness Continuity PlanKeeps essential business functions running through disruption
DRPDisaster Recovery PlanRestores IT systems and data after a disruption
KRIKey Risk IndicatorMetric giving early warning a risk is trending toward materializing
SLESingle Loss ExpectancyDollar cost of one occurrence of a risk (AV × EF)
ALEAnnualized Loss ExpectancyExpected dollar cost per year (SLE × ARO)
AROAnnualized Rate of OccurrenceExpected number of occurrences per year
EFExposure FactorPercentage of asset value lost in one occurrence
BIABusiness Impact AnalysisQuantifies operational cost of downtime, drives RTO/RPO
RTORecovery Time ObjectiveMaximum acceptable time to restore a system
RPORecovery Point ObjectiveMaximum acceptable data loss, measured backward in time
MTTRMean Time To RepairAverage actual time taken to repair a failed component
MTBFMean Time Between FailuresAverage time a component operates before failing
SLAService Level AgreementBinding, measurable performance commitment
MOUMemorandum of UnderstandingNon-binding statement of mutual intent
MOAMemorandum of AgreementFormal agreement specifying agreed obligations
MSAMaster Service AgreementBaseline contract terms governing future work orders/SOWs
SOWStatement of WorkDefines scope, deliverables, timeline, cost for one engagement
WOWork OrderAuthorizes specific work, often under an MSA, alternative to SOW
NDANon-Disclosure AgreementProtects confidential information shared between parties
BPABusiness Partners AgreementDefines structure/responsibilities of a business partnership

Drills: 20 flashcards + 10 exam-realistic questions, at the end of this page.

Interactive drills

Flashcards

Click a card to flip it, then rate how well you knew it — cards you rate lower come back sooner. 20 cards from real study drills, scheduled with spaced repetition.

Due today: 20

Flipped: 0/20

Quiz

10 exam-style questions, easy to hard. Pick an option to see whether you're right, and why.

Score: 0/10

Q1Easythe organization's security team publishes a mandatory requirement stating all workstation passwords must be at least 14 characters with complexity enabled. Which type of governance document is this?

Q2EasyIn quantitative risk analysis, which term specifically represents the percentage of an asset's value that would be lost if a given risk event occurred one time?

Q3EasyA cloud vendor stores and processes the organization's case file backups strictly according to the organization's written instructions and does not decide why or how the data is used beyond that. Under SY0-701 privacy terminology, what is the vendor acting as?

Q4Mediumthe organization's executive leadership formally states in a written risk statement that they will pursue new digital service initiatives even if it means accepting a higher level of security risk than in past years, provided it drives faster service delivery. Which risk concept does this statement represent, and what type would it be categorized as?

Q5MediumTwo government agencies draft a document stating they intend to collaborate on a future joint cybersecurity information-sharing initiative. The document expresses mutual goodwill and shared intent but does not obligate either party to specific deliverables or create a legally binding commitment. What type of agreement is this?

Q6MediumBefore signing a contract with a new cloud backup vendor, the organization's IT team reviews the vendor's independent security audit reports, checks references, and verifies their compliance certifications. Which compliance monitoring concept does this pre-contract investigation represent?

Q7MediumA penetration tester is given a standard user account and the general subnet range of the target environment, but is not provided network diagrams, source code, or administrative credentials. Which type of test environment is this?

Q8MediumA former legal aid client requests that the organization delete all personal data related to a case that is currently subject to an active legal hold due to ongoing litigation. Can the organization comply immediately using the right to be forgotten?

Q9Hard, PBQ — quantitative risk calculationthe organization assesses risk to its case-management database server, valued at AV = $200,000. A ransomware event is estimated to compromise 30% of that value in recovery costs and data loss (EF = 0.30). Based on incident history across similar government agencies, an event of this type is expected once every two years (ARO = 0.5). What is the annualized loss expectancy (ALE)?

Q10Hard, PBQ — matching agreement types to scenariosFor each statement, identify which agreement type it describes: