Security+ SY0-701 · Domain 5
Domain 5: Security Program Management & Oversight
Why This Domain Matters
Domain 5 is one-fifth of the final score and almost none of it is technical — it's vocabulary, frameworks, and business process, tested at the same density as everything else.
A policy is a policy regardless of who wrote it, and the exam expects the exact word CompTIA uses for each layer of governance, each risk term, each agreement type.
That makes this domain unusually well-suited to flashcards — it rewards raw recall more than any other domain, and it punishes "I sort of know what that means" harder, because half the difficulty on exam day is picking the right synonym out of four plausible-sounding options.
It's also the domain interviewers use to probe whether a candidate understands the business side of security, not just the technical side — "how would you explain risk appetite to a manager who wants to skip a control" is a Domain 5 question in disguise.
Target 85%+ here — it's entirely achievable through memorization, and the ROI on flashcard time is higher in this domain than anywhere else in the exam.
Objective-by-Objective Breakdown
5.1 Elements of Effective Security Governance
Governance hierarchy: broad intent narrows into specific, actionable steps
Governance documents form a hierarchy from vague to specific — guidelines, policies, standards, procedures — see Confusables for how to keep these straight under exam pressure.
Named policy types you must recognize by function:
- an AUP: acceptable use policy
- the umbrella information security policy
- business continuity policy: keeping essential operations running through disruption — broader than IT
- disaster recovery policy: restoring IT systems specifically after a disruption
- incident response policy
- SDLC policy: building security into development rather than bolting it on after
- change management policy: controlling how changes are proposed, approved, and rolled back
Standards translate policy intent into specific, testable requirements for passwords, access control, physical security, and encryption (e.g., "12+ character minimum" is a password standard implementing the umbrella security policy).
Procedures cover change management, onboarding/offboarding, and playbooks (step-by-step guides for specific incident types). External considerations — regulatory, legal, industry, and geographic scope (local/regional, national, global) — constrain what a policy is even allowed to say.
Governance is never "set and forget": monitoring and revision checks that policies are still followed and still fit a changed threat or business environment.
Governance structures vary:
- a board of directors: ultimate strategic authority
- a dedicated committee: delegated oversight, e.g., a risk committee
- a government entity: a public-sector body operating within a legislative/statutory framework rather than a corporate charter
- the centralized-vs-decentralized question of whether one body sets policy for the whole organization or individual units set their own
A government agency, as a statutory authority, is a textbook example of the "government entity" governance structure the objective names directly — a useful mental anchor in place of a generic corporate board.
Roles and responsibilities for systems and data assign accountability:
- owners: accountable for an asset's protection and classification — a business role, not IT
- controllers: decide the purposes and means of processing data
- processors: process data on a controller's behalf, per their instructions
- custodians/stewards: day-to-day technical implementation — patching, backups, access provisioning — without owning the underlying business decision
See Confusables for the full role breakdown.
5.2 Risk Management
The loss-expectancy cascade: AV × EF = SLE, then SLE × ARO = ALE
Risk management starts with identification (finding what could go wrong) and moves into assessment, run on different cadences: ad hoc (unscheduled, event-triggered), recurring (regularly scheduled, e.g., annual), one-time (a single assessment for a specific project), and continuous (ongoing, near-real-time).
Analysis splits into qualitative (relative labels — low/medium/high, a red-amber-green heat map — fast and subjective) and quantitative, which assigns dollar figures and is the sub-block the exam loves to test with arithmetic.
Four terms build the formula: exposure factor (EF) — the percentage of an asset's value lost if the risk materializes once; single loss expectancy (SLE), calculated as SLE = AV × EF; annualized rate of occurrence (ARO) — expected occurrences per year (can be a fraction — once every four years is an ARO of 0.25); and annualized loss expectancy (ALE), calculated as ALE = SLE × ARO. Probability/likelihood are the qualitative cousins of ARO; impact is the qualitative cousin of EF/SLE. Worked example: the organization's regional file server is valued at AV = $40,000. A ransomware incident is assessed as likely to destroy or corrupt 50% of that value in downtime, recovery labor, and data loss before backups fully restore service — EF = 0.5. So SLE = $40,000 × 0.5 = $20,000 per incident.
History suggests an incident like this hits roughly once every four years — ARO = 0.25. So ALE = $20,000 × 0.25 = $5,000 per year — the figure that justifies (or fails to justify) the annual cost of a mitigating control.
A risk register tracks key risk indicators (KRIs — metrics giving early warning a risk is trending toward materializing), a named risk owner per entry, and a risk threshold (the point requiring escalation).
Risk tolerance is the organization's general capacity to absorb variation from an expected outcome; risk appetite is the more deliberate, strategic statement of how much risk it's willing to pursue — expansionary (embraces risk for growth), conservative (minimizes exposure), or neutral — see Confusables for how tolerance and appetite differ despite sounding synonymous.
Four strategies cover every response:
- transfer: shift the financial consequence to a third party — the same logic as buying insurance: you can't eliminate the risk of an accident, but you can make someone else absorb the cost, exactly how cyber-insurance and outsourcing work at the organizational level
- accept: retain the risk, formalized as an exemption — a permanent approved deviation — or an exception — a temporary, time-boxed one
- avoid: eliminate the activity creating the exposure entirely
- mitigate: reduce likelihood or impact via controls
Risk reporting communicates all of this upward in a form decision-makers can act on. A business impact analysis (BIA) quantifies the operational cost of downtime and drives four recovery metrics — RTO, RPO, MTTR, MTBF — see Confusables.
5.3 Third-Party Risk Assessment and Management
Vendor assessment tools include penetration testing results, a right-to-audit clause (a contractual term letting you inspect the vendor's security practices directly), evidence of internal audits (the vendor's own self-checks), independent assessments (a neutral third party's evaluation, carrying more weight than self-reporting), and supply chain analysis (risk introduced by the vendor's own upstream suppliers, not just the vendor itself).
Vendor selection rests on due diligence (thoroughly investigating a vendor before signing) and screening for conflict of interest.
Once selected, the relationship is governed by a range of agreement types — SLA, MOU, MOA, MSA, SOW/WO, NDA, BPA — each with different formality and legal weight; see Confusables, since the exam frequently gives a scenario and asks which single type fits it.
Vendor monitoring doesn't stop at signing — ongoing questionnaires (structured, repeatable security self-assessments sent periodically) keep the risk picture current. Rules of engagement define the agreed boundaries, scope, and methods before any vendor-facing security testing begins.
5.4 Security Compliance
Compliance reporting can be internal (to leadership, a board, or an audit committee) or external (to a regulator, customer, or certifying body).
Non-compliance carries real consequences:
- fines
- sanctions
- reputational damage
- loss of license
- contractual impacts: breach clauses, lost business, terminated agreements
Compliance monitoring covers due diligence (the reasonable investigation done before an action or relationship — a point-in-time check) and, related but distinct, due care (the ongoing standard of reasonable caution maintained afterward) — plus attestation (a formal, often executive-level declaration that requirements are met) and acknowledgement (an individual's sign-off that they've read and agree to a policy, e.g., an AUP), split across internal/external monitoring and increasingly delivered through automation (continuous, tool-driven checking rather than a manual annual review).
Privacy folds in the legal dimension: legal implications vary by scope (local/regional, national, global — the same jurisdictional ladder as 5.1's external considerations, applied to data protection law). A data subject is the individual a piece of personal data is about.
A controller decides why and how data is processed; a processor processes it on the controller's behalf, per the controller's instructions — a distinction the exam tests relentlessly because the two roles carry different legal accountability even when handling identical data.
Ownership assigns accountability for a dataset. A data inventory catalogs what personal data exists and where; retention defines how long it can or must be kept, balancing legal obligation against minimization principles.
The right to be forgotten is a data subject's right to request deletion of their personal data, subject to legal exceptions (e.g., a case file under an active legal hold couldn't simply be deleted on request) — directly relevant to any organization, like a legal aid commission, holding case-related personal data under its own retention obligations.
5.5 Audits and Assessments
Attestation (a formal statement that a control or requirement has been verified) underlies both audit categories.
Internal audits include compliance audits (adherence to internal policy), an audit committee (a governance body, often board-level, overseeing audit activity), and self-assessments (the organization checking its own posture, no outside party).
External audits include regulatory audits (mandated by a regulator), examinations (a formal regulatory review), assessments (a broader external evaluation), and independent third-party audits (a neutral outside firm, carrying the most credibility precisely because it isn't the organization checking its own work).
Penetration testing is tested along two dimensions.
By posture:
- physical: badge readers, locks, tailgating resistance
- offensive: red team — simulating an attacker
- defensive: blue team — testing detection and response
- integrated: purple team — red and blue collaborating in real time rather than working in isolation
By information given to the tester beforehand:
- known environment: full information in advance — diagrams, source code, credentials; formerly white box
- partially known environment: some information; formerly gray box
- unknown environment (none, simulating a real external attacker from zero; formerly black box) — see Confusables
Reconnaissance splits into passive (gathering information without touching the target — public records, OSINT, WHOIS) and active (directly interacting with the target — port scanning, banner grabbing — carrying a real detection risk passive recon doesn't).
5.6 Security Awareness Practices
Phishing defense runs as an ongoing campaign, not a one-time event: simulated phishing sent to staff, training them to recognize a real attempt (mismatched sender domains, urgency, unexpected attachments/links, requests bypassing normal process), and a defined workflow for responding to reported suspicious messages (a user reports it, the SOC investigates, confirmed threats get blocked and fed back into detection rules).
Anomalous behavior recognition trains staff to notice three categories:
- risky: against policy but not malicious, e.g., a personal USB drive
- unexpected: a deviation from someone's normal pattern worth a second look
- unintentional: accidental human error, like a misdirected email
User guidance and training covers policy/handbook awareness, situational awareness, insider threat awareness (the threat can come from inside, not only outside), password management, safe handling of removable media and cables (an unknown USB drive or malicious charging cable are real delivery vectors, not just an old warning), social engineering resistance, operational security (OPSEC — not letting small, individually-harmless details add up to something an adversary can exploit), and hybrid/remote work considerations (home network security, public Wi-Fi exposure, physical device security outside a controlled office).
Reporting and monitoring runs on two cadences — initial (onboarding, before touching production systems) and recurring (ongoing refreshers and repeat simulations, since awareness decays without reinforcement) — and the program has a development phase (designing content/cadence) and an execution phase (delivering it), treated as distinct lifecycle steps.
Confusables — Don't Mix These Up
Policy vs. Standard vs. Procedure vs. Guideline
| Term | Mandatory? | Level of detail | Exam tell |
|---|---|---|---|
| Policy | Yes | High-level statement of intent | "Defines what the organization requires and why" |
| Standard | Yes | Specific, measurable requirement implementing a policy | "Passwords must be a minimum of 12 characters" |
| Procedure | Yes | Step-by-step instructions for one task | "Step 1: verify identity. Step 2: disable the account…" |
| Guideline | No — recommended | Best-practice advice, flexible | "Consider using a passphrase" |
Risk Tolerance vs. Risk Appetite
| Term | What it describes | Nature | Exam tell |
|---|---|---|---|
| Risk tolerance | How much deviation from an expected outcome the organization can absorb | Often narrower, operational/tactical | "The acceptable variance before a risk requires escalation" |
| Risk appetite | How much risk the organization is strategically willing to pursue in the first place, categorized as expansionary/conservative/neutral | Broader, strategic, often board-set | "Leadership decided the organization would pursue an expansionary posture toward new market risk" |
SLE vs. ALE vs. ARO (+ Exposure Factor)
| Term | What it is | Formula | Units |
|---|---|---|---|
| Exposure factor (EF) | % of asset value lost in one occurrence | Input value | Percentage |
| SLE | Cost of a single occurrence | AV × EF | Dollars |
| ARO | Expected occurrences per year | Input value (can be < 1) | Times/year |
| ALE | Expected cost per year | SLE × ARO | Dollars/year |
RTO vs. RPO vs. MTTR vs. MTBF
| Term | Question it answers | Type of metric |
|---|---|---|
| RTO | How long can this system be down before it's unacceptable? | Recovery target (time) |
| RPO | How much data can we afford to lose, measured backward in time? | Recovery target (data loss window) |
| MTTR | How long does it actually take, on average, to repair this? | Observed/actual repair performance |
| MTBF | How long does this component run, on average, before it fails? | Reliability (not a recovery metric at all) |
SLA vs. MOU vs. MOA vs. MSA vs. SOW vs. NDA vs. BPA
| Term | Purpose | Binding? | Exam tell |
|---|---|---|---|
| SLA | Defines measurable performance commitments (uptime, response time) | Yes | "99.9% uptime guaranteed, with penalties for breach" |
| MOU | States mutual understanding/intent between parties | Typically no | "Both parties agree in principle to cooperate on…" |
| MOA | States specific agreed obligations/responsibilities between parties | Often yes, more detailed than an MOU | "Each party will provide X by Y date" |
| MSA | Sets baseline terms governing all future work between the parties | Yes | "Governs all future statements of work under this master contract" |
| SOW / WO | Defines scope, deliverables, timeline, and cost for one specific engagement | Yes | "This engagement covers a 6-week assessment for $X" |
| NDA | Protects confidential information shared between parties | Yes | "Neither party will disclose the other's proprietary information" |
| BPA | Defines the structure of a business partnership (responsibilities, profit share) | Yes | "Partners will split revenue according to…" |
Data Owner vs. Controller vs. Processor vs. Custodian/Steward
| Role | Accountable for | Exam tell |
|---|---|---|
| Owner | The asset/dataset's classification and overall protection (business role) | "Approves who is allowed to access this dataset" |
| Controller | Deciding the purpose and means of processing personal data | "Determined why and how the data would be collected and used" |
| Processor | Processing data on the controller's behalf, per their instructions | "A vendor stores and processes the data exactly as instructed by the organization that collected it" |
| Custodian/Steward | Day-to-day technical implementation — backups, patching, access provisioning | "Performs the daily backup and access-review tasks for the dataset" |
Known vs. Partially Known vs. Unknown Pen Test Environments
| Term | Information given to tester | Old name | Exam tell |
|---|---|---|---|
| Known environment | Full — network diagrams, source code, credentials | White box | "The tester was given complete architecture documentation in advance" |
| Partially known environment | Some — limited documentation or partial access | Gray box | "The tester was given user-level credentials but no internal diagrams" |
| Unknown environment | None — starts from zero, like a real external attacker | Black box | "The tester had no prior information about the target" |
Exam Traps
- The exam loves ALE math questions — expect at least one scenario requiring you to compute SLE, then ALE, from given AV/EF/ARO figures. The most common trap answers are the SLE value alone (forgetting to multiply by ARO) and AV × ARO (skipping EF entirely, as if the whole asset were lost every time).
- Controller vs. processor trips everyone — the controller decides why and how data is processed; the processor only processes it on the controller's instructions. A vendor storing data exactly as told is a processor, even if they physically hold all of it.
- Right to be forgotten is not absolute — it's subject to legal exceptions (litigation holds, statutory retention requirements). A stem describing data that legally cannot be deleted on request hasn't disproven the concept — it's describing the exception, not an exam contradiction.
- Risk tolerance and risk appetite are not synonyms — appetite is the strategic "how much are we willing to pursue," set top-down; tolerance is the narrower "how much variance can we absorb" before escalation kicks in.
- Due diligence happens before; due care continues after — due diligence is the investigation done before entering a relationship or taking an action; due care is the ongoing reasonable standard maintained afterward. A stem about vetting a new vendor is due diligence; a stem about maintaining safeguards on an existing system is due care.
- MOU and MOA are the closest pair on the exam and the easiest to swap — an MOU states mutual intent without binding obligations; an MOA specifies actual agreed responsibilities and is more likely to carry legal weight. If the stem names specific deliverables each party owes the other, lean MOA over MOU.
- Known/partially known/unknown replaced white/gray/black box on SY0-701 — both naming conventions describe the same three tiers of information given to a tester in advance; expect either name in a stem.
- Business continuity and disaster recovery are related but not identical — business continuity is the broader umbrella (keeping the business running, including non-IT functions); disaster recovery is specifically about restoring IT systems after a disruption. A DR plan is typically one component that supports the larger BC plan.
- MTBF is not a recovery metric — it measures how long a component runs before failing (reliability), while RTO/RPO/MTTR all describe recovery targets or performance after failure has already occurred. A stem about "expected operating life before failure" is MTBF, not MTTR.
Acronym Table
| Acronym | Expansion | One-line meaning |
|---|---|---|
| AUP | Acceptable Use Policy | Defines permitted use of organizational systems |
| SDLC | Software Development Life Cycle | Framework for building security into software development from the start |
| BCP | Business Continuity Plan | Keeps essential business functions running through disruption |
| DRP | Disaster Recovery Plan | Restores IT systems and data after a disruption |
| KRI | Key Risk Indicator | Metric giving early warning a risk is trending toward materializing |
| SLE | Single Loss Expectancy | Dollar cost of one occurrence of a risk (AV × EF) |
| ALE | Annualized Loss Expectancy | Expected dollar cost per year (SLE × ARO) |
| ARO | Annualized Rate of Occurrence | Expected number of occurrences per year |
| EF | Exposure Factor | Percentage of asset value lost in one occurrence |
| BIA | Business Impact Analysis | Quantifies operational cost of downtime, drives RTO/RPO |
| RTO | Recovery Time Objective | Maximum acceptable time to restore a system |
| RPO | Recovery Point Objective | Maximum acceptable data loss, measured backward in time |
| MTTR | Mean Time To Repair | Average actual time taken to repair a failed component |
| MTBF | Mean Time Between Failures | Average time a component operates before failing |
| SLA | Service Level Agreement | Binding, measurable performance commitment |
| MOU | Memorandum of Understanding | Non-binding statement of mutual intent |
| MOA | Memorandum of Agreement | Formal agreement specifying agreed obligations |
| MSA | Master Service Agreement | Baseline contract terms governing future work orders/SOWs |
| SOW | Statement of Work | Defines scope, deliverables, timeline, cost for one engagement |
| WO | Work Order | Authorizes specific work, often under an MSA, alternative to SOW |
| NDA | Non-Disclosure Agreement | Protects confidential information shared between parties |
| BPA | Business Partners Agreement | Defines structure/responsibilities of a business partnership |
Drills: 20 flashcards + 10 exam-realistic questions, at the end of this page.
Interactive drills
Flashcards
Click a card to flip it, then rate how well you knew it — cards you rate lower come back sooner. 20 cards from real study drills, scheduled with spaced repetition.
Due today: 20
Flipped: 0/20
Quiz
10 exam-style questions, easy to hard. Pick an option to see whether you're right, and why.
Score: 0/10
Q1Easythe organization's security team publishes a mandatory requirement stating all workstation passwords must be at least 14 characters with complexity enabled. Which type of governance document is this?
Q2EasyIn quantitative risk analysis, which term specifically represents the percentage of an asset's value that would be lost if a given risk event occurred one time?
Q3EasyA cloud vendor stores and processes the organization's case file backups strictly according to the organization's written instructions and does not decide why or how the data is used beyond that. Under SY0-701 privacy terminology, what is the vendor acting as?
Q4Mediumthe organization's executive leadership formally states in a written risk statement that they will pursue new digital service initiatives even if it means accepting a higher level of security risk than in past years, provided it drives faster service delivery. Which risk concept does this statement represent, and what type would it be categorized as?
Q5MediumTwo government agencies draft a document stating they intend to collaborate on a future joint cybersecurity information-sharing initiative. The document expresses mutual goodwill and shared intent but does not obligate either party to specific deliverables or create a legally binding commitment. What type of agreement is this?
Q6MediumBefore signing a contract with a new cloud backup vendor, the organization's IT team reviews the vendor's independent security audit reports, checks references, and verifies their compliance certifications. Which compliance monitoring concept does this pre-contract investigation represent?
Q7MediumA penetration tester is given a standard user account and the general subnet range of the target environment, but is not provided network diagrams, source code, or administrative credentials. Which type of test environment is this?
Q8MediumA former legal aid client requests that the organization delete all personal data related to a case that is currently subject to an active legal hold due to ongoing litigation. Can the organization comply immediately using the right to be forgotten?
Q9Hard, PBQ — quantitative risk calculationthe organization assesses risk to its case-management database server, valued at AV = $200,000. A ransomware event is estimated to compromise 30% of that value in recovery costs and data loss (EF = 0.30). Based on incident history across similar government agencies, an event of this type is expected once every two years (ARO = 0.5). What is the annualized loss expectancy (ALE)?
Q10Hard, PBQ — matching agreement types to scenariosFor each statement, identify which agreement type it describes: