Domain 1: Security and Privacy Governance, Risk Management, and Compliance Program
1.1 Demonstrate knowledge in security and privacy governance, risk management,
and compliance program
1.2 Demonstrate knowledge in security and privacy governance, risk management
and compliance program processes
1.3 Demonstrate knowledge of compliance frameworks, regulations, privacy,
and security requirements
Domain 2: Scope of the System
2.1 Describe the system
2.2 Determine security compliance required
Domain 3: Selection and Approval of Framework, Security, and Privacy Controls
3.1 Identify and document baseline and inherited controls
3.2 Select and tailor controls
Domain 4: Implementation of Security and Privacy Controls
4.1 Develop implementation strategy (e.g., resourcing, funding, timeline, effectiveness)
and compliance for security and privacy controls
4.2 Implement selected controls
Domain 5: Assessment/Audit of Security and Privacy Controls
5.1 Prepare for assessment/audit
5.2 Conduct assessment/audit
5.3 Prepare the initial assessment/audit report
5.4 Review initial assessment/audit report and plan risk response actions
5.5 Develop final assessment/audit report
5.6 Develop risk response plan
Domain 6: System Compliance
6.1 Review and submit security/privacy documents
6.2 Determine system risk posture
6.3 Document system compliance
Domain 7: Compliance Maintenance
7.1 Perform system change management
7.2 Perform ongoing compliance activities based on requirements
7.3 Engage in audits activities based on compliance requirements
7.4 Decommission system when applicable