StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 1: Security & risk management

Legal and regulatory issues: cybercrime, privacy law, intellectual property, transborder data flow

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

A CISSP is expected to understand the legal environment well enough to know which obligations apply, how laws shape controls and when to call legal counsel. You are not expected to be a lawyer, and exam answers that suggest you act as one, such as deciding on your own whether a breach is legally reportable, are usually wrong. Laws fall into three broad categories you should recognize: criminal law (offenses against society, prosecuted by the government and punished by prison or fines), civil law (disputes between parties, remedied by damages, such as contract breaches) and administrative or regulatory law (rules made by government agencies that carry the force of law).

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan