Every Certified Information Systems Security Professional (CISSP) agrees to follow the ISC2 Code of Ethics, and a proven violation can cost you the certification. The exam rarely asks you to recite the code word for word. Instead it gives you a short dilemma, often with a manager, client or colleague pressuring you, and asks what the certified professional should do first or most appropriately. To answer well you need to know the four canons, and above all the order in which they apply when they pull in different directions.
The code opens with a preamble: the safety and welfare of society and the common good, duty to our principals, and duty to each other require that members adhere, and be seen to adhere, to the highest ethical standards of behavior. Strict adherence is a condition of certification. Notice the phrase 'be seen to adhere'. Conduct that merely looks like a conflict of interest, such as quietly recommending a vendor that pays you a referral fee, can damage trust even if the recommendation was sound. Transparency and disclosure are part of ethical behavior, not optional extras.
The four canons, in priority order, are: (1) protect society, the common good, necessary public trust and confidence, and the infrastructure; (2) act honorably, honestly, justly, responsibly and legally; (3) provide diligent and competent service to principals; (4) advance and protect the profession. A principal is whoever you serve professionally: your employer, a client or a customer. When canons conflict, the higher one wins. If your employer asks you to conceal a flaw that endangers the public, canon one outranks canon three. If a client asks you to cut a legal corner to save money, canon two outranks canon three. Serving the profession, canon four, never justifies harming the public or acting dishonestly.
ISC2 runs a formal complaint process through an ethics committee. Broadly, anyone can file a complaint about a breach of the first two canons, only principals can complain about the third, and other certified or licensed professionals who subscribe to a code of ethics can complain about the fourth. Complaints must be written, specific and supported, and the accused member gets a chance to respond. Members are also expected to support the process, which means that knowingly staying silent about a serious violation can itself be a problem.
Organizational ethics is the second half of this topic. Your employer will have its own code of conduct, acceptable use policy and values statement, and a CISSP is expected to help build and model them. A healthy ethics program has written expectations, training, a safe way to raise concerns (often an anonymous hotline), protection from retaliation for good-faith reporters, and consistent enforcement from the top. Senior management sets the tone: if executives ignore the rules, no policy will survive. You may also meet older guidance such as the Internet Architecture Board's 'Ethics and the Internet', which calls activities like seeking unauthorized access, disrupting intended use of the internet and wasting resources unethical. The common theme is that security professionals hold extra access and knowledge, so they carry extra responsibility not to misuse it.
Consider a worked example. You are a consultant finishing a penetration test for a water utility. You find that a remote access gateway to the treatment plant's control network accepts a default password. The utility's IT director asks you to leave the finding out of the written report because the board meets next week and he does not want bad news. Canon three says to serve the client diligently, but canons one and two outrank it: the finding affects public safety, and omitting it would be dishonest. The right path is to report it accurately, explain the risk in business terms, recommend immediate compensating controls, and escalate to higher management if the director insists. You do not leak it to the press or post it online, because that would be neither honorable nor legal.
Common mistakes: treating the canons as equal rather than ranked; assuming loyalty to the employer always comes first; picking the most dramatic answer, such as going straight to the media or law enforcement, when internal escalation is still available; and confusing the organization's code of conduct with the ISC2 code. Another trap is thinking ethics only covers big decisions. Using privileged access to peek at a colleague's salary file, or accepting a lavish gift from a vendor under evaluation, are everyday violations.
On the exam, clue words such as 'public safety', 'critical infrastructure' or 'society' point to canon one. 'Lie', 'conceal', 'illegal' or 'falsify' point to canon two. 'Client', 'employer' or 'competent service' point to canon three, and 'mentoring', 'reputation of the profession' or 'unqualified practice' point to canon four. Think like a manager and a professional at the same time: choose the answer that is honest, lawful and protects people, raise concerns through proper channels first, and document what you did. The best answer is usually measured and principled rather than silent or explosive.
Key terms
- ISC2 Code of Ethics
- The preamble and four canons that every ISC2-certified member agrees to follow as a condition of certification.
- Canon
- One of the four ranked principles of the code; when two conflict, the higher-ranked canon takes priority.
- Principal
- The party you serve professionally, such as an employer, client or customer.
- Conflict of interest
- A situation where personal gain or divided loyalty could influence, or appear to influence, professional judgment.
- Code of conduct
- An organization's own written statement of expected behavior, values and consequences for violations.
- Ethics hotline
- A confidential or anonymous channel for staff to report suspected misconduct without fear of retaliation.
- Tone at the top
- The ethical climate set by senior leadership through its own behavior and enforcement.
A security engineer at a medical device maker discovers that an insulin pump's wireless interface lacks authentication. Her manager wants to delay disclosure until after a product launch. She documents the risk, escalates to the chief information security officer and the product safety board, and pushes for coordinated disclosure with regulators and customers. She chooses protecting patients (canon one) and honesty (canon two) over the launch schedule, while still working through legitimate internal channels.
Check yourself
What is the correct priority order of the four ISC2 canons?
Protect society and infrastructure; act honorably, honestly, justly, responsibly and legally; serve principals diligently and competently; advance and protect the profession.
Your employer asks you to hide a vulnerability that could endanger the public. Which canon governs your response?
Canon one, protecting society and the common good, which outranks the duty to principals in canon three.
Who may file an ethics complaint about a breach of canon three?
Only principals, meaning the employers, clients or customers the member served.
Why does the preamble say members must 'be seen to adhere' to high standards?
Because the appearance of impropriety, such as an undisclosed conflict of interest, erodes public trust even when no actual harm occurred.