🏠 Back to Exam Syllabus 📺 RooCloud on YouTube 🎯 Free CISSP Practice Test

CISSP 8.4 - Select Controls Based on Systems Security Requirements

This episode of the ISC2 Certified Information Systems Security Professional (CISSP) exam prep series looks at how buyers judge whether a system is actually secure enough, a core Domain 3 skill for anyone choosing products for high-stakes environments. It walks through the shared framework that turns vendor promises into independent evidence, and the formal approval that puts a system into real-world operation.

What this episode covers

Watch the full episode above for the worked examples and detailed explanations of each concept.

Frequently Asked Questions

Why do organizations demand formal security evaluations?

Because some data is too valuable, or too dangerous, to protect on faith. Buyers of sensitive systems, like national security agencies or major financial firms, want to understand a product’s strengths and weaknesses before they ever purchase it, so they insist on systems that have passed a formal evaluation and earned a security rating. Usually a trusted independent third party performs that testing, and their seal of approval is the real prize.

What is the Common Criteria?

The Common Criteria is an internationally recognized framework that defines standardized levels for testing and confirming a system’s security capabilities, replacing older, more rigid rating systems. It is published as an international standard adopted by many countries, so one nation’s evaluation is honored by the others, avoiding wasteful duplicate testing. Even the highest rating, however, never guarantees a system is flawless.

How do protection profiles and security targets fit together?

A protection profile is the customer’s wish list, stating the security requirements the buyer needs from the product being evaluated. A security target is the vendor’s answer, stating the security claims actually built into their system, and vendors can also offer optional packages of extra security features. The buyer then matches their protection profile against the security targets on offer and picks the closest fit.

What do the evaluation assurance levels measure?

Evaluation assurance levels, running from 1 up to 7, grade how rigorously a system was tested and verified. A low level means only basic confidence, suitable when threats are not serious, while higher levels deepen the engineering discipline from methodically tested to semi-formally verified, and the very top level demands formal, mathematically rigorous analysis reserved for the highest-risk situations. These levels give buyers a standardized way to compare vendors on trustworthiness.

What is an authorization to operate?

An authorization to operate is the official green light to run a secured system for real work and to formally accept its risk, coming from the risk management framework as the modern replacement for accreditation. An authorizing official can issue four kinds of decisions: a full authorization to operate, a common control authorization, an authorization to use for third-party services, or a denial when risk is too high. It is not forever and must be renewed when it expires, after a significant breach, or after a major security change.

📚 Master the ISC2 CISSP Exam!

Reinforce this lesson with real practice. The RooCloud CISSP Practice Pack gives you 6,000+ exam-style questions, 366 section-wise practice tests and 40 full-length adaptive (CAT) tests across all 8 CISSP domains, with full explanations. Start with a FREE full-length adaptive CISSP test →


Reference: This article is based on concepts discussed in CISSP 8.4 - Select Controls Based on Systems Security Requirements.