07/31/2026
One of the challenges of studying for cybersecurity certifications is the sheer volume of material. CISSP, CCSP, CSSLP, Security+, CISM... each covers a vast body of knowledge that can seem overwhelming.
After teaching ISC2 CISSP for the past 10 years, we've become convinced that the students who succeed are the ones who recognize that all of those topics are built on a few timeless principles. Technology changes rapidly—especially with AI—but the fundamentals have remained remarkably constant.
To me, nearly everything in cybersecurity comes back to two foundational concepts.
1. Risk
Cybersecurity exists to manage risk. We identify threats and vulnerabilities, assess the likelihood and impact, and implement administrative, technical, and physical controls to reduce risk to an acceptable level. Whether you're discussing governance, cloud security, software development, cryptography, or incident response, you're really discussing different ways of managing risk.
2. State
Information systems are constantly changing state. Users authenticate. Processes execute. Files are created, modified, transmitted, encrypted, archived, and eventually destroyed. Privileges are granted and revoked. Network connections are established and terminated.
Security controls exist to ensure those state transitions occur only in authorized ways—and to prevent, detect, or correct unauthorized changes. In many ways, cybersecurity is the discipline of governing the allowable state transitions of systems while continuously managing the risk associated with them.
Whenever we introduce a new CISSP domain, we mentally ask two questions:
• What risk are we trying to manage?
• What state are we trying to control?
Those two questions have served us well as an instructor, a practitioner, and an architect. More importantly, they help transform cybersecurity from a collection of disconnected technologies into a coherent discipline.
We'd be interested to hear from other security professionals. What foundational principle has remained constant throughout your career, regardless of how much the technology has changed?