In this chapter, we introduce legal, regulatory, investigatory and compliance aspects of security that CISSP professionals must be aware of. This section has low testability because the exam has become more global. However, there are a number of components that are key to profession and your ability to be successful as an advisor on security matters that require an examination of these principals. Among other things, we'll discuss common terms, attach motivations, and types of law specific to security. We also discuss at length some key terms such as liability, due diligence and culpable negligence and why having an intimate understanding of them is critical. And we'll look at intellectual property and trade secrets and what copyright infringement entails, the time lengths of these statutes which are all testable exam components.

