2.1 Comply with Codes of Ethics
Key Takeaways
- The ISC2 Code of Ethics has four mandatory canons, in this order: (1) Protect society, the common good, necessary public trust and confidence, and the infrastructure; (2) Act honorably, honestly, justly, responsibly, and legally; (3) Provide diligent and competent service to principals; (4) Advance and protect the profession.
- The preamble requires that practitioners adhere, and be seen to adhere, to the highest ethical standards; strict adherence is a condition of SSCP and other ISC2 certification.
- When canons conflict, society and infrastructure come first. A manager's order to skip a control, punch an unprotected firewall hole, or hide a finding does not override Canons I and II.
- ISC2 members who observe another member's breach must follow the official ethics complaint procedure; failing to do so can itself violate Canon IV.
- Organizational codes of ethics apply in addition to the ISC2 Code. A silent or weaker employer rule does not license illegal, dishonest, or publicly harmful operations.
Why codes of ethics show up on an operations exam
Domain 1, Security Concepts and Practices, is weighted at 16% of the Systems Security Certified Practitioner (SSCP) exam under the outline effective 1 October 2025. Knowledge area 1.1 — Comply with codes of ethics — is first in that domain because ISC2 treats ethics as an operational control on the practitioner, not a human-resources poster. You implement firewalls, reset accounts, and read packet captures. You also decide whether to open a port without a ticket, whether to hide a finding, and whether to stay silent when a certified colleague forges evidence. Those decisions are in scope.
The ISC2 Code of Ethics binds every ISC2 member and Associate, including SSCP holders. Certification is a privilege that must be earned and maintained. Members who intentionally or knowingly violate any provision of the Code are subject to action by a peer review panel, which may result in revocation of certification. The exam will not ask you to recite a mailing address for the ethics committee, but it will ask which duty wins when a manager, a customer, and the public pull in different directions.
There are only four mandatory canons. ISC2 states that such high-level guidance is not a substitute for the ethical judgment of the professional. That sentence is a trap if you treat it as "ethics is subjective." The canons are mandatory. Judgment is how you apply them to a messy change ticket, not permission to ignore them.
Preamble: society, principals, and a condition of certification
The Code of Ethics preamble has two clauses you should be able to paraphrase accurately:
- The safety and welfare of society and the common good, duty to our principals, and duty to each other, require that we adhere, and be seen to adhere, to the highest ethical standards of behavior.
- Therefore, strict adherence to this Code is a condition of certification.
Three duties sit in that first sentence: society and the common good, principals (the employer or client you serve), and each other (the professional community). "Be seen to adhere" is not marketing language. A Security Operations Center (SOC) analyst who uses a shared admin password, or who accepts a vendor dinner the night before scoring that vendor's product, can destroy necessary public trust even if no exploit is dropped. Appearance of impropriety is already a Canon I problem.
"Condition of certification" means the Code does not expire when you walk out of the Pearson VUE center. Passing the Computerized Adaptive Testing (CAT) exam without the experience requirement makes you an Associate of ISC2; you are still bound. Letting the credential lapse does not license you to keep using the letters, and using the letters while ignoring the Code is the kind of conduct Canon IV exists to stop.
The four canons, in order
Memorize the canons in this sequence. The exam uses order as the conflict-resolution key.
| Order | Canon | What it means on an SSCP shift |
|---|---|---|
| 1 | Protect society, the common good, necessary public trust and confidence, and the infrastructure | Customer data, public services, and the systems other people depend on come first. Do not weaken an internet-facing control to hit a project date. |
| 2 | Act honorably, honestly, justly, responsibly, and legally | Tell the truth in tickets, metrics, and audits. Do not break the law because a vice president asked. Do not alter logs. |
| 3 | Provide diligent and competent service to principals | Do the technical job well: patch, monitor, document, escalate, and refuse to fake competence. |
| 4 | Advance and protect the profession | Mentor, share non-secret knowledge, and use the official ethics process instead of rumor. |
Canon I is about society and infrastructure, not politeness. An SSCP supporting a hospital who allows an unpatched imaging workstation onto the clinical virtual local area network (VLAN) "so the surgeon can work" is failing Canon I even if that surgeon is the principal's largest revenue source. Canon II is where legality lives: you cannot "diligently" implement an unauthorized mailbox search, a covert packet capture of a labor dispute, or a cover-up. Canon III is why laziness is in scope — shipping a half-tested access control list (ACL) that you do not understand is not diligent service. Canon IV is why you do not trash the profession on a public forum, and why you also do not protect a colleague who is trashing it in private.
When canons conflict: society first
The canons collide on purpose. A principal (Canon III) may want speed that harms the public or the infrastructure (Canon I), or that is dishonest or illegal (Canon II). The published order is the exam's tie-breaker: protect society first. Diligent service to an employer never requires you to lie, break the law, or expose other people's data and systems.
Scenario: a manager asks you to skip a control
You are the security administrator for a regional logistics company. A vice president wants TCP port 445 opened from the internet to an internal file server "just for this afternoon" so an overseas vendor can copy a dataset. The VP also tells you to skip the change-advisory-board (CAB) ticket and the jump-host requirement because "legal already signed the contract." That request is a Canon III pull: serve the principal quickly. It is also a Canon I and Canon II problem. Exposing Server Message Block (SMB) to the internet is a well-known ransomware path, and skipping documented change control can violate policy and, in a regulated environment, legal duties.
The SSCP response is operational, not theatrical. You refuse the unprotected exception. You offer a competent alternative: time-boxed virtual private network (VPN) access, a unique vendor account with least privilege, full logging, and an emergency CAB change. If the manager orders you to punch the hole anyway, you still do not implement it. You document the order, notify the next accountable owner — typically the information security officer, legal, or risk — and you preserve evidence. Serving the principal diligently includes protecting that principal from a breach they are about to cause. Hiding the conversation, or implementing the hole and hoping the vendor is "safe," fails Canons I, II, and III at once.
The same pattern applies when someone asks you to disable multi-factor authentication (MFA) for an executive, to turn off Data Loss Prevention (DLP) "for a demo," or to leave a finding out of a board pack. Skip the control, and you have chosen the principal's convenience over society, honesty, or both.
Ethics complaint duty
ISC2 members are obligated to follow the ethics complaint procedure upon observing any action by an ISC2 member that breaches the Code. Failure to do so may be considered a breach of the Code pursuant to Canon IV. That duty is the opposite of "not my circus." You are not required to run a private investigation, and you must not try the colleague in a Slack channel.
Procedure points that show up in scenario items:
- Complaints must be in writing, as a sworn affidavit, and must specify the canon alleged to have been violated.
- The Professional Conduct (Ethics) Committee is not an investigative body and does not compel testimony. It considers evidence submitted voluntarily. If a prima facie case is not made, the complaint can close without prejudice.
- Standing depends on the canon. Any member of the public may complain about Canons I or II. Only principals — those with an employer or contractor relationship with the certificate holder — may complain about Canon III. Only other professionals who are certified or licensed and who subscribe to a code of ethics may complain about Canon IV.
- The board and its agents keep complainant and respondent identities confidential from the general public where possible. The respondent is entitled to timely notice, to see the complaint and evidence, and to respond by sworn affidavit.
- Discipline of certificate holders is at the sole discretion of the ISC2 board. Decisions of the board are final.
Do not confuse this process with a human-resources grievance, a SOC incident ticket, or a public social-media warning. Canon IV is about protecting the profession through the official channel. Public shaming can itself harm necessary public trust.
Organizational codes versus the ISC2 Code
Outline 1.1 tests both the ISC2 Code and the organizational code of ethics. Employers publish acceptable-use, conflict-of-interest, gift, moonlighting, and data-handling rules. You must follow both. They are not substitutes.
| Situation | Practitioner action |
|---|---|
| The organizational code is stricter (zero vendor gifts) | Follow the stricter employer rule. Canons II and III support that. |
| The organization is silent (shared break-glass password on a whiteboard) | ISC2 still binds you. Shared secrets destroy accountability and public trust. |
| The organization conflicts with law or public safety ("delete the breach tickets") | Canons I and II win. You do not destroy evidence. |
| A customer code and an employer code both apply (managed service) | Identify the principal for the task, honor contracts and law, and still refuse illegal or harmful acts. |
Organizational ethics appear in daily work as the policies you already enforce: do not browse mailboxes out of curiosity, do not copy production records into a lab, do not reuse a customer's network diagram in a conference talk, do not trade on knowledge of an unannounced incident. An SSCP who is technically sharp but treats production as a playground still fails 1.1.
Read the employer's code of conduct the same week you receive privileged credentials. If a local habit — skipping after-hours change control, using personal email for admin messages, leaving a data-center cage propped open — contradicts either code, change the habit. You do not inherit unethical operations because "that is how we have always done it."
How to attack a CAT ethics item
Translate the stem into duties:
- Name the canons in play.
- Apply order: society and infrastructure, then honest and legal conduct, then service to principals, then the profession.
- Prefer a competent alternative that still serves the principal.
- If you observed a breach by an ISC2 member, use the complaint procedure rather than silence or public accusation.
That is the same pattern you use on a real shift: protect people and infrastructure, tell the truth, do the job well, and do not cover for professional misconduct.
A security administrator holding SSCP certification is told to open TCP 445 from the internet to an internal file server and to skip the change ticket so an overseas vendor can copy customer records the same afternoon. The administrator believes the change would expose those records and weaken public trust. If duty to the employer conflicts with that concern, which ISC2 Code of Ethics canon must take priority?
According to the ISC2 Code of Ethics preamble, which statement is true for SSCP holders and other ISC2 members?
An SSCP member watches another ISC2-certified colleague alter firewall logs after an unauthorized change. What is the member's ethics duty?