The document provides an overview of the Information Security & Risk Management domain for the CISSP certification. It discusses key topics including information security concepts, governance, risk management, information classification, and security controls. The objectives are to understand planning and securing information assets, developing security policies and procedures, conducting risk assessments, and implementing controls to ensure confidentiality, integrity and availability. New requirements for 2012 include project management knowledge and privacy compliance.