An organization cannot effectively protect information and technology unless it first understands:
what assets it possesses;
where those assets are located;
how important they are;
who owns them;
who is permitted to use them;
how sensitive the information is;
how the information should be handled;
how long it should be retained;
how it should be protected throughout its lifecycle;
when it should be retired or destroyed.
This is the foundation of Asset Security, CISSP Domain 2.
The current CISSP examination outline assigns 10% of the examination to Asset Security and divides the domain into six major objectives:
identify and classify information and assets;
establish information and asset handling requirements;
provision information and assets securely;
manage the data lifecycle;
ensure appropriate asset retention, including End of Life and End of Support;
determine appropriate data-security controls and compliance requirements.
The current outline explicitly includes data classification, asset classification, ownership, inventories, tangible and intangible assets, data roles, collection, location, maintenance, retention, remanence, destruction, data states, scoping, tailoring, standards selection, Digital Rights Management, Data Loss Prevention, and Cloud Access Security Brokers.
The central question for Lesson Seven is:
What information and assets does the organization possess, how valuable or sensitive are they, who is responsible for them, and how should protection follow them throughout their lifecycle?
| Lesson Topic | CISSP Objective |
|---|---|
| Information identification | 2.1 |
| Data classification | 2.1 |
| Asset classification | 2.1 |
| Handling requirements | 2.2 |
| Secure provisioning | 2.3 |
| Information ownership | 2.3 |
| Asset ownership | 2.3 |
| Tangible asset inventory | 2.3 |
| Intangible asset inventory | 2.3 |
| Asset management | 2.3 |
| Data owners | 2.4 |
| Controllers | 2.4 |
| Custodians | 2.4 |
| Processors | 2.4 |
| Users / subjects | 2.4 |
| Data collection | 2.4 |
| Data location | 2.4 |
| Data maintenance | 2.4 |
| Data retention | 2.4 |
| Data remanence | 2.4 |
| Data destruction | 2.4 |
| End of Life | 2.5 |
| End of Support | 2.5 |
| Data at rest | 2.6 |
| Data in transit | 2.6 |
| Data in use | 2.6 |
| Scoping | 2.6 |
| Tailoring | 2.6 |
| Standards selection | 2.6 |
| Digital Rights Management | 2.6 |
| Data Loss Prevention | 2.6 |
| Cloud Access Security Broker | 2.6 |
These topics are explicitly contained in the current Domain 2 examination objectives.
After completing this lesson, you should be able to:
Define an organizational asset.
Distinguish information assets from physical and technological assets.
Distinguish tangible from intangible assets.
Explain why asset identification must precede appropriate protection.
Define data classification.
Define asset classification.
Explain how value, sensitivity, criticality, and business impact influence classification.
Develop an example classification hierarchy.
Explain why classification schemes should be understandable and manageable.
Explain the relationship between classification and handling requirements.
Describe handling requirements for storing, transmitting, printing, copying, sharing, and disposing of information.
Explain information ownership.
Explain system and asset ownership.
Explain the role of asset inventories.
Describe secure asset provisioning.
Distinguish asset owner, data owner, controller, custodian, processor, user, and data subject.
Explain the complete information lifecycle.
Explain why data collection should be controlled.
Explain the importance of knowing data location.
Describe data maintenance requirements.
Explain retention requirements.
Define data remanence.
Explain why normal deletion may not securely remove information.
Explain sanitization and secure destruction.
Explain End of Life and End of Support risks.
Distinguish data at rest, in transit, and in use.
Select appropriate controls according to data state.
Explain scoping and tailoring.
Explain standards selection.
Define Digital Rights Management.
Define Data Loss Prevention.
Define Cloud Access Security Broker.
Explain how DRM, DLP, and CASB differ.
Explain data masking, tokenization, and encryption at an introductory level.
Apply asset-security principles to CISSP-style scenarios.
Recognize common examination traps involving ownership, classification, retention, and disposal.
An asset is anything that has value to an organization or its stakeholders.
Assets may support:
revenue;
operations;
legal obligations;
customer relationships;
safety;
intellectual property;
organizational mission.
Examples include:
databases;
servers;
cloud services;
laptops;
customer records;
source code;
contracts;
cryptographic keys;
manufacturing equipment;
intellectual property;
employee knowledge.
Asset security concerns the identification, classification, ownership, handling, protection, retention, and disposition of organizational information and assets.
Asset security asks:
What do we have?
Why does it matter?
Who owns it?
How sensitive or critical is it?
How should it be handled?
How long should it exist?
How should it be destroyed?
IDENTIFY
β
βΌ
CLASSIFY
β
βΌ
ASSIGN OWNER
β
βΌ
PROVISION
β
βΌ
PROTECT
β
βΌ
USE / MAINTAIN
β
βΌ
RETAIN
β
βΌ
REVIEW
β
βΌ
RETIRE
β
βΌ
SANITIZE / DESTROY
Asset security is therefore a lifecycle activity.
Consider this question:
How should an organization protect confidential intellectual property if it does not know the information exists?
It cannot.
Likewise:
How can an organization patch an unknown server?
It cannot.
How can it terminate a forgotten cloud account?
It cannot.
Therefore:
You cannot effectively protect what you do not know you possess.
An asset inventory provides visibility into organizational resources.
A useful inventory may include:
asset identifier;
description;
owner;
location;
classification;
status;
criticality;
lifecycle stage;
support status.
| Asset ID | Asset | Owner | Classification | Location | Status |
|---|---|---|---|---|---|
| A-001 | Payroll DB | HR Director | Confidential | Cloud Region A | Production |
| A-002 | Public Website | Marketing | Public | Cloud Region B | Production |
| A-003 | Domain Controller | CIO | Critical | Data Center | Production |
| A-004 | Old Laptop | Finance | Confidential | Storage | Pending disposal |
The inventory should support security decisions rather than exist merely for audit purposes.
Tangible assets have physical form.
Examples:
laptops;
servers;
smartphones;
storage devices;
routers;
buildings;
backup media.
Intangible assets do not necessarily have a physical form.
Examples:
data;
software;
intellectual property;
reputation;
source code;
credentials;
business processes;
licenses.
The current CISSP outline explicitly includes both tangible and intangible assets in asset inventory and management.
| Tangible | Intangible |
|---|---|
| Laptop | Customer database |
| Server | Source code |
| Building | Brand reputation |
| Backup tape | Encryption key |
| Network switch | Software license |
A physical device may have low replacement cost while containing extremely high-value information.
A laptop may cost:
$1,500.
But if it contains:
trade secrets;
customer information;
cryptographic keys;
the organizational impact of compromise may be far greater than the hardware's purchase price.
Therefore:
Asset value should be evaluated in business context.
Data classification assigns information to categories based on characteristics such as:
sensitivity;
value;
confidentiality;
criticality;
legal requirements.
Classification helps determine appropriate protection.
Without classification, organizations may:
overprotect public information;
underprotect sensitive information;
apply inconsistent controls;
waste resources.
Classification provides a rational basis for protection.
A private-sector organization might use:
RESTRICTED
β²
CONFIDENTIAL
β²
INTERNAL
β²
PUBLIC
Higher levels generally require stronger controls.
Public information is intended for general disclosure.
Examples:
published press releases;
public website content;
approved marketing materials.
Confidentiality requirements may be low.
Integrity can still matter greatly.
An attacker who changes a company's public website can cause reputational harm.
Internal information is intended primarily for organizational use.
Examples:
routine internal communications;
internal procedures;
staff directories.
Unauthorized public disclosure may create limited or moderate harm.
Confidential information could cause significant harm if disclosed improperly.
Examples:
employee records;
customer information;
contracts;
financial reports.
Controls may include:
access restrictions;
encryption;
monitoring;
secure transmission.
The highest category may contain information whose compromise could result in severe harm.
Examples:
cryptographic root keys;
merger plans;
high-value intellectual property;
highly sensitive investigative information.
Protection may involve:
strict need to know;
privileged access controls;
enhanced monitoring;
strong encryption;
limited distribution.
| Level | Example | Typical Protection |
|---|---|---|
| Public | Marketing brochure | Integrity controls |
| Internal | Internal memo | Employee access |
| Confidential | Payroll | Encryption + restricted access |
| Restricted | Root cryptographic key | HSM / strict control |
Exact names differ among organizations.
CISSP questions typically focus on the principle, not one universal naming convention.
Organizations may classify information based on:
sensitivity;
business impact;
privacy;
regulatory requirements;
financial impact;
operational importance.
A classification scheme with 25 nearly identical categories may be difficult to use correctly.
Effective classification should be:
understandable;
consistent;
enforceable;
aligned with business requirements.
Classification should not necessarily remain unchanged forever.
DATA CREATED
β
βΌ
CLASSIFIED
β
βΌ
USED
β
βΌ
REVIEWED
β
βΌ
STILL SAME SENSITIVITY?
ββββββ΄βββββ
YES NO
β β
KEEP RECLASSIFY
Example:
A confidential acquisition plan may become public after the acquisition is officially announced.
Data classification focuses on information.
Asset classification considers the importance or sensitivity of broader assets.
| Data Classification | Asset Classification |
|---|---|
| Focuses on information | Focuses on broader organizational asset |
| Payroll = Confidential | Payroll server = Critical |
| Contract = Restricted | Contract repository = High Criticality |
An asset can be critical because of:
business dependency;
safety consequences;
availability requirements;
legal obligations;
financial impact.
Two identical servers may have very different classification.
Server A:
Development test server.
Server B:
Emergency communications server.
Same technology.
Different business importance.
Therefore:
Technical similarity does not imply equal criticality.
Every important information set or asset should have an accountable owner.
Without ownership:
classification may be unclear;
access decisions may be inconsistent;
retention may be undefined;
risks may remain unresolved.
The data owner is typically responsible for determining requirements regarding the information.
Responsibilities may include:
classification;
authorized access;
protection requirements;
retention;
acceptable use.
Memory aid:
Owner decides.
An asset owner is accountable for the asset's organizational use and protection requirements.
Examples:
application owner;
system owner;
business-process owner.
The custodian implements and operates protections.
Examples:
database administrator;
cloud administrator;
storage administrator.
Memory aid:
Owner decides. Custodian implements.
The current CISSP Domain 2 outline specifically identifies:
owners;
controllers;
custodians;
processors;
users / subjects
as important data-lifecycle roles.
The data owner determines organizational requirements for information.
Typical responsibilities:
classification;
access criteria;
protection expectations;
retention.
In privacy frameworks using this terminology, a controller generally determines:
why personal information is processed;
how processing occurs.
The exact legal meaning depends on the applicable privacy regime.
The custodian performs operational protection.
Examples:
maintaining databases;
implementing backup;
applying encryption;
administering permissions.
A processor processes personal information on behalf of another entity under an applicable arrangement.
Example:
A cloud payroll provider may process employee information for an employer.
A user accesses or uses organizational information according to authorization.
Responsibilities may include:
following policy;
protecting credentials;
handling data appropriately.
A data subject is the individual to whom personal information relates under privacy frameworks using this term.
Example:
An employee whose personnel information appears in an HR database.
| Role | Primary Function |
|---|---|
| Owner | Determines requirements |
| Controller | Determines purpose/means of processing |
| Custodian | Implements and maintains controls |
| Processor | Processes on behalf of another party |
| User | Authorized information user |
| Data Subject | Individual represented by personal data |
Classification has little value if it does not affect behavior.
Example:
Marking a document:
CONFIDENTIAL
but allowing it to be:
emailed publicly;
copied freely;
left unattended;
makes the classification meaningless.
CLASSIFICATION
β
βΌ
ACCESS RULES
β
βΌ
STORAGE RULES
β
βΌ
TRANSMISSION RULES
β
βΌ
USE / COPYING RULES
β
βΌ
RETENTION
β
βΌ
DISPOSAL
Handling rules may address:
access;
storage;
printing;
copying;
transmission;
sharing;
labeling;
backup;
disposal.
| Classification | Storage | Printing | Disposal | |
|---|---|---|---|---|
| Public | Allowed | Standard | Allowed | Standard |
| Internal | Internal channels | Managed systems | Controlled | Approved disposal |
| Confidential | Protected channel | Encrypted | Restricted | Secure sanitization |
| Restricted | Strong protection | Highly controlled | Limited | Verified destruction |
Provisioning is the process of preparing and assigning an asset for authorized use.
Examples:
issuing a laptop;
creating a cloud database;
deploying a server;
provisioning a software license.
Secure provisioning may include:
inventory registration;
ownership assignment;
classification;
approved configuration;
encryption;
endpoint protection;
access controls;
logging.
ASSET ACQUIRED
β
βΌ
REGISTER IN INVENTORY
β
βΌ
ASSIGN OWNER
β
βΌ
CLASSIFY
β
βΌ
APPLY BASELINE
β
βΌ
APPLY SECURITY CONTROLS
β
βΌ
AUTHORIZE USE
β
βΌ
MONITOR
A newly purchased laptop should not simply be handed to an employee.
Appropriate provisioning might include:
asset tag;
inventory record;
secure operating-system baseline;
encryption;
endpoint security;
approved applications;
authentication controls.
Assets change.
They may be:
purchased;
reassigned;
upgraded;
moved;
retired.
Asset inventory should reflect these changes.
For every important asset, ask:
What is it?
Who owns it?
Where is it?
What does it contain?
How critical is it?
What is its support status?
Who has access?
When should it be retired?
Unknown or unauthorized assets create risk.
Examples:
shadow IT;
personal cloud accounts;
unmanaged laptops;
unauthorized software.
These assets may bypass:
patching;
logging;
inventory;
backup;
monitoring.
The current CISSP outline explicitly requires candidates to manage:
collection;
location;
maintenance;
retention;
remanence;
destruction.
A broader instructional model is:
COLLECT / CREATE
β
βΌ
CLASSIFY
β
βΌ
STORE
β
βΌ
USE / PROCESS
β
βΌ
SHARE / TRANSMIT
β
βΌ
MAINTAIN
β
βΌ
RETAIN / ARCHIVE
β
βΌ
DESTROY
Security must follow data throughout the lifecycle.
Data collection should have:
defined purpose;
ownership;
classification;
security requirements.
Collecting unnecessary information creates unnecessary risk.
An application needs:
name;
email.
But also collects:
government ID;
date of birth;
detailed location;
without legitimate need.
This increases:
privacy exposure;
breach impact;
storage burden.
Data may exist in:
databases;
laptops;
backups;
SaaS platforms;
email;
cloud storage;
mobile devices.
If the organization does not know where data exists, it cannot reliably:
protect it;
delete it;
respond to breaches.
CUSTOMER DATA
β
βββββββββββββββββββΌββββββββββββββββββ
βΌ βΌ βΌ
DATABASE BACKUP SaaS
β β β
βΌ βΌ βΌ
DATA CENTER CLOUD PROVIDER
β
βΌ
ADMIN LAPTOP
One information set may exist in many locations.
Data sprawl occurs when information is copied across many systems without adequate governance.
Examples:
duplicate spreadsheets;
old backups;
personal cloud drives;
email attachments.
More copies generally mean:
More locations requiring protection.
Data maintenance involves keeping information:
accurate;
available;
appropriately protected;
usable.
Maintenance may include:
updating records;
correcting errors;
validating integrity;
adjusting permissions.
Poorly maintained information may become inaccurate.
Example:
An employee leaves the organization but remains listed as an active privileged user.
The information may no longer reflect reality.
This can become a security risk.
Retention is the period during which information must or should be preserved.
Retention may depend on:
business need;
law;
regulation;
contract;
investigation;
privacy requirements.
Keeping data forever is usually not a good default.
More retained data creates:
greater breach exposure;
storage cost;
legal discovery burden;
privacy risk.
A retention schedule specifies:
data category;
retention period;
authority;
disposition method.
| Information | Retention | Reason | Disposition |
|---|---|---|---|
| Tax record | Defined legal period | Legal | Secure disposal |
| Security logs | Business/security period | Investigation | Sanitization |
| Applicant resume | Defined HR period | Business/legal | Secure deletion |
| Temporary report | Short period | Operational | Delete |
Specific periods depend on applicable requirements.
DATA EXISTS
β
βΌ
IS RETENTION REQUIRED?
ββββ΄ββββ
YES NO
β β
βΌ βΌ
RETAIN BUSINESS NEED?
β
βββββ΄ββββ
YES NO
β β
RETAIN DISPOSE
As discussed in Lesson Six, information subject to an authorized legal hold may need to be preserved even if the normal retention period has expired.
Therefore:
Do not automatically delete information simply because the normal schedule says its retention period has ended.
Data remanence is residual information remaining on storage media after normal deletion or attempted removal.
Example:
Deleting a file may remove its directory reference while leaving recoverable information on the storage medium.
FILE EXISTS
β
βΌ
USER PRESSES DELETE
β
βΌ
DIRECTORY REFERENCE REMOVED
β
βΌ
DATA MAY STILL EXIST
ON STORAGE MEDIA
This distinction is central to secure disposal.
Residual data can expose:
passwords;
personal information;
financial information;
intellectual property;
cryptographic material.
Media sanitization aims to make access to targeted data infeasible at an appropriate level of effort.
Current NIST SP 800-88 Rev. 2, published in September 2025, emphasizes establishing an enterprise sanitization program, matching sanitization decisions to information sensitivity, validating sanitization, and addressing modern environments including logical/cloud storage.
The correct method depends on:
information sensitivity;
media type;
reuse plans;
regulatory requirements;
threat model.
Common approaches may include:
Use logical techniques appropriate for reuse under defined conditions.
Use stronger techniques intended to make recovery significantly more difficult.
Destroy appropriate encryption keys so previously encrypted information becomes inaccessible when conditions are properly satisfied.
Physically render the media unusable when required.
Current NIST guidance emphasizes approved sanitization standards, validation, and enterprise program governance rather than relying only on simplistic one-size-fits-all techniques.
MEDIA READY FOR DISPOSITION
β
βΌ
WHAT DATA IS PRESENT?
β
βΌ
HOW SENSITIVE?
β
βΌ
WILL MEDIA BE REUSED?
ββββ΄ββββ
YES NO
β β
βΌ βΌ
APPROVED SANITIZE /
SANITIZE DESTROY
β β
βββββ¬ββββ
βΌ
VALIDATE
β
βΌ
DOCUMENT
A sanitization process should not simply assume success.
Organizations may need to verify that the selected process operated correctly.
This is especially important for highly sensitive information.
Data destruction should ensure information is no longer recoverable to an unacceptable degree.
Possible methods depend on:
media;
sensitivity;
approved organizational standards.
Media may include:
hard drives;
SSDs;
USB devices;
backup tapes;
optical media;
smartphones.
Different storage technologies may require different sanitization approaches.
Cloud introduces additional complexity.
The customer may not physically control the storage medium.
Therefore, the organization should understand:
provider deletion mechanisms;
encryption-key management;
replication;
backups;
contractual requirements.
Domain 2.5 requires appropriate asset retention and explicitly includes:
End of Life;
End of Support.
Asset retention asks:
Should this technology still be in service?
End of Life generally refers to the point at which a product reaches the end of its intended lifecycle.
The vendor may:
stop selling it;
transition customers;
stop development.
End of Support indicates the vendor no longer provides normal support.
This may include cessation of:
security patches;
fixes;
technical assistance.
Unsupported technology may develop vulnerabilities that no longer receive remediation.
This can create:
security exposure;
compliance problems;
compatibility issues;
operational risk.
ASSET IN USE
β
βΌ
SUPPORTED?
ββββ΄ββββ
YES NO
β β
USE ASSESS RISK
β
βΌ
REPLACE?
ββββββ΄βββββ
YES NO
β β
MIGRATE COMPENSATING
CONTROLS +
APPROVAL +
PLAN
If immediate replacement is impossible:
document risk;
restrict exposure;
apply compensating controls;
plan migration.
The CISSP outline explicitly identifies:
data at rest;
data in transit;
data in use.
Data at rest is stored information not actively traversing a communication channel.
Examples:
database records;
files;
backups;
storage volumes.
Possible controls:
encryption;
access control;
disk protection;
physical protection;
key management.
Data in transit is moving between systems, locations, or users.
Examples:
web traffic;
email;
API communications;
database replication.
Possible safeguards:
TLS;
VPN;
authenticated protocols;
secure tunnels;
network controls.
Detailed cryptography and secure protocols will be taught later.
Data in use is actively being processed or accessed.
Examples:
information loaded into memory;
open application records;
decrypted documents in use.
Encryption at rest does not necessarily protect information after an authorized application decrypts it.
Controls may include:
access control;
process isolation;
memory protection;
endpoint security;
least privilege.
DATA
β
βββββββββββΌββββββββββ
βΌ βΌ βΌ
AT REST IN TRANSIT IN USE
β β β
βΌ βΌ βΌ
Encryption TLS Access Control
Storage ACL VPN Memory Protection
Physical Secure Endpoint Security
Security Channel
Information may move from:
DATABASE
β
βΌ
APPLICATION
β
βΌ
NETWORK
β
βΌ
USER DEVICE
β
βΌ
CLOUD STORAGE
Protection should follow the information rather than relying only on the original system.
Scoping determines which systems, information, assets, and processes are subject to particular requirements.
Example:
A payment-card standard may apply specifically to systems within the cardholder-data environment.
If scope is too narrow:
Important systems may be excluded.
If scope is unnecessarily broad:
Resources may be wasted protecting systems beyond the applicable requirement.
Ask:
What information is involved?
Which systems process it?
Which systems store it?
Which networks transmit it?
Which third parties handle it?
Which dependencies could affect it?
Tailoring adjusts control implementation to fit the organization's:
environment;
mission;
technology;
risk;
legal requirements.
Tailoring does not mean:
Ignore controls you dislike.
It means:
Adapt requirements through an authorized, risk-based process.
| Scoping | Tailoring |
|---|---|
| Determines what is included | Determines how controls are appropriately applied |
| Defines boundary | Adjusts implementation |
| βWhat is in scope?β | βHow should this fit our environment?β |
The current Domain 2 outline requires candidates to understand standards selection.
Organizations should select standards based on:
industry;
jurisdiction;
business requirements;
contractual obligations;
risk.
Poor approach:
βUse a standard because competitors mention it.β
Better approach:
Determine requirements and select the standard that appropriately supports them.
Data protection may involve:
access control;
encryption;
DRM;
DLP;
CASB;
masking;
tokenization;
monitoring.
Digital Rights Management controls the permitted use of digital information or content.
DRM may restrict:
copying;
printing;
forwarding;
editing;
access duration.
A confidential document may allow the authorized employee to:
read it;
but prevent:
printing;
forwarding;
copying.
DRM focuses on:
What can an authorized recipient do with the content?
Data Loss Prevention technologies and processes attempt to identify and prevent unauthorized exposure or movement of sensitive information.
DLP may inspect:
email;
endpoints;
network traffic;
cloud uploads.
An employee attempts to email a spreadsheet containing thousands of customer records to a personal email account.
A DLP system may:
detect sensitive information;
block transmission;
generate an alert.
SENSITIVE DATA
β
βΌ
USER ATTEMPTS TRANSFER
β
βΌ
DLP INSPECTION
β
βΌ
POLICY MATCH?
ββββββ΄βββββ
YES NO
β β
BLOCK / ALLOW
ALERT
DLP is not magic.
Effectiveness depends on:
accurate classification;
policies;
coverage;
tuning;
monitoring.
A Cloud Access Security Broker helps organizations apply security policy and visibility around the use of cloud services.
CASB is explicitly included by ISC2 as a Domain 2 data-protection method.
NIST also recognizes CASB terminology in its cybersecurity glossary.
Depending on the solution, a CASB may help with:
cloud-service visibility;
policy enforcement;
access control;
data protection;
activity monitoring;
cloud-risk management.
Employee attempts:
CORPORATE DEVICE
β
βΌ
UPLOAD CONFIDENTIAL FILE
β
βΌ
UNAPPROVED CLOUD SERVICE
β
βΌ
CASB POLICY
β
βΌ
BLOCK / ALERT
| Technology | Main Focus | Example |
|---|---|---|
| DRM | Control permitted use of content | Prevent printing |
| DLP | Prevent unauthorized data movement | Block sensitive email |
| CASB | Govern cloud-service use | Block upload to unsanctioned SaaS |
These controls can complement one another.
Encryption can help protect:
data at rest;
data in transit.
But encryption effectiveness depends on:
algorithm;
implementation;
key management;
authorized access.
Detailed cryptography will be covered in Lesson Ten.
Masking obscures sensitive information while preserving a usable representation.
Example:
Credit Card:
4587-2299-1034-8821
Masked:
****-****-****-8821
A customer-service employee may need:
Last four digits.
They may not require:
Full payment-card number.
Masking can reduce unnecessary exposure.
Tokenization replaces sensitive values with surrogate values called tokens.
Example:
ORIGINAL
4111 1111 1111 1111
β
TOKEN
TKN-94F8-221A
The sensitive original remains protected separately.
At a high level:
| Encryption | Tokenization |
|---|---|
| Transforms data using cryptography | Replaces value with surrogate token |
| Reversible with appropriate key | Mapping or token system recovers original |
| Cryptographic mechanism | Data-substitution approach |
Detailed distinctions will be expanded later.
Organizations often protect assets carefully while they are in production but forget them during disposal.
An abandoned hard drive may contain:
credentials;
customer information;
source code.
ASSET RETIRED
β
βΌ
CHECK RETENTION REQUIREMENTS
β
βΌ
BACKUP REQUIRED DATA
β
βΌ
REMOVE ACCOUNTS / KEYS
β
βΌ
SANITIZE MEDIA
β
βΌ
VALIDATE
β
βΌ
DESTROY / REUSE
β
βΌ
UPDATE INVENTORY
An executive laptop reaches replacement age.
It contains:
customer data;
contracts;
cached email;
VPN credentials.
The employee receives a new device.
What should happen to the old laptop?
A. Sell it immediately.
B. Delete visible files and give it away.
C. Follow approved sanitization and asset-disposition procedures.
D. Leave it in storage indefinitely.
C
Normal deletion may leave recoverable data.
Asset disposition should follow:
classification;
sanitization requirements;
inventory procedures.
A marketing department publishes an approved brochure.
Which security objective may still be highly important even though confidentiality is low?
A. Integrity.
B. Confidentiality only.
C. Nonrepudiation only.
D. None.
A
Public information should not be modified by unauthorized parties.
A confidential merger proposal is being developed.
What should primarily determine access?
A. Employee seniority alone.
B. Classification, business need, and authorization.
C. Whoever asks first.
D. Whether the employee owns a laptop.
B
A database administrator receives a request from an employee asking for access to confidential HR records.
Who should generally determine whether the access is appropriate?
A. Data owner or authorized business authority.
B. Database administrator alone.
C. Any user.
D. Hardware vendor.
A
The custodian implements the decision.
Who is typically accountable for determining the appropriate classification of business information?
A. Data owner.
B. Custodian.
C. Help desk.
D. Visitor.
A
A company wants to protect sensitive information stored on employee laptops if devices are stolen.
Which control is MOST directly appropriate?
A. Full-disk encryption.
B. Email filtering.
C. Load balancing.
D. DNSSEC.
A
Sensitive information is transmitted between an application and a remote service.
Which control is MOST directly appropriate?
A. Secure encrypted communication protocol.
B. Locked filing cabinet.
C. Screen filter.
D. Paper shredder.
A
An authorized application has decrypted highly sensitive information into memory.
Which concept MOST directly recognizes this exposure?
A. Data in use.
B. Data at rest.
C. Data retention.
D. Data disposal.
A
A user attempts to email confidential customer records outside the organization.
Which control is MOST specifically designed to detect and prevent this type of data movement?
A. DLP.
B. DRM only.
C. UPS.
D. RAID.
A
A company wants an authorized user to read a confidential report but prevent printing and forwarding.
Which technology is MOST directly applicable?
A. DRM.
B. DLP only.
C. CASB only.
D. Antivirus.
A
Employees are uploading sensitive information to unsanctioned cloud applications.
Which technology can help enforce cloud-use security policy?
A. CASB.
B. RAID.
C. BIOS.
D. UPS.
A
Generally:
Owner determines requirements. Custodian implements them.
Public information may have low confidentiality but high integrity or availability requirements.
Ordinary file deletion may leave recoverable residual information.
Think:
Retention should be based on:
requirements;
business need.
Excess data creates additional risk.
Encryption does not determine:
classification;
retention;
authorized use;
disposal.
The owner is accountable for requirements.
Custodians or administrators typically implement technical controls.
Asset inventory may include:
tangible assets;
intangible assets;
information;
software;
licenses.
They are related but should be distinguished.
EOL concerns lifecycle retirement.
EOS concerns loss of vendor support.
DLP:
Controls data movement.
DRM:
Controls permitted content usage.
A CASB is a security-policy and visibility mechanism associated with cloud-service use.
Overclassification can:
increase cost;
reduce usability;
cause users to ignore labels.
Classification should reflect actual risk.
Use the SierraTec Secure PROTECT model for asset-security questions.
What information or resource exists?
How valuable, sensitive, or critical is it?
Who determines requirements?
Where is it now and where will it move?
How should it be stored, transmitted, and used?
Which safeguards apply?
How will the asset or data be retired and destroyed?
P
PINPOINT ASSET
β
βΌ
R
RATE SENSITIVITY
β
βΌ
O
OWNER
β
βΌ
T
TRACK LIFECYCLE
β
βΌ
E
ESTABLISH HANDLING
β
βΌ
C
CONTROL & PROTECT
β
βΌ
T
TERMINATE SECURELY
What should generally occur before selecting protection controls for information?
A. Identify and classify it.
B. Destroy it.
C. Transfer ownership.
D. Publish it.
A
Who is typically responsible for determining data classification?
A. Data owner.
B. Custodian.
C. Network switch.
D. External attacker.
A
Who typically implements protection requirements established by the owner?
A. Custodian.
B. Visitor.
C. Customer.
D. Competitor.
A
Which is an intangible asset?
A. Source code.
B. Server rack.
C. Laptop.
D. Building.
A
What is the primary purpose of an asset inventory?
A. Provide visibility into organizational assets.
B. Replace risk management.
C. Encrypt data.
D. Eliminate ownership.
A
What does data classification primarily determine?
A. Sensitivity and required protection.
B. Network speed.
C. Purchase price only.
D. CPU model.
A
Which classification level typically requires the strongest protection?
A. Restricted/highly sensitive.
B. Public.
C. Marketing.
D. Published.
A
What is data remanence?
A. Residual data remaining after deletion or attempted removal.
B. An authentication factor.
C. Network redundancy.
D. Cloud availability.
A
Which BEST describes data at rest?
A. Stored data.
B. Data traversing a network.
C. Data actively processed in memory.
D. Deleted data only.
A
Which BEST describes data in transit?
A. Information moving between systems or locations.
B. Stored backup information.
C. Archived paper.
D. Data deleted from disk.
A
Which BEST describes data in use?
A. Information actively processed or accessed.
B. Archived data.
C. Printed data only.
D. Destroyed data.
A
What is the main purpose of DRM?
A. Control permitted use of digital content.
B. Prevent hardware failure.
C. Manage network routing.
D. Replace authentication.
A
What is the main purpose of DLP?
A. Detect or prevent unauthorized data movement.
B. Provide electrical power.
C. Build applications.
D. Classify network packets only.
A
Which technology helps enforce security policy around cloud-service use?
A. CASB.
B. RAID.
C. BIOS.
D. UPS.
A
What is the primary risk associated with End of Support?
A. Security updates and support may no longer be available.
B. Data is automatically encrypted.
C. The asset becomes public.
D. Authentication is eliminated.
A
What is scoping?
A. Determining which assets and systems are subject to requirements.
B. Deleting controls.
C. Extending retention indefinitely.
D. Purchasing software.
A
What is tailoring?
A. Adjusting control implementation appropriately for the environment.
B. Ignoring requirements.
C. Removing all controls.
D. Encrypting everything identically.
A
Which role represents the individual to whom personal information relates?
A. Data subject.
B. Custodian.
C. Controller.
D. Auditor.
A
Which role commonly determines the purpose and means of personal-data processing under privacy frameworks using that terminology?
A. Controller.
B. User.
C. Custodian.
D. Help desk.
A
Which process should occur before a retired storage device containing sensitive information is reused or disposed of?
A. Appropriate sanitization.
B. Rename the files.
C. Move them to the recycle bin.
D. Change the desktop wallpaper.
A
An organization discovers thousands of sensitive files but cannot determine who is responsible for setting access requirements.
What is the MOST important governance weakness?
A. Lack of clearly assigned data ownership.
B. Lack of disk space.
C. Slow network routing.
D. Excessive printing.
A
A company labels almost every document βHighly Restricted.β
What is the GREATEST concern?
A. Overclassification may reduce usability and weaken meaningful handling distinctions.
B. Highly restricted data cannot be encrypted.
C. Public data no longer exists.
D. Classification always reduces security.
A
An employee deletes confidential files before selling an old laptop.
What should happen NEXT?
A. Sell immediately.
B. Apply approved sanitization appropriate to the data and media.
C. Rename the drive.
D. Remove shortcuts.
B
A payroll administrator decides which employees should have access to payroll records even though HR is designated as the data owner.
What is the PRIMARY concern?
A. Custodian is making an ownership decision.
B. Availability.
C. Network latency.
D. Encryption.
A
A critical application runs on an operating system that no longer receives vendor security updates.
What is the PRIMARY concern?
A. End-of-support risk.
B. Data classification.
C. Tokenization.
D. Copyright.
A
A highly sensitive database is encrypted at rest, but employees can export unencrypted records to personal cloud services.
What additional control would MOST directly address this risk?
A. DLP.
B. RAID.
C. UPS.
D. Load balancing.
A
The organization knows its sensitive information is stored in its primary database but does not know whether copies exist in backups, SaaS applications, or employee laptops.
Which Asset Security activity should receive priority?
A. Data-location discovery and inventory.
B. Patent filing.
C. Firewall replacement.
D. Physical relocation.
A
A user legitimately receives a sensitive report but should not forward or print it.
Which technology MOST directly addresses this requirement?
A. DRM.
B. CASB.
C. Load balancer.
D. IDS.
A
Employees are using several unsanctioned SaaS applications to store organizational information.
Which control can provide visibility and policy enforcement around cloud use?
A. CASB.
B. RAID.
C. DHCP.
D. UPS.
A
A legal hold is issued for records whose normal retention period expires tomorrow.
What should happen?
A. Preserve the relevant records according to the hold.
B. Delete them according to the normal schedule.
C. Send them to all users.
D. Reclassify them as public.
A
Something of value to an organization.
Asset having physical form.
Nonphysical asset such as data, software, or intellectual property.
Assignment of information to categories based on sensitivity or value.
Assignment of assets to categories based on criticality, sensitivity, or business importance.
Role accountable for determining information requirements.
Role accountable for an asset's business use and protection requirements.
Role determining purposes and means of personal-data processing where applicable.
Role implementing and maintaining controls.
Role processing information on behalf of another party under applicable arrangements.
Authorized user of organizational information.
Individual to whom personal information relates.
Structured record of organizational assets.
Rule defining how information may be stored, used, transmitted, copied, or disposed of.
Stages through which information progresses from creation or collection to destruction.
Period information is kept.
Residual information remaining after attempted removal or deletion.
Process intended to render access to targeted stored data infeasible at an appropriate level of effort.
Point at which a product reaches the end of its lifecycle.
Point after which normal vendor support or security updates are no longer provided.
Stored information.
Information moving between systems.
Information actively being processed.
Determining which assets and systems are subject to a requirement.
Authorized adjustment of control implementation for organizational circumstances.
Digital Rights Management; controls permitted use of digital content.
Data Loss Prevention; identifies and limits unauthorized movement or disclosure of sensitive information.
Cloud Access Security Broker; provides security-policy and visibility capabilities for cloud-service use.
Obscuring sensitive information while preserving a usable representation.
Replacing a sensitive value with a surrogate token.
Remember the sequence:
IDENTIFY
β
CLASSIFY
β
ASSIGN OWNER
β
ESTABLISH HANDLING
β
PROTECT
β
TRACK LOCATION
β
MAINTAIN
β
RETAIN
β
REVIEW
β
SANITIZE / DESTROY
For CISSP questions:
You cannot protect assets you have not identified.
Classification should reflect business value, sensitivity, and risk.
Public information can still require integrity and availability.
Owners determine protection requirements.
Custodians implement controls.
Inventories include tangible and intangible assets.
Classification should drive handling requirements.
Data location matters throughout the lifecycle.
Unnecessary data increases exposure.
Retention should be based on legitimate requirements.
Legal holds can override normal disposal schedules.
Normal deletion may leave data remanence.
Sanitization should match information sensitivity and media characteristics.
Current NIST guidance emphasizes enterprise sanitization programs and validation.
End-of-Life and End-of-Support assets require risk management.
Data at rest, in transit, and in use require different safeguards.
Scoping determines what is subject to requirements.
Tailoring adjusts implementation appropriately; it does not mean ignoring controls.
DRM governs permitted content use.
DLP focuses on unauthorized data movement.
CASB supports cloud-service governance and policy.
Encryption does not replace ownership, classification, retention, or disposal.
Asset security continues from acquisition through final disposition.
Lesson Seven introduced the complete Asset Security and Information Lifecycle Management foundation.
You learned that information security begins with identifying what the organization possesses.
The current CISSP Asset Security domain requires candidates to understand:
information and asset classification;
handling requirements;
ownership;
inventories;
asset management;
data roles;
collection;
location;
maintenance;
retention;
remanence;
destruction;
End of Life;
End of Support;
data states;
scoping;
tailoring;
standards selection;
DRM;
DLP;
CASB.
You learned the relationship:
ASSET
β
βΌ
VALUE
β
βΌ
CLASSIFICATION
β
βΌ
OWNER
β
βΌ
HANDLING REQUIREMENTS
β
βΌ
SECURITY CONTROLS
You examined data through its complete lifecycle:
COLLECT
β
CLASSIFY
β
STORE
β
USE
β
TRANSMIT
β
MAINTAIN
β
RETAIN
β
DESTROY
You also learned that simply pressing Delete does not necessarily eliminate information.
Data remanence may permit recovery from storage media.
Current NIST SP 800-88 Rev. 2 emphasizes an enterprise media-sanitization program, selection of appropriate methods based on information sensitivity, and verification that sanitization was successful.
The central Lesson Seven principle is:
Protection should follow the information throughout its lifecycleβfrom the moment it is created or acquired until the moment its authorized retention ends and its remaining copies are securely disposed of.
Before proceeding to Lesson Eight, make sure you can explain:
What an asset is.
Why asset identification comes before protection.
The difference between tangible and intangible assets.
What an asset inventory should accomplish.
What data classification means.
What asset classification means.
Why classification should be based on business impact.
Why public information may still need protection.
How classification drives handling requirements.
Who normally determines classification.
What a data owner does.
What an asset owner does.
What a custodian does.
What a controller does conceptually.
What a processor does.
What a data subject is.
Why secure provisioning matters.
Why unauthorized assets create risk.
The stages of the data lifecycle.
Why data collection should be limited.
Why data location matters.
What data maintenance means.
Why retention schedules exist.
Why excessive retention creates risk.
What data remanence means.
Why ordinary deletion is not necessarily sanitization.
What media sanitization accomplishes.
Why sanitization should be validated.
What EOL means.
What EOS means.
Why unsupported systems create security risk.
The difference between data at rest, in transit, and in use.
Controls commonly applied to each data state.
What scoping means.
What tailoring means.
Why scoping and tailoring are different.
What standards selection means.
What DRM does.
What DLP does.
What CASB does.
How DRM, DLP, and CASB differ.
What masking means.
What tokenization means.
Why asset-disposition procedures are part of cybersecurity.
Lesson Eight will begin CISSP Domain 3 β Security Architecture and Engineering.
This is where the protection mechanisms you asked about earlier will be developed in depth.
The lesson will cover:
security architecture;
secure-design principles;
abstraction;
data hiding;
encapsulation;
isolation;
process isolation;
memory protection;
security domains;
security boundaries;
trust boundaries;
protection rings;
reference monitor;
security kernel;
Trusted Computing Base;
hardware roots of trust;
Trusted Platform Module;
secure boot;
secure defaults;
fail securely;
economy of mechanism / keep it simple;
least privilege;
separation of duties;
defense in depth;
Zero Trust;
privacy by design;
shared responsibility;
Secure Access Service Edge;
system security capabilities;
architectural attack surfaces;
protection-mechanism comparisons;
original architecture diagrams;
CISSP scenario questions.
The central question for Lesson Eight will be:
How should systems be architected so that security is enforced by design rather than depending only on users, procedures, or individual security products?
This lesson is independently developed educational material for the SierraTec Secure CISSP Certification Preparation Course.
CISSP is administered by ISC2. SierraTec Secure's course is independent certification-preparation material and should not be represented as official ISC2 training unless separately authorized.
The principal examination alignment for this lesson was verified against the current CISSP Certification Exam Outline. Domain 2 explicitly covers information and asset classification, handling requirements, secure provisioning, ownership, tangible and intangible inventories, data roles and lifecycle, EOL/EOS, data states, scoping and tailoring, standards selection, and protection methods including DRM, DLP, and CASB.
The media-sanitization discussion was updated to reflect NIST SP 800-88 Rev. 2, published September 26, 2025, which superseded Revision 1 and emphasizes enterprise sanitization programs, information sensitivity, modern storage environments, and sanitization validation.
The SierraTec Secure PROTECT model, lesson structure, diagrams, examples, knowledge checks, and practice questions are original instructional content and are not actual, recalled, leaked, or official CISSP examination questions.