Lesson 7: Asset Security and Information Lifecycle Management

Lesson 8/28 | Study Time: 10 Min

Lesson Seven

Asset Security and Information Lifecycle Management

SierraTec Secure CISSP Certification Preparation Course


Lesson Overview

An organization cannot effectively protect information and technology unless it first understands:

  • what assets it possesses;

  • where those assets are located;

  • how important they are;

  • who owns them;

  • who is permitted to use them;

  • how sensitive the information is;

  • how the information should be handled;

  • how long it should be retained;

  • how it should be protected throughout its lifecycle;

  • when it should be retired or destroyed.

This is the foundation of Asset Security, CISSP Domain 2.

The current CISSP examination outline assigns 10% of the examination to Asset Security and divides the domain into six major objectives:

  1. identify and classify information and assets;

  2. establish information and asset handling requirements;

  3. provision information and assets securely;

  4. manage the data lifecycle;

  5. ensure appropriate asset retention, including End of Life and End of Support;

  6. determine appropriate data-security controls and compliance requirements.

The current outline explicitly includes data classification, asset classification, ownership, inventories, tangible and intangible assets, data roles, collection, location, maintenance, retention, remanence, destruction, data states, scoping, tailoring, standards selection, Digital Rights Management, Data Loss Prevention, and Cloud Access Security Brokers.

The central question for Lesson Seven is:

What information and assets does the organization possess, how valuable or sensitive are they, who is responsible for them, and how should protection follow them throughout their lifecycle?


CISSP Exam Objective Alignment

Lesson TopicCISSP Objective
Information identification2.1
Data classification2.1
Asset classification2.1
Handling requirements2.2
Secure provisioning2.3
Information ownership2.3
Asset ownership2.3
Tangible asset inventory2.3
Intangible asset inventory2.3
Asset management2.3
Data owners2.4
Controllers2.4
Custodians2.4
Processors2.4
Users / subjects2.4
Data collection2.4
Data location2.4
Data maintenance2.4
Data retention2.4
Data remanence2.4
Data destruction2.4
End of Life2.5
End of Support2.5
Data at rest2.6
Data in transit2.6
Data in use2.6
Scoping2.6
Tailoring2.6
Standards selection2.6
Digital Rights Management2.6
Data Loss Prevention2.6
Cloud Access Security Broker2.6

These topics are explicitly contained in the current Domain 2 examination objectives.


Learning Objectives

After completing this lesson, you should be able to:

  1. Define an organizational asset.

  2. Distinguish information assets from physical and technological assets.

  3. Distinguish tangible from intangible assets.

  4. Explain why asset identification must precede appropriate protection.

  5. Define data classification.

  6. Define asset classification.

  7. Explain how value, sensitivity, criticality, and business impact influence classification.

  8. Develop an example classification hierarchy.

  9. Explain why classification schemes should be understandable and manageable.

  10. Explain the relationship between classification and handling requirements.

  11. Describe handling requirements for storing, transmitting, printing, copying, sharing, and disposing of information.

  12. Explain information ownership.

  13. Explain system and asset ownership.

  14. Explain the role of asset inventories.

  15. Describe secure asset provisioning.

  16. Distinguish asset owner, data owner, controller, custodian, processor, user, and data subject.

  17. Explain the complete information lifecycle.

  18. Explain why data collection should be controlled.

  19. Explain the importance of knowing data location.

  20. Describe data maintenance requirements.

  21. Explain retention requirements.

  22. Define data remanence.

  23. Explain why normal deletion may not securely remove information.

  24. Explain sanitization and secure destruction.

  25. Explain End of Life and End of Support risks.

  26. Distinguish data at rest, in transit, and in use.

  27. Select appropriate controls according to data state.

  28. Explain scoping and tailoring.

  29. Explain standards selection.

  30. Define Digital Rights Management.

  31. Define Data Loss Prevention.

  32. Define Cloud Access Security Broker.

  33. Explain how DRM, DLP, and CASB differ.

  34. Explain data masking, tokenization, and encryption at an introductory level.

  35. Apply asset-security principles to CISSP-style scenarios.

  36. Recognize common examination traps involving ownership, classification, retention, and disposal.


Part I β€” Understanding Assets

1. What Is an Asset?

An asset is anything that has value to an organization or its stakeholders.

Assets may support:

  • revenue;

  • operations;

  • legal obligations;

  • customer relationships;

  • safety;

  • intellectual property;

  • organizational mission.

Examples include:

  • databases;

  • servers;

  • cloud services;

  • laptops;

  • customer records;

  • source code;

  • contracts;

  • cryptographic keys;

  • manufacturing equipment;

  • intellectual property;

  • employee knowledge.


2. Asset Security

Asset security concerns the identification, classification, ownership, handling, protection, retention, and disposition of organizational information and assets.

Asset security asks:

What do we have?

Why does it matter?

Who owns it?

How sensitive or critical is it?

How should it be handled?

How long should it exist?

How should it be destroyed?


3. The Asset Security Lifecycle

IDENTIFY
β”‚
β–Ό
CLASSIFY
β”‚
β–Ό
ASSIGN OWNER
β”‚
β–Ό
PROVISION
β”‚
β–Ό
PROTECT
β”‚
β–Ό
USE / MAINTAIN
β”‚
β–Ό
RETAIN
β”‚
β–Ό
REVIEW
β”‚
β–Ό
RETIRE
β”‚
β–Ό
SANITIZE / DESTROY

Asset security is therefore a lifecycle activity.


4. Why Identification Comes First

Consider this question:

How should an organization protect confidential intellectual property if it does not know the information exists?

It cannot.

Likewise:

How can an organization patch an unknown server?

It cannot.

How can it terminate a forgotten cloud account?

It cannot.

Therefore:

You cannot effectively protect what you do not know you possess.


5. Asset Inventory

An asset inventory provides visibility into organizational resources.

A useful inventory may include:

  • asset identifier;

  • description;

  • owner;

  • location;

  • classification;

  • status;

  • criticality;

  • lifecycle stage;

  • support status.


6. Example Asset Inventory

Asset IDAssetOwnerClassificationLocationStatus
A-001Payroll DBHR DirectorConfidentialCloud Region AProduction
A-002Public WebsiteMarketingPublicCloud Region BProduction
A-003Domain ControllerCIOCriticalData CenterProduction
A-004Old LaptopFinanceConfidentialStoragePending disposal

The inventory should support security decisions rather than exist merely for audit purposes.


Part II β€” Tangible and Intangible Assets

7. Tangible Assets

Tangible assets have physical form.

Examples:

  • laptops;

  • servers;

  • smartphones;

  • storage devices;

  • routers;

  • buildings;

  • backup media.


8. Intangible Assets

Intangible assets do not necessarily have a physical form.

Examples:

  • data;

  • software;

  • intellectual property;

  • reputation;

  • source code;

  • credentials;

  • business processes;

  • licenses.

The current CISSP outline explicitly includes both tangible and intangible assets in asset inventory and management.


9. Asset Comparison

TangibleIntangible
LaptopCustomer database
ServerSource code
BuildingBrand reputation
Backup tapeEncryption key
Network switchSoftware license

A physical device may have low replacement cost while containing extremely high-value information.


10. Asset Value Is More Than Purchase Price

A laptop may cost:

$1,500.

But if it contains:

  • trade secrets;

  • customer information;

  • cryptographic keys;

the organizational impact of compromise may be far greater than the hardware's purchase price.

Therefore:

Asset value should be evaluated in business context.


Part III β€” Information Classification

11. What Is Data Classification?

Data classification assigns information to categories based on characteristics such as:

  • sensitivity;

  • value;

  • confidentiality;

  • criticality;

  • legal requirements.

Classification helps determine appropriate protection.


12. Why Classify Data?

Without classification, organizations may:

  • overprotect public information;

  • underprotect sensitive information;

  • apply inconsistent controls;

  • waste resources.

Classification provides a rational basis for protection.


13. Example Commercial Classification Scheme

A private-sector organization might use:

       RESTRICTED
β–²
CONFIDENTIAL
β–²
INTERNAL
β–²
PUBLIC

Higher levels generally require stronger controls.


14. Public

Public information is intended for general disclosure.

Examples:

  • published press releases;

  • public website content;

  • approved marketing materials.

Confidentiality requirements may be low.

Integrity can still matter greatly.

An attacker who changes a company's public website can cause reputational harm.


15. Internal

Internal information is intended primarily for organizational use.

Examples:

  • routine internal communications;

  • internal procedures;

  • staff directories.

Unauthorized public disclosure may create limited or moderate harm.


16. Confidential

Confidential information could cause significant harm if disclosed improperly.

Examples:

  • employee records;

  • customer information;

  • contracts;

  • financial reports.

Controls may include:

  • access restrictions;

  • encryption;

  • monitoring;

  • secure transmission.


17. Restricted / Highly Sensitive

The highest category may contain information whose compromise could result in severe harm.

Examples:

  • cryptographic root keys;

  • merger plans;

  • high-value intellectual property;

  • highly sensitive investigative information.

Protection may involve:

  • strict need to know;

  • privileged access controls;

  • enhanced monitoring;

  • strong encryption;

  • limited distribution.


18. Classification Example

LevelExampleTypical Protection
PublicMarketing brochureIntegrity controls
InternalInternal memoEmployee access
ConfidentialPayrollEncryption + restricted access
RestrictedRoot cryptographic keyHSM / strict control

Exact names differ among organizations.

CISSP questions typically focus on the principle, not one universal naming convention.


19. Classification Criteria

Organizations may classify information based on:

  • sensitivity;

  • business impact;

  • privacy;

  • regulatory requirements;

  • financial impact;

  • operational importance.


20. Classification Should Be Manageable

A classification scheme with 25 nearly identical categories may be difficult to use correctly.

Effective classification should be:

  • understandable;

  • consistent;

  • enforceable;

  • aligned with business requirements.


21. Classification Lifecycle

Classification should not necessarily remain unchanged forever.

DATA CREATED
β”‚
β–Ό
CLASSIFIED
β”‚
β–Ό
USED
β”‚
β–Ό
REVIEWED
β”‚
β–Ό
STILL SAME SENSITIVITY?
β”Œβ”€β”€β”€β”€β”΄β”€β”€β”€β”€β”
YES NO
β”‚ β”‚
KEEP RECLASSIFY

Example:

A confidential acquisition plan may become public after the acquisition is officially announced.


Part IV β€” Asset Classification

22. Data Classification Versus Asset Classification

Data classification focuses on information.

Asset classification considers the importance or sensitivity of broader assets.

Data ClassificationAsset Classification
Focuses on informationFocuses on broader organizational asset
Payroll = ConfidentialPayroll server = Critical
Contract = RestrictedContract repository = High Criticality

23. Asset Criticality

An asset can be critical because of:

  • business dependency;

  • safety consequences;

  • availability requirements;

  • legal obligations;

  • financial impact.


24. Example

Two identical servers may have very different classification.

Server A:

Development test server.

Server B:

Emergency communications server.

Same technology.

Different business importance.

Therefore:

Technical similarity does not imply equal criticality.


Part V β€” Information and Asset Ownership

25. Why Ownership Matters

Every important information set or asset should have an accountable owner.

Without ownership:

  • classification may be unclear;

  • access decisions may be inconsistent;

  • retention may be undefined;

  • risks may remain unresolved.


26. Data Owner

The data owner is typically responsible for determining requirements regarding the information.

Responsibilities may include:

  • classification;

  • authorized access;

  • protection requirements;

  • retention;

  • acceptable use.

Memory aid:

Owner decides.


27. Asset Owner

An asset owner is accountable for the asset's organizational use and protection requirements.

Examples:

  • application owner;

  • system owner;

  • business-process owner.


28. Custodian

The custodian implements and operates protections.

Examples:

  • database administrator;

  • cloud administrator;

  • storage administrator.

Memory aid:

Owner decides. Custodian implements.


Part VI β€” Data Roles

The current CISSP Domain 2 outline specifically identifies:

  • owners;

  • controllers;

  • custodians;

  • processors;

  • users / subjects

as important data-lifecycle roles.


29. Data Owner

The data owner determines organizational requirements for information.

Typical responsibilities:

  • classification;

  • access criteria;

  • protection expectations;

  • retention.


30. Data Controller

In privacy frameworks using this terminology, a controller generally determines:

  • why personal information is processed;

  • how processing occurs.

The exact legal meaning depends on the applicable privacy regime.


31. Data Custodian

The custodian performs operational protection.

Examples:

  • maintaining databases;

  • implementing backup;

  • applying encryption;

  • administering permissions.


32. Data Processor

A processor processes personal information on behalf of another entity under an applicable arrangement.

Example:

A cloud payroll provider may process employee information for an employer.


33. User

A user accesses or uses organizational information according to authorization.

Responsibilities may include:

  • following policy;

  • protecting credentials;

  • handling data appropriately.


34. Data Subject

A data subject is the individual to whom personal information relates under privacy frameworks using this term.

Example:

An employee whose personnel information appears in an HR database.


35. Role Comparison

RolePrimary Function
OwnerDetermines requirements
ControllerDetermines purpose/means of processing
CustodianImplements and maintains controls
ProcessorProcesses on behalf of another party
UserAuthorized information user
Data SubjectIndividual represented by personal data

Part VII β€” Information Handling Requirements

36. Classification Must Lead to Handling

Classification has little value if it does not affect behavior.

Example:

Marking a document:

CONFIDENTIAL

but allowing it to be:

  • emailed publicly;

  • copied freely;

  • left unattended;

makes the classification meaningless.


37. Handling Lifecycle

CLASSIFICATION
β”‚
β–Ό
ACCESS RULES
β”‚
β–Ό
STORAGE RULES
β”‚
β–Ό
TRANSMISSION RULES
β”‚
β–Ό
USE / COPYING RULES
β”‚
β–Ό
RETENTION
β”‚
β–Ό
DISPOSAL

38. Handling Requirements

Handling rules may address:

  • access;

  • storage;

  • printing;

  • copying;

  • transmission;

  • sharing;

  • labeling;

  • backup;

  • disposal.


39. Handling Matrix Example

ClassificationEmailStoragePrintingDisposal
PublicAllowedStandardAllowedStandard
InternalInternal channelsManaged systemsControlledApproved disposal
ConfidentialProtected channelEncryptedRestrictedSecure sanitization
RestrictedStrong protectionHighly controlledLimitedVerified destruction

Part VIII β€” Secure Provisioning

40. Provisioning Assets

Provisioning is the process of preparing and assigning an asset for authorized use.

Examples:

  • issuing a laptop;

  • creating a cloud database;

  • deploying a server;

  • provisioning a software license.


41. Secure Provisioning

Secure provisioning may include:

  • inventory registration;

  • ownership assignment;

  • classification;

  • approved configuration;

  • encryption;

  • endpoint protection;

  • access controls;

  • logging.


42. Provisioning Flow

ASSET ACQUIRED
β”‚
β–Ό
REGISTER IN INVENTORY
β”‚
β–Ό
ASSIGN OWNER
β”‚
β–Ό
CLASSIFY
β”‚
β–Ό
APPLY BASELINE
β”‚
β–Ό
APPLY SECURITY CONTROLS
β”‚
β–Ό
AUTHORIZE USE
β”‚
β–Ό
MONITOR

43. Secure Laptop Example

A newly purchased laptop should not simply be handed to an employee.

Appropriate provisioning might include:

  • asset tag;

  • inventory record;

  • secure operating-system baseline;

  • encryption;

  • endpoint security;

  • approved applications;

  • authentication controls.


Part IX β€” Asset Management

44. Asset Management Is Continuous

Assets change.

They may be:

  • purchased;

  • reassigned;

  • upgraded;

  • moved;

  • retired.

Asset inventory should reflect these changes.


45. Asset Inventory Questions

For every important asset, ask:

  • What is it?

  • Who owns it?

  • Where is it?

  • What does it contain?

  • How critical is it?

  • What is its support status?

  • Who has access?

  • When should it be retired?


46. Unauthorized Assets

Unknown or unauthorized assets create risk.

Examples:

  • shadow IT;

  • personal cloud accounts;

  • unmanaged laptops;

  • unauthorized software.

These assets may bypass:

  • patching;

  • logging;

  • inventory;

  • backup;

  • monitoring.


Part X β€” Data Lifecycle

47. The Data Lifecycle

The current CISSP outline explicitly requires candidates to manage:

  • collection;

  • location;

  • maintenance;

  • retention;

  • remanence;

  • destruction.

A broader instructional model is:

COLLECT / CREATE
β”‚
β–Ό
CLASSIFY
β”‚
β–Ό
STORE
β”‚
β–Ό
USE / PROCESS
β”‚
β–Ό
SHARE / TRANSMIT
β”‚
β–Ό
MAINTAIN
β”‚
β–Ό
RETAIN / ARCHIVE
β”‚
β–Ό
DESTROY

Security must follow data throughout the lifecycle.


Part XI β€” Data Collection

48. Collect Only What Is Needed

Data collection should have:

  • defined purpose;

  • ownership;

  • classification;

  • security requirements.

Collecting unnecessary information creates unnecessary risk.


49. Collection Example

An application needs:

  • name;

  • email.

But also collects:

  • government ID;

  • date of birth;

  • detailed location;

without legitimate need.

This increases:

  • privacy exposure;

  • breach impact;

  • storage burden.


Part XII β€” Data Location

50. Know Where Data Exists

Data may exist in:

  • databases;

  • laptops;

  • backups;

  • SaaS platforms;

  • email;

  • cloud storage;

  • mobile devices.

If the organization does not know where data exists, it cannot reliably:

  • protect it;

  • delete it;

  • respond to breaches.


51. Data Location Diagram

                    CUSTOMER DATA
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β–Ό β–Ό β–Ό
DATABASE BACKUP SaaS
β”‚ β”‚ β”‚
β–Ό β–Ό β–Ό
DATA CENTER CLOUD PROVIDER
β”‚
β–Ό
ADMIN LAPTOP

One information set may exist in many locations.


52. Data Sprawl

Data sprawl occurs when information is copied across many systems without adequate governance.

Examples:

  • duplicate spreadsheets;

  • old backups;

  • personal cloud drives;

  • email attachments.

More copies generally mean:

More locations requiring protection.


Part XIII β€” Data Maintenance

53. Data Maintenance

Data maintenance involves keeping information:

  • accurate;

  • available;

  • appropriately protected;

  • usable.

Maintenance may include:

  • updating records;

  • correcting errors;

  • validating integrity;

  • adjusting permissions.


54. Maintenance and Integrity

Poorly maintained information may become inaccurate.

Example:

An employee leaves the organization but remains listed as an active privileged user.

The information may no longer reflect reality.

This can become a security risk.


Part XIV β€” Data Retention

55. What Is Retention?

Retention is the period during which information must or should be preserved.

Retention may depend on:

  • business need;

  • law;

  • regulation;

  • contract;

  • investigation;

  • privacy requirements.


56. Retention Principle

Keeping data forever is usually not a good default.

More retained data creates:

  • greater breach exposure;

  • storage cost;

  • legal discovery burden;

  • privacy risk.


57. Retention Schedule

A retention schedule specifies:

  • data category;

  • retention period;

  • authority;

  • disposition method.


58. Example Retention Schedule

InformationRetentionReasonDisposition
Tax recordDefined legal periodLegalSecure disposal
Security logsBusiness/security periodInvestigationSanitization
Applicant resumeDefined HR periodBusiness/legalSecure deletion
Temporary reportShort periodOperationalDelete

Specific periods depend on applicable requirements.


59. Retention Decision Flow

DATA EXISTS
β”‚
β–Ό
IS RETENTION REQUIRED?
β”Œβ”€β”€β”΄β”€β”€β”€β”
YES NO
β”‚ β”‚
β–Ό β–Ό
RETAIN BUSINESS NEED?
β”‚
β”Œβ”€β”€β”€β”΄β”€β”€β”€β”
YES NO
β”‚ β”‚
RETAIN DISPOSE

60. Legal Hold Overrides Routine Destruction

As discussed in Lesson Six, information subject to an authorized legal hold may need to be preserved even if the normal retention period has expired.

Therefore:

Do not automatically delete information simply because the normal schedule says its retention period has ended.


Part XV β€” Data Remanence

61. What Is Data Remanence?

Data remanence is residual information remaining on storage media after normal deletion or attempted removal.

Example:

Deleting a file may remove its directory reference while leaving recoverable information on the storage medium.


62. Deletion Is Not Always Destruction

FILE EXISTS
β”‚
β–Ό
USER PRESSES DELETE
β”‚
β–Ό
DIRECTORY REFERENCE REMOVED
β”‚
β–Ό
DATA MAY STILL EXIST
ON STORAGE MEDIA

This distinction is central to secure disposal.


63. Why Remanence Matters

Residual data can expose:

  • passwords;

  • personal information;

  • financial information;

  • intellectual property;

  • cryptographic material.


Part XVI β€” Media Sanitization

64. What Is Sanitization?

Media sanitization aims to make access to targeted data infeasible at an appropriate level of effort.

Current NIST SP 800-88 Rev. 2, published in September 2025, emphasizes establishing an enterprise sanitization program, matching sanitization decisions to information sensitivity, validating sanitization, and addressing modern environments including logical/cloud storage.


65. Sanitization Must Match the Risk

The correct method depends on:

  • information sensitivity;

  • media type;

  • reuse plans;

  • regulatory requirements;

  • threat model.


66. Sanitization Approaches

Common approaches may include:

Clear

Use logical techniques appropriate for reuse under defined conditions.

Purge

Use stronger techniques intended to make recovery significantly more difficult.

Cryptographic Erase

Destroy appropriate encryption keys so previously encrypted information becomes inaccessible when conditions are properly satisfied.

Physical Destruction

Physically render the media unusable when required.

Current NIST guidance emphasizes approved sanitization standards, validation, and enterprise program governance rather than relying only on simplistic one-size-fits-all techniques.


67. Media Sanitization Decision

MEDIA READY FOR DISPOSITION
β”‚
β–Ό
WHAT DATA IS PRESENT?
β”‚
β–Ό
HOW SENSITIVE?
β”‚
β–Ό
WILL MEDIA BE REUSED?
β”Œβ”€β”€β”΄β”€β”€β”€β”
YES NO
β”‚ β”‚
β–Ό β–Ό
APPROVED SANITIZE /
SANITIZE DESTROY
β”‚ β”‚
β””β”€β”€β”€β”¬β”€β”€β”€β”˜
β–Ό
VALIDATE
β”‚
β–Ό
DOCUMENT

68. Validation Matters

A sanitization process should not simply assume success.

Organizations may need to verify that the selected process operated correctly.

This is especially important for highly sensitive information.


Part XVII β€” Data Destruction

69. Destruction

Data destruction should ensure information is no longer recoverable to an unacceptable degree.

Possible methods depend on:

  • media;

  • sensitivity;

  • approved organizational standards.


70. Physical Media Examples

Media may include:

  • hard drives;

  • SSDs;

  • USB devices;

  • backup tapes;

  • optical media;

  • smartphones.

Different storage technologies may require different sanitization approaches.


71. Cloud Destruction

Cloud introduces additional complexity.

The customer may not physically control the storage medium.

Therefore, the organization should understand:

  • provider deletion mechanisms;

  • encryption-key management;

  • replication;

  • backups;

  • contractual requirements.


Part XVIII β€” Asset Retention

72. Asset Retention

Domain 2.5 requires appropriate asset retention and explicitly includes:

  • End of Life;

  • End of Support.

Asset retention asks:

Should this technology still be in service?


73. End of Life β€” EOL

End of Life generally refers to the point at which a product reaches the end of its intended lifecycle.

The vendor may:

  • stop selling it;

  • transition customers;

  • stop development.


74. End of Support β€” EOS

End of Support indicates the vendor no longer provides normal support.

This may include cessation of:

  • security patches;

  • fixes;

  • technical assistance.


75. Why Unsupported Technology Is Risky

Unsupported technology may develop vulnerabilities that no longer receive remediation.

This can create:

  • security exposure;

  • compliance problems;

  • compatibility issues;

  • operational risk.


76. EOL/EOS Decision Flow

ASSET IN USE
β”‚
β–Ό
SUPPORTED?
β”Œβ”€β”€β”΄β”€β”€β”€β”
YES NO
β”‚ β”‚
USE ASSESS RISK
β”‚
β–Ό
REPLACE?
β”Œβ”€β”€β”€β”€β”΄β”€β”€β”€β”€β”
YES NO
β”‚ β”‚
MIGRATE COMPENSATING
CONTROLS +
APPROVAL +
PLAN

77. Unsupported Does Not Mean Ignore

If immediate replacement is impossible:

  • document risk;

  • restrict exposure;

  • apply compensating controls;

  • plan migration.


Part XIX β€” Data States

78. Three Data States

The CISSP outline explicitly identifies:

  • data at rest;

  • data in transit;

  • data in use.


79. Data at Rest

Data at rest is stored information not actively traversing a communication channel.

Examples:

  • database records;

  • files;

  • backups;

  • storage volumes.


80. Data-at-Rest Controls

Possible controls:

  • encryption;

  • access control;

  • disk protection;

  • physical protection;

  • key management.


81. Data in Transit

Data in transit is moving between systems, locations, or users.

Examples:

  • web traffic;

  • email;

  • API communications;

  • database replication.


82. Data-in-Transit Controls

Possible safeguards:

  • TLS;

  • VPN;

  • authenticated protocols;

  • secure tunnels;

  • network controls.

Detailed cryptography and secure protocols will be taught later.


83. Data in Use

Data in use is actively being processed or accessed.

Examples:

  • information loaded into memory;

  • open application records;

  • decrypted documents in use.


84. Data-in-Use Challenges

Encryption at rest does not necessarily protect information after an authorized application decrypts it.

Controls may include:

  • access control;

  • process isolation;

  • memory protection;

  • endpoint security;

  • least privilege.


85. Data-State Diagram

                 DATA
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β–Ό β–Ό β–Ό
AT REST IN TRANSIT IN USE
β”‚ β”‚ β”‚
β–Ό β–Ό β–Ό
Encryption TLS Access Control
Storage ACL VPN Memory Protection
Physical Secure Endpoint Security
Security Channel

Part XX β€” Controls Should Follow the Data

86. Data Moves

Information may move from:

DATABASE
β”‚
β–Ό
APPLICATION
β”‚
β–Ό
NETWORK
β”‚
β–Ό
USER DEVICE
β”‚
β–Ό
CLOUD STORAGE

Protection should follow the information rather than relying only on the original system.


Part XXI β€” Scoping

87. What Is Scoping?

Scoping determines which systems, information, assets, and processes are subject to particular requirements.

Example:

A payment-card standard may apply specifically to systems within the cardholder-data environment.


88. Why Scope Matters

If scope is too narrow:

Important systems may be excluded.

If scope is unnecessarily broad:

Resources may be wasted protecting systems beyond the applicable requirement.


89. Scoping Questions

Ask:

  • What information is involved?

  • Which systems process it?

  • Which systems store it?

  • Which networks transmit it?

  • Which third parties handle it?

  • Which dependencies could affect it?


Part XXII β€” Tailoring

90. What Is Tailoring?

Tailoring adjusts control implementation to fit the organization's:

  • environment;

  • mission;

  • technology;

  • risk;

  • legal requirements.

Tailoring does not mean:

Ignore controls you dislike.

It means:

Adapt requirements through an authorized, risk-based process.


91. Scoping Versus Tailoring

ScopingTailoring
Determines what is includedDetermines how controls are appropriately applied
Defines boundaryAdjusts implementation
β€œWhat is in scope?β€β€œHow should this fit our environment?”

Part XXIII β€” Standards Selection

92. Select Standards Based on Requirements

The current Domain 2 outline requires candidates to understand standards selection.

Organizations should select standards based on:

  • industry;

  • jurisdiction;

  • business requirements;

  • contractual obligations;

  • risk.


93. Avoid Framework Shopping

Poor approach:

β€œUse a standard because competitors mention it.”

Better approach:

Determine requirements and select the standard that appropriately supports them.


Part XXIV β€” Data Protection Methods

94. Protection Is Layered

Data protection may involve:

  • access control;

  • encryption;

  • DRM;

  • DLP;

  • CASB;

  • masking;

  • tokenization;

  • monitoring.


Part XXV β€” Digital Rights Management

95. What Is DRM?

Digital Rights Management controls the permitted use of digital information or content.

DRM may restrict:

  • copying;

  • printing;

  • forwarding;

  • editing;

  • access duration.


96. DRM Example

A confidential document may allow the authorized employee to:

  • read it;

but prevent:

  • printing;

  • forwarding;

  • copying.


97. DRM Focus

DRM focuses on:

What can an authorized recipient do with the content?


Part XXVI β€” Data Loss Prevention

98. What Is DLP?

Data Loss Prevention technologies and processes attempt to identify and prevent unauthorized exposure or movement of sensitive information.

DLP may inspect:

  • email;

  • endpoints;

  • network traffic;

  • cloud uploads.


99. DLP Example

An employee attempts to email a spreadsheet containing thousands of customer records to a personal email account.

A DLP system may:

  • detect sensitive information;

  • block transmission;

  • generate an alert.


100. DLP Concept

SENSITIVE DATA
β”‚
β–Ό
USER ATTEMPTS TRANSFER
β”‚
β–Ό
DLP INSPECTION
β”‚
β–Ό
POLICY MATCH?
β”Œβ”€β”€β”€β”€β”΄β”€β”€β”€β”€β”
YES NO
β”‚ β”‚
BLOCK / ALLOW
ALERT

101. DLP Limitations

DLP is not magic.

Effectiveness depends on:

  • accurate classification;

  • policies;

  • coverage;

  • tuning;

  • monitoring.


Part XXVII β€” Cloud Access Security Broker

102. What Is a CASB?

A Cloud Access Security Broker helps organizations apply security policy and visibility around the use of cloud services.

CASB is explicitly included by ISC2 as a Domain 2 data-protection method.

NIST also recognizes CASB terminology in its cybersecurity glossary.


103. CASB Functions

Depending on the solution, a CASB may help with:

  • cloud-service visibility;

  • policy enforcement;

  • access control;

  • data protection;

  • activity monitoring;

  • cloud-risk management.


104. CASB Example

Employee attempts:

CORPORATE DEVICE
β”‚
β–Ό
UPLOAD CONFIDENTIAL FILE
β”‚
β–Ό
UNAPPROVED CLOUD SERVICE
β”‚
β–Ό
CASB POLICY
β”‚
β–Ό
BLOCK / ALERT

Part XXVIII β€” DRM, DLP, and CASB Comparison

105. Comparison Table

TechnologyMain FocusExample
DRMControl permitted use of contentPrevent printing
DLPPrevent unauthorized data movementBlock sensitive email
CASBGovern cloud-service useBlock upload to unsanctioned SaaS

These controls can complement one another.


Part XXIX β€” Encryption

106. Encryption and Asset Security

Encryption can help protect:

  • data at rest;

  • data in transit.

But encryption effectiveness depends on:

  • algorithm;

  • implementation;

  • key management;

  • authorized access.

Detailed cryptography will be covered in Lesson Ten.


Part XXX β€” Masking

107. Data Masking

Masking obscures sensitive information while preserving a usable representation.

Example:

Credit Card:
4587-2299-1034-8821

Masked:
****-****-****-8821

108. Masking Use Case

A customer-service employee may need:

Last four digits.

They may not require:

Full payment-card number.

Masking can reduce unnecessary exposure.


Part XXXI β€” Tokenization

109. Tokenization

Tokenization replaces sensitive values with surrogate values called tokens.

Example:

ORIGINAL
4111 1111 1111 1111

↓

TOKEN
TKN-94F8-221A

The sensitive original remains protected separately.


110. Tokenization Versus Encryption

At a high level:

EncryptionTokenization
Transforms data using cryptographyReplaces value with surrogate token
Reversible with appropriate keyMapping or token system recovers original
Cryptographic mechanismData-substitution approach

Detailed distinctions will be expanded later.


Part XXXII β€” Asset Disposal

111. Disposal Is Part of Security

Organizations often protect assets carefully while they are in production but forget them during disposal.

An abandoned hard drive may contain:

  • credentials;

  • customer information;

  • source code.


112. Secure Disposal Flow

ASSET RETIRED
β”‚
β–Ό
CHECK RETENTION REQUIREMENTS
β”‚
β–Ό
BACKUP REQUIRED DATA
β”‚
β–Ό
REMOVE ACCOUNTS / KEYS
β”‚
β–Ό
SANITIZE MEDIA
β”‚
β–Ό
VALIDATE
β”‚
β–Ό
DESTROY / REUSE
β”‚
β–Ό
UPDATE INVENTORY

Part XXXIII β€” Asset Lifecycle Case Study

113. Case Study: Executive Laptop

An executive laptop reaches replacement age.

It contains:

  • customer data;

  • contracts;

  • cached email;

  • VPN credentials.

The employee receives a new device.

What should happen to the old laptop?

A. Sell it immediately.

B. Delete visible files and give it away.

C. Follow approved sanitization and asset-disposition procedures.

D. Leave it in storage indefinitely.

Correct Answer

C


114. Why?

Normal deletion may leave recoverable data.

Asset disposition should follow:

  • classification;

  • sanitization requirements;

  • inventory procedures.


Part XXXIV β€” Classification Case Studies

115. Scenario β€” Public Data

A marketing department publishes an approved brochure.

Which security objective may still be highly important even though confidentiality is low?

A. Integrity.

B. Confidentiality only.

C. Nonrepudiation only.

D. None.

Correct Answer

A

Public information should not be modified by unauthorized parties.


116. Scenario β€” Merger Documents

A confidential merger proposal is being developed.

What should primarily determine access?

A. Employee seniority alone.

B. Classification, business need, and authorization.

C. Whoever asks first.

D. Whether the employee owns a laptop.

Correct Answer

B


Part XXXV β€” Ownership Scenarios

117. Scenario β€” Access Decision

A database administrator receives a request from an employee asking for access to confidential HR records.

Who should generally determine whether the access is appropriate?

A. Data owner or authorized business authority.

B. Database administrator alone.

C. Any user.

D. Hardware vendor.

Correct Answer

A

The custodian implements the decision.


118. Scenario β€” Classification

Who is typically accountable for determining the appropriate classification of business information?

A. Data owner.

B. Custodian.

C. Help desk.

D. Visitor.

Correct Answer

A


Part XXXVI β€” Data-State Scenarios

119. Scenario β€” Data at Rest

A company wants to protect sensitive information stored on employee laptops if devices are stolen.

Which control is MOST directly appropriate?

A. Full-disk encryption.

B. Email filtering.

C. Load balancing.

D. DNSSEC.

Correct Answer

A


120. Scenario β€” Data in Transit

Sensitive information is transmitted between an application and a remote service.

Which control is MOST directly appropriate?

A. Secure encrypted communication protocol.

B. Locked filing cabinet.

C. Screen filter.

D. Paper shredder.

Correct Answer

A


121. Scenario β€” Data in Use

An authorized application has decrypted highly sensitive information into memory.

Which concept MOST directly recognizes this exposure?

A. Data in use.

B. Data at rest.

C. Data retention.

D. Data disposal.

Correct Answer

A


Part XXXVII β€” DLP / DRM / CASB Scenarios

122. Scenario β€” Email

A user attempts to email confidential customer records outside the organization.

Which control is MOST specifically designed to detect and prevent this type of data movement?

A. DLP.

B. DRM only.

C. UPS.

D. RAID.

Correct Answer

A


123. Scenario β€” Document Restrictions

A company wants an authorized user to read a confidential report but prevent printing and forwarding.

Which technology is MOST directly applicable?

A. DRM.

B. DLP only.

C. CASB only.

D. Antivirus.

Correct Answer

A


124. Scenario β€” Unauthorized Cloud

Employees are uploading sensitive information to unsanctioned cloud applications.

Which technology can help enforce cloud-use security policy?

A. CASB.

B. RAID.

C. BIOS.

D. UPS.

Correct Answer

A


Part XXXVIII β€” Common CISSP Exam Traps

125. Trap β€” Custodian Classifies the Data

Generally:

Owner determines requirements. Custodian implements them.


126. Trap β€” Public Means No Security

Public information may have low confidentiality but high integrity or availability requirements.


127. Trap β€” Delete Means Destroy

Ordinary file deletion may leave recoverable residual information.

Think:

Data Remanence


128. Trap β€” Keep Everything Forever

Retention should be based on:

  • requirements;

  • business need.

Excess data creates additional risk.


129. Trap β€” Encryption Solves Every Data Problem

Encryption does not determine:

  • classification;

  • retention;

  • authorized use;

  • disposal.


130. Trap β€” Owner Performs All Technical Work

The owner is accountable for requirements.

Custodians or administrators typically implement technical controls.


131. Trap β€” Inventory Is Only Hardware

Asset inventory may include:

  • tangible assets;

  • intangible assets;

  • information;

  • software;

  • licenses.


132. Trap β€” EOL and EOS Mean Exactly the Same Thing

They are related but should be distinguished.

EOL concerns lifecycle retirement.

EOS concerns loss of vendor support.


133. Trap β€” DLP and DRM Are the Same

DLP:

Controls data movement.

DRM:

Controls permitted content usage.


134. Trap β€” CASB Is Just Cloud Storage

A CASB is a security-policy and visibility mechanism associated with cloud-service use.


135. Trap β€” Highest Classification for Everything

Overclassification can:

  • increase cost;

  • reduce usability;

  • cause users to ignore labels.

Classification should reflect actual risk.


Part XXXIX β€” SierraTec Secure Asset Protection Model

136. PROTECT Model

Use the SierraTec Secure PROTECT model for asset-security questions.

P β€” Pinpoint the Asset

What information or resource exists?

R β€” Rate the Sensitivity

How valuable, sensitive, or critical is it?

O β€” Owner and Accountability

Who determines requirements?

T β€” Track Location and Lifecycle

Where is it now and where will it move?

E β€” Establish Handling Requirements

How should it be stored, transmitted, and used?

C β€” Control Access and Protection

Which safeguards apply?

T β€” Terminate Securely

How will the asset or data be retired and destroyed?


137. PROTECT Diagram

P
PINPOINT ASSET
β”‚
β–Ό
R
RATE SENSITIVITY
β”‚
β–Ό
O
OWNER
β”‚
β–Ό
T
TRACK LIFECYCLE
β”‚
β–Ό
E
ESTABLISH HANDLING
β”‚
β–Ό
C
CONTROL & PROTECT
β”‚
β–Ό
T
TERMINATE SECURELY

Part XL β€” Knowledge Check

138. Knowledge Check

Question 1

What should generally occur before selecting protection controls for information?

A. Identify and classify it.

B. Destroy it.

C. Transfer ownership.

D. Publish it.

Correct Answer

A


Question 2

Who is typically responsible for determining data classification?

A. Data owner.

B. Custodian.

C. Network switch.

D. External attacker.

Correct Answer

A


Question 3

Who typically implements protection requirements established by the owner?

A. Custodian.

B. Visitor.

C. Customer.

D. Competitor.

Correct Answer

A


Question 4

Which is an intangible asset?

A. Source code.

B. Server rack.

C. Laptop.

D. Building.

Correct Answer

A


Question 5

What is the primary purpose of an asset inventory?

A. Provide visibility into organizational assets.

B. Replace risk management.

C. Encrypt data.

D. Eliminate ownership.

Correct Answer

A


Question 6

What does data classification primarily determine?

A. Sensitivity and required protection.

B. Network speed.

C. Purchase price only.

D. CPU model.

Correct Answer

A


Question 7

Which classification level typically requires the strongest protection?

A. Restricted/highly sensitive.

B. Public.

C. Marketing.

D. Published.

Correct Answer

A


Question 8

What is data remanence?

A. Residual data remaining after deletion or attempted removal.

B. An authentication factor.

C. Network redundancy.

D. Cloud availability.

Correct Answer

A


Question 9

Which BEST describes data at rest?

A. Stored data.

B. Data traversing a network.

C. Data actively processed in memory.

D. Deleted data only.

Correct Answer

A


Question 10

Which BEST describes data in transit?

A. Information moving between systems or locations.

B. Stored backup information.

C. Archived paper.

D. Data deleted from disk.

Correct Answer

A


Question 11

Which BEST describes data in use?

A. Information actively processed or accessed.

B. Archived data.

C. Printed data only.

D. Destroyed data.

Correct Answer

A


Question 12

What is the main purpose of DRM?

A. Control permitted use of digital content.

B. Prevent hardware failure.

C. Manage network routing.

D. Replace authentication.

Correct Answer

A


Question 13

What is the main purpose of DLP?

A. Detect or prevent unauthorized data movement.

B. Provide electrical power.

C. Build applications.

D. Classify network packets only.

Correct Answer

A


Question 14

Which technology helps enforce security policy around cloud-service use?

A. CASB.

B. RAID.

C. BIOS.

D. UPS.

Correct Answer

A


Question 15

What is the primary risk associated with End of Support?

A. Security updates and support may no longer be available.

B. Data is automatically encrypted.

C. The asset becomes public.

D. Authentication is eliminated.

Correct Answer

A


Question 16

What is scoping?

A. Determining which assets and systems are subject to requirements.

B. Deleting controls.

C. Extending retention indefinitely.

D. Purchasing software.

Correct Answer

A


Question 17

What is tailoring?

A. Adjusting control implementation appropriately for the environment.

B. Ignoring requirements.

C. Removing all controls.

D. Encrypting everything identically.

Correct Answer

A


Question 18

Which role represents the individual to whom personal information relates?

A. Data subject.

B. Custodian.

C. Controller.

D. Auditor.

Correct Answer

A


Question 19

Which role commonly determines the purpose and means of personal-data processing under privacy frameworks using that terminology?

A. Controller.

B. User.

C. Custodian.

D. Help desk.

Correct Answer

A


Question 20

Which process should occur before a retired storage device containing sensitive information is reused or disposed of?

A. Appropriate sanitization.

B. Rename the files.

C. Move them to the recycle bin.

D. Change the desktop wallpaper.

Correct Answer

A


Part XLI β€” Original CISSP-Style Scenario Practice

139. Practice Question 1

An organization discovers thousands of sensitive files but cannot determine who is responsible for setting access requirements.

What is the MOST important governance weakness?

A. Lack of clearly assigned data ownership.

B. Lack of disk space.

C. Slow network routing.

D. Excessive printing.

Correct Answer

A


140. Practice Question 2

A company labels almost every document β€œHighly Restricted.”

What is the GREATEST concern?

A. Overclassification may reduce usability and weaken meaningful handling distinctions.

B. Highly restricted data cannot be encrypted.

C. Public data no longer exists.

D. Classification always reduces security.

Correct Answer

A


141. Practice Question 3

An employee deletes confidential files before selling an old laptop.

What should happen NEXT?

A. Sell immediately.

B. Apply approved sanitization appropriate to the data and media.

C. Rename the drive.

D. Remove shortcuts.

Correct Answer

B


142. Practice Question 4

A payroll administrator decides which employees should have access to payroll records even though HR is designated as the data owner.

What is the PRIMARY concern?

A. Custodian is making an ownership decision.

B. Availability.

C. Network latency.

D. Encryption.

Correct Answer

A


143. Practice Question 5

A critical application runs on an operating system that no longer receives vendor security updates.

What is the PRIMARY concern?

A. End-of-support risk.

B. Data classification.

C. Tokenization.

D. Copyright.

Correct Answer

A


144. Practice Question 6

A highly sensitive database is encrypted at rest, but employees can export unencrypted records to personal cloud services.

What additional control would MOST directly address this risk?

A. DLP.

B. RAID.

C. UPS.

D. Load balancing.

Correct Answer

A


145. Practice Question 7

The organization knows its sensitive information is stored in its primary database but does not know whether copies exist in backups, SaaS applications, or employee laptops.

Which Asset Security activity should receive priority?

A. Data-location discovery and inventory.

B. Patent filing.

C. Firewall replacement.

D. Physical relocation.

Correct Answer

A


146. Practice Question 8

A user legitimately receives a sensitive report but should not forward or print it.

Which technology MOST directly addresses this requirement?

A. DRM.

B. CASB.

C. Load balancer.

D. IDS.

Correct Answer

A


147. Practice Question 9

Employees are using several unsanctioned SaaS applications to store organizational information.

Which control can provide visibility and policy enforcement around cloud use?

A. CASB.

B. RAID.

C. DHCP.

D. UPS.

Correct Answer

A


148. Practice Question 10

A legal hold is issued for records whose normal retention period expires tomorrow.

What should happen?

A. Preserve the relevant records according to the hold.

B. Delete them according to the normal schedule.

C. Send them to all users.

D. Reclassify them as public.

Correct Answer

A


Part XLII β€” Key Terms

149. Key Terms

Asset

Something of value to an organization.

Tangible Asset

Asset having physical form.

Intangible Asset

Nonphysical asset such as data, software, or intellectual property.

Data Classification

Assignment of information to categories based on sensitivity or value.

Asset Classification

Assignment of assets to categories based on criticality, sensitivity, or business importance.

Data Owner

Role accountable for determining information requirements.

Asset Owner

Role accountable for an asset's business use and protection requirements.

Controller

Role determining purposes and means of personal-data processing where applicable.

Custodian

Role implementing and maintaining controls.

Processor

Role processing information on behalf of another party under applicable arrangements.

User

Authorized user of organizational information.

Data Subject

Individual to whom personal information relates.

Asset Inventory

Structured record of organizational assets.

Handling Requirement

Rule defining how information may be stored, used, transmitted, copied, or disposed of.

Data Lifecycle

Stages through which information progresses from creation or collection to destruction.

Data Retention

Period information is kept.

Data Remanence

Residual information remaining after attempted removal or deletion.

Media Sanitization

Process intended to render access to targeted stored data infeasible at an appropriate level of effort.

End of Life

Point at which a product reaches the end of its lifecycle.

End of Support

Point after which normal vendor support or security updates are no longer provided.

Data at Rest

Stored information.

Data in Transit

Information moving between systems.

Data in Use

Information actively being processed.

Scoping

Determining which assets and systems are subject to a requirement.

Tailoring

Authorized adjustment of control implementation for organizational circumstances.

DRM

Digital Rights Management; controls permitted use of digital content.

DLP

Data Loss Prevention; identifies and limits unauthorized movement or disclosure of sensitive information.

CASB

Cloud Access Security Broker; provides security-policy and visibility capabilities for cloud-service use.

Data Masking

Obscuring sensitive information while preserving a usable representation.

Tokenization

Replacing a sensitive value with a surrogate token.


Part XLIII β€” CISSP Exam Focus

150. Asset Security Mindset

Remember the sequence:

IDENTIFY
↓
CLASSIFY
↓
ASSIGN OWNER
↓
ESTABLISH HANDLING
↓
PROTECT
↓
TRACK LOCATION
↓
MAINTAIN
↓
RETAIN
↓
REVIEW
↓
SANITIZE / DESTROY

For CISSP questions:

  • You cannot protect assets you have not identified.

  • Classification should reflect business value, sensitivity, and risk.

  • Public information can still require integrity and availability.

  • Owners determine protection requirements.

  • Custodians implement controls.

  • Inventories include tangible and intangible assets.

  • Classification should drive handling requirements.

  • Data location matters throughout the lifecycle.

  • Unnecessary data increases exposure.

  • Retention should be based on legitimate requirements.

  • Legal holds can override normal disposal schedules.

  • Normal deletion may leave data remanence.

  • Sanitization should match information sensitivity and media characteristics.

  • Current NIST guidance emphasizes enterprise sanitization programs and validation.

  • End-of-Life and End-of-Support assets require risk management.

  • Data at rest, in transit, and in use require different safeguards.

  • Scoping determines what is subject to requirements.

  • Tailoring adjusts implementation appropriately; it does not mean ignoring controls.

  • DRM governs permitted content use.

  • DLP focuses on unauthorized data movement.

  • CASB supports cloud-service governance and policy.

  • Encryption does not replace ownership, classification, retention, or disposal.

  • Asset security continues from acquisition through final disposition.


151. Lesson Summary

Lesson Seven introduced the complete Asset Security and Information Lifecycle Management foundation.

You learned that information security begins with identifying what the organization possesses.

The current CISSP Asset Security domain requires candidates to understand:

  • information and asset classification;

  • handling requirements;

  • ownership;

  • inventories;

  • asset management;

  • data roles;

  • collection;

  • location;

  • maintenance;

  • retention;

  • remanence;

  • destruction;

  • End of Life;

  • End of Support;

  • data states;

  • scoping;

  • tailoring;

  • standards selection;

  • DRM;

  • DLP;

  • CASB.

You learned the relationship:

ASSET
β”‚
β–Ό
VALUE
β”‚
β–Ό
CLASSIFICATION
β”‚
β–Ό
OWNER
β”‚
β–Ό
HANDLING REQUIREMENTS
β”‚
β–Ό
SECURITY CONTROLS

You examined data through its complete lifecycle:

COLLECT
↓
CLASSIFY
↓
STORE
↓
USE
↓
TRANSMIT
↓
MAINTAIN
↓
RETAIN
↓
DESTROY

You also learned that simply pressing Delete does not necessarily eliminate information.

Data remanence may permit recovery from storage media.

Current NIST SP 800-88 Rev. 2 emphasizes an enterprise media-sanitization program, selection of appropriate methods based on information sensitivity, and verification that sanitization was successful.

The central Lesson Seven principle is:

Protection should follow the information throughout its lifecycleβ€”from the moment it is created or acquired until the moment its authorized retention ends and its remaining copies are securely disposed of.


Exam Readiness Check

Before proceeding to Lesson Eight, make sure you can explain:

  • What an asset is.

  • Why asset identification comes before protection.

  • The difference between tangible and intangible assets.

  • What an asset inventory should accomplish.

  • What data classification means.

  • What asset classification means.

  • Why classification should be based on business impact.

  • Why public information may still need protection.

  • How classification drives handling requirements.

  • Who normally determines classification.

  • What a data owner does.

  • What an asset owner does.

  • What a custodian does.

  • What a controller does conceptually.

  • What a processor does.

  • What a data subject is.

  • Why secure provisioning matters.

  • Why unauthorized assets create risk.

  • The stages of the data lifecycle.

  • Why data collection should be limited.

  • Why data location matters.

  • What data maintenance means.

  • Why retention schedules exist.

  • Why excessive retention creates risk.

  • What data remanence means.

  • Why ordinary deletion is not necessarily sanitization.

  • What media sanitization accomplishes.

  • Why sanitization should be validated.

  • What EOL means.

  • What EOS means.

  • Why unsupported systems create security risk.

  • The difference between data at rest, in transit, and in use.

  • Controls commonly applied to each data state.

  • What scoping means.

  • What tailoring means.

  • Why scoping and tailoring are different.

  • What standards selection means.

  • What DRM does.

  • What DLP does.

  • What CASB does.

  • How DRM, DLP, and CASB differ.

  • What masking means.

  • What tokenization means.

  • Why asset-disposition procedures are part of cybersecurity.


Coming Next

Lesson Eight: Security Architecture Foundations and Protection Mechanisms

Lesson Eight will begin CISSP Domain 3 β€” Security Architecture and Engineering.

This is where the protection mechanisms you asked about earlier will be developed in depth.

The lesson will cover:

  • security architecture;

  • secure-design principles;

  • abstraction;

  • data hiding;

  • encapsulation;

  • isolation;

  • process isolation;

  • memory protection;

  • security domains;

  • security boundaries;

  • trust boundaries;

  • protection rings;

  • reference monitor;

  • security kernel;

  • Trusted Computing Base;

  • hardware roots of trust;

  • Trusted Platform Module;

  • secure boot;

  • secure defaults;

  • fail securely;

  • economy of mechanism / keep it simple;

  • least privilege;

  • separation of duties;

  • defense in depth;

  • Zero Trust;

  • privacy by design;

  • shared responsibility;

  • Secure Access Service Edge;

  • system security capabilities;

  • architectural attack surfaces;

  • protection-mechanism comparisons;

  • original architecture diagrams;

  • CISSP scenario questions.

The central question for Lesson Eight will be:

How should systems be architected so that security is enforced by design rather than depending only on users, procedures, or individual security products?


Publication and Independence Notice

This lesson is independently developed educational material for the SierraTec Secure CISSP Certification Preparation Course.

CISSP is administered by ISC2. SierraTec Secure's course is independent certification-preparation material and should not be represented as official ISC2 training unless separately authorized.

The principal examination alignment for this lesson was verified against the current CISSP Certification Exam Outline. Domain 2 explicitly covers information and asset classification, handling requirements, secure provisioning, ownership, tangible and intangible inventories, data roles and lifecycle, EOL/EOS, data states, scoping and tailoring, standards selection, and protection methods including DRM, DLP, and CASB.

The media-sanitization discussion was updated to reflect NIST SP 800-88 Rev. 2, published September 26, 2025, which superseded Revision 1 and emphasizes enterprise sanitization programs, information sensitivity, modern storage environments, and sanitization validation.

The SierraTec Secure PROTECT model, lesson structure, diagrams, examples, knowledge checks, and practice questions are original instructional content and are not actual, recalled, leaked, or official CISSP examination questions.

Sallieu Kanu

Sallieu Kanu

Product Designer
0
Best Seller
Faithful User
Expert Vendor
King Seller

Class Sessions

1- Introduction to CISSP 2- Thinking Like a CISSP: Security Principles, Risk, and Professional Decision-Making 3- Lesson 1 4- Lesson 3 5- Lesson 4: Risk Management, Risk Assessment, and Risk Treatment 6- Lesson 5: Threat Modeling, Supply-Chain Risk, and Third-Party Risk 7- Lesson 6: Legal, Regulatory, Privacy, Compliance, and Investigation Foundations 8- Lesson 7: Asset Security and Information Lifecycle Management 9- Lesson 8: Security Architecture Foundations and Protection Mechanisms 10- Lesson 9: Security Models, Trusted Systems, and Secure Design 11- Lesson 10: Cryptography and Cryptographic Solutions 12- Lesson 11: Cryptographic Attacks and Public Key Infrastructure 13- Lesson 12: Physical and Facility Security Architecture 14- Lesson 13: Information System Lifecycle and Secure Engineering 15- Lesson 14: Communication and Network Security Foundations 16- Lesson 15: Secure Network Components and Infrastructure Protection 17- Lesson 16: Secure Communication Channels, Remote Access, and Third-Party Connectivity 18- Lesson 17: Identity and Access Management Foundations 19- Lesson 18: Authentication Systems, Federation, SSO, and Identity Protocols 20- Lesson 19: Authorization Models and Access-Control Enforcement 21- Lesson 20: Identity Provisioning, Access Reviews, Privileged Access, and Account Lifecycle 22- Lesson 21: Security Assessment and Testing Foundations 23- Lesson 22: Advanced Security Control Testing and Vulnerability Management 24- Lesson 23: Security Metrics, Test Analysis, Reporting, and Audit Assurance 25- Lesson 24: Security Operations, Investigations, Evidence, and Logging Foundations 26- Lesson 25: Configuration Management, Resource Protection, Patch Management, and Change Control 27- Lesson 26: Incident Management and Operational Detection and Prevention 28- Lesson 27: Backup, Recovery Strategies, Disaster Recovery, and Business Continuity Operations

Join Us Today

We'll send the best deals and offers to your email. No spam, ever.

GDPR

When you visit any of our websites, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and manage your preferences. Please note, that blocking some types of cookies may impact your experience of the site and the services we are able to offer.