CISSP Domain 2: Asset Security

What the organisation owns, who is answerable for it, and how it is handled from creation to destruction: classification, the data roles, the states data moves through, retention, and the end of a product or a medium. Small in weighting, and a frequent source of confusable pairs.

10% OF THE EXAM · 2 ARTICLES · 7 TERMS

What the exam outline covers

The ISC2 CISSP exam outline lists these areas for Domain 2 and gives the domain a weighting of 10%. The wording below is a plain-English paraphrase; the outline itself is the source.

  1. Identify and classify information and assets
  2. Establish information and asset handling requirements
  3. Provision resources securely, including ownership and inventory
  4. Manage the data lifecycle: roles, collection, location, maintenance, retention, remanence and destruction
  5. Ensure appropriate asset retention, including end of life and end of support
  6. Determine data security controls and compliance requirements

Articles

Key terms

The process of assigning sensitivity labels to information so that handling, storage, and access requirements follow from the label, and controls are selected to match it.

The senior business role accountable for a data set: the owner classifies the data, approves access, and sets protection requirements, and that accountability cannot be delegated.

The technical role that implements data protection on the owner's behalf: backups, access permissions, patching, and secure storage. Responsible for the work, never accountable for the data.

The three conditions data occupies (at rest in storage, in transit across networks, in use during processing), each demanding its own distinct protection mechanisms.

The residual data that remains on storage media after deletion or formatting, recoverable until the media is properly cleared, purged, or destroyed.

Content-inspection technology that identifies sensitive data and enforces policy to stop it leaving the organisation, deployed at the network edge, on endpoints, or as discovery scans.

A policy enforcement point between users and cloud services that delivers visibility, compliance, data security, and threat protection, including discovery of shadow IT.

Reading is half of it. Scenario questions in this domain tend to turn on the distinctions above, and the quickest way to find out which ones you hold is to answer some. The CISSP practice tests cover all eight domains with an explanation for every answer, and the free assessment gives you a baseline first.