CISSP · D2 · 10%

Asset Security

Assign ownership, classify assets and information, define handling, provision securely, manage lifecycle and retention, and select data controls.

Provider facts checked 2026-08-03

Objective coverage

Objective 2.1 · high

Identify and classify information and assets

Inventory tangible and intangible assets, assign ownership and data roles, and classify by sensitivity and business impact.

Lesson
d2-lesson
Practice pool
d2-questions
Application
cissp-s03
Objective 2.2 · high

Establish handling requirements

Translate classification into access, labeling, transmission, storage, processing, sharing, and destruction requirements.

Lesson
d2-lesson
Practice pool
d2-questions
Application
cissp-s03
Objective 2.3 · normal

Provision information and assets securely

Apply approved acquisition, configuration, assignment, ownership, access, tracking, and acceptance controls.

Lesson
d2-lesson
Practice pool
d2-questions
Application
cissp-s03
Objective 2.4 · high

Manage the data lifecycle

Govern collection, location, use, maintenance, sharing, archival, retention, deletion, and remanence.

Lesson
d2-lesson
Practice pool
d2-questions
Application
cissp-s03
Objective 2.5 · normal

Ensure appropriate retention

Align retention and disposal with legal hold, business need, end-of-life, end-of-support, risk, and defensible deletion.

Lesson
d2-lesson
Practice pool
d2-questions
Application
cissp-s03
Objective 2.6 · high

Determine data controls and compliance

Select scoping, standards, rights management, DLP, CASB, encryption, masking, and monitoring from requirements.

Lesson
d2-lesson
Practice pool
d2-questions
Application
cissp-s03

title: "Asset Security" summary: "Lifecycle decisions for identifying, classifying, handling, retaining, protecting, and disposing of information assets."

Ownership drives protection

Inventory information and assets, assign owners and custodians, identify data subjects/controllers/processors where relevant, and classify by sensitivity, criticality, legal duty, and business impact. Classification must translate into observable handling rules.

Define collection, creation, labeling, access, use, storage, transmission, sharing, processing, location, backup, archival, retention, legal hold, end-of-life, end-of-support, remanence, and destruction. Provision assets through approved acquisition, configuration, ownership, acceptance, tracking, and access processes.

Select encryption, rights management, DLP, CASB, masking, tokenization, access, monitoring, physical, and contractual controls from data state and requirement. Technology does not replace ownership or minimization. Retaining everything “just in case” can increase legal, privacy, recovery, and breach impact.

Self-check

For a global analytics dataset, name the owner, classification, roles, permitted purposes, locations, handling rules, retention trigger, legal-hold behavior, deletion method, and evidence that destruction is effective.