CISSP · D2 · 10%

Asset Security

Assign ownership, classify assets and information, define handling, provision securely, manage lifecycle and retention, and select data controls.

Provider facts checked 2026-08-03

Objective coverage

Objective 2.1 · high

Identify and classify information and assets

Inventory tangible and intangible assets, assign ownership and data roles, and classify by sensitivity and business impact.

Lesson
d2-lesson
Practice pool
d2-questions
Application
cissp-s03
Objective 2.2 · high

Establish handling requirements

Translate classification into access, labeling, transmission, storage, processing, sharing, and destruction requirements.

Lesson
d2-lesson
Practice pool
d2-questions
Application
cissp-s03
Objective 2.3 · normal

Provision information and assets securely

Apply approved acquisition, configuration, assignment, ownership, access, tracking, and acceptance controls.

Lesson
d2-lesson
Practice pool
d2-questions
Application
cissp-s03
Objective 2.4 · high

Manage the data lifecycle

Govern collection, location, use, maintenance, sharing, archival, retention, deletion, and remanence.

Lesson
d2-lesson
Practice pool
d2-questions
Application
cissp-s03
Objective 2.5 · normal

Ensure appropriate retention

Align retention and disposal with legal hold, business need, end-of-life, end-of-support, risk, and defensible deletion.

Lesson
d2-lesson
Practice pool
d2-questions
Application
cissp-s03
Objective 2.6 · high

Determine data controls and compliance

Select scoping, standards, rights management, DLP, CASB, encryption, masking, and monitoring from requirements.

Lesson
d2-lesson
Practice pool
d2-questions
Application
cissp-s03

Decision frame

An organization cannot protect data and assets it has not identified, owned, and placed in context. Asset security connects business value and harm to handling requirements across creation, collection, use, sharing, storage, archival, retention, and destruction.

Classify first, then select controls. Do not begin with encryption or DLP and attempt to infer the policy afterward.

Objective map

ObjectiveRequired judgmentProof
2.1 Identify and classify information and assetsInventory assets, assign ownership, and classify from sensitivity and business impactEach material asset has an owner, location, classification, and review date
2.2 Establish handling requirementsTranslate classification into access, labeling, transfer, storage, processing, sharing, and destructionHandling controls remain consistent across systems and third parties
2.3 Provision information and assets securelyGovern acquisition, configuration, assignment, acceptance, tracking, and accessAssets enter service only after ownership and control acceptance
2.4 Manage the data lifecycleControl collection through location, use, maintenance, sharing, archival, and deletionData lineage and state changes are visible and owned
2.5 Ensure appropriate retentionBalance legal hold, business need, end-of-life, risk, and defensible disposalRetention is authorized, enforced, suspended for hold, and verifiably completed
2.6 Determine data controls and complianceSelect scoping, DLP, rights management, CASB, encryption, masking, and monitoringControls address the classified data and sanctioned use without blocking required work

Ownership and classification

Assets include information, applications, infrastructure, devices, facilities, intellectual property, credentials, cryptographic keys, models, code, records, contracts, and services. Inventory enough attributes to support decisions: owner, custodian, users, location, dependency, lifecycle, sensitivity, criticality, support status, and recovery requirement.

The owner is accountable for classification and access decisions. Custodians implement handling and technical controls. Users follow requirements. Privacy roles such as controller and processor depend on applicable law and relationship; do not substitute them blindly for internal ownership.

Classification should be understandable and limited to useful tiers. Criteria can include disclosure harm, integrity impact, availability impact, legal duty, contract, and business value. Labels might differ by organization, but each level needs explicit handling. Overclassification raises cost and encourages bypass; underclassification exposes data. Review classification when purpose, ownership, regulation, or impact changes.

Handling and provisioning

Handling requirements cover collection, labeling, approved storage, access, transmission, printing, copying, export, collaboration, remote use, backup, incident response, return, and destruction. Map them to both human procedure and technical controls. Encryption can protect a transfer while an authorized recipient still misuses the data; contracts, access, monitoring, and minimization remain relevant.

Provision assets through approved acquisition and acceptance. Establish owner, intended use, configuration baseline, support, license, supplier, warranty, inventory identifier, location, access, data class, logging, backup, and disposal plan. For cloud resources and software services, record account, Region, administrative owner, data processing, integrations, export, and termination behavior.

Asset assignment should connect to identity and role. On transfer or termination, recover devices and tokens, change ownership, revoke access, handle data, and update inventory. Orphaned systems and service accounts often outlive the person or project that created them.

Data lifecycle

Collect only what has a legitimate purpose. Record source, consent or authority where relevant, classification, owner, location, transformation, recipients, and retention. Data can spread into caches, indexes, logs, analytics, development copies, backups, messages, exports, AI embeddings, and supplier systems. A deletion request or retention rule must account for those derivatives and document unavoidable constraints.

Use data lineage to trace transformations and movement. Maintain integrity through validation, versioning, controlled change, reconciliation, and provenance. Separate authoritative systems from replicas and reports. Define who may correct a record and how corrections propagate.

Retention comes from law, regulation, contract, litigation hold, records schedule, business need, and risk. Longer is not always safer: unnecessary data expands breach impact, discovery cost, privacy risk, and storage. Shorter can violate duty or eliminate evidence. Legal holds suspend ordinary disposal for relevant material under authorized guidance. When retention ends, dispose through methods appropriate to media, encryption, remanence, copies, and supplier commitments, then retain proof suitable to the requirement.

Data controls

Use access controls from classification, role, purpose, and need. Encrypt at rest and in transit with governed keys. Mask or tokenize when full values are unnecessary. Rights-management controls can restrict use after distribution in supported environments. DLP detects or blocks defined data movement; it needs accurate classification, sanctioned channels, tuned policies, incident ownership, and false-positive management. A CASB or cloud access control can add visibility and policy for cloud use but does not replace provider configuration and identity governance.

Scoping reduces compliance and breach surface by isolating regulated data and limiting where it can flow. Monitoring should detect anomalous access, bulk export, policy changes, unusual destinations, failed protections, and retention exceptions. Do not log sensitive data merely to monitor it.

Decision patterns

NeedStrong approachFrequent mistake
New sensitive datasetOwner, purpose, classification, lineage, handling, retention before ingestionStore first and classify later
Analytics without direct identifiersMinimize, mask/tokenize, restrict re-identification, validate utilityCopy the production dataset broadly
Prevent unsanctioned sharingDLP plus identity, sanctioned channels, training, and responseAssume DLP detects every encoding and context
Supplier processingContract, purpose limitation, access, location, retention, return/destruction evidenceRely only on the supplier's general policy
Media disposalMethod matched to media, data, reuse, and verificationDelete file names and assume data is gone

Scenario drill

A product team wants to copy customer-support records into a new analytics platform and retain them indefinitely “for future AI use.”

  1. Identify the data owner, purpose, subjects, fields, sources, jurisdictions, suppliers, and existing retention duties.
  2. Challenge indefinite collection and remove fields not required for approved analytics.
  3. Classify the dataset and define access, masking, export, monitoring, backup, and incident handling.
  4. Establish lineage into derived tables, indexes, models, logs, and exports.
  5. Set an authorized retention schedule, hold process, review, and verifiable deletion across copies.
  6. Require a separate approval before changing the purpose to AI processing.

Common traps

  • Treating the security team as the data owner.
  • Using one classification label with no handling rules.
  • Protecting the source database but ignoring exports, logs, backups, and indexes.
  • Retaining everything because storage is inexpensive.
  • Assuming encryption removes retention, access, or breach concerns.
  • Deploying DLP without data discovery, business context, and response ownership.
  • Deleting a cloud resource without validating replicas and provider retention behavior.

Self-check

  1. Distinguish owner, custodian, user, controller, and processor.
  2. Write handling requirements for one confidential data class.
  3. Trace a record through collection, transformation, backup, export, and deletion.
  4. Choose a disposal method for a reused drive, failed SSD, paper record, and encrypted cloud object.
  5. Explain what evidence proves a supplier returned or destroyed data.

Primary references