Identify and classify information and assets
Inventory tangible and intangible assets, assign ownership and data roles, and classify by sensitivity and business impact.
- Lesson
- d2-lesson
- Practice pool
- d2-questions
- Application
- cissp-s03
Assign ownership, classify assets and information, define handling, provision securely, manage lifecycle and retention, and select data controls.
Inventory tangible and intangible assets, assign ownership and data roles, and classify by sensitivity and business impact.
Translate classification into access, labeling, transmission, storage, processing, sharing, and destruction requirements.
Apply approved acquisition, configuration, assignment, ownership, access, tracking, and acceptance controls.
Govern collection, location, use, maintenance, sharing, archival, retention, deletion, and remanence.
Align retention and disposal with legal hold, business need, end-of-life, end-of-support, risk, and defensible deletion.
Select scoping, standards, rights management, DLP, CASB, encryption, masking, and monitoring from requirements.
An organization cannot protect data and assets it has not identified, owned, and placed in context. Asset security connects business value and harm to handling requirements across creation, collection, use, sharing, storage, archival, retention, and destruction.
Classify first, then select controls. Do not begin with encryption or DLP and attempt to infer the policy afterward.
| Objective | Required judgment | Proof |
|---|---|---|
| 2.1 Identify and classify information and assets | Inventory assets, assign ownership, and classify from sensitivity and business impact | Each material asset has an owner, location, classification, and review date |
| 2.2 Establish handling requirements | Translate classification into access, labeling, transfer, storage, processing, sharing, and destruction | Handling controls remain consistent across systems and third parties |
| 2.3 Provision information and assets securely | Govern acquisition, configuration, assignment, acceptance, tracking, and access | Assets enter service only after ownership and control acceptance |
| 2.4 Manage the data lifecycle | Control collection through location, use, maintenance, sharing, archival, and deletion | Data lineage and state changes are visible and owned |
| 2.5 Ensure appropriate retention | Balance legal hold, business need, end-of-life, risk, and defensible disposal | Retention is authorized, enforced, suspended for hold, and verifiably completed |
| 2.6 Determine data controls and compliance | Select scoping, DLP, rights management, CASB, encryption, masking, and monitoring | Controls address the classified data and sanctioned use without blocking required work |
Assets include information, applications, infrastructure, devices, facilities, intellectual property, credentials, cryptographic keys, models, code, records, contracts, and services. Inventory enough attributes to support decisions: owner, custodian, users, location, dependency, lifecycle, sensitivity, criticality, support status, and recovery requirement.
The owner is accountable for classification and access decisions. Custodians implement handling and technical controls. Users follow requirements. Privacy roles such as controller and processor depend on applicable law and relationship; do not substitute them blindly for internal ownership.
Classification should be understandable and limited to useful tiers. Criteria can include disclosure harm, integrity impact, availability impact, legal duty, contract, and business value. Labels might differ by organization, but each level needs explicit handling. Overclassification raises cost and encourages bypass; underclassification exposes data. Review classification when purpose, ownership, regulation, or impact changes.
Handling requirements cover collection, labeling, approved storage, access, transmission, printing, copying, export, collaboration, remote use, backup, incident response, return, and destruction. Map them to both human procedure and technical controls. Encryption can protect a transfer while an authorized recipient still misuses the data; contracts, access, monitoring, and minimization remain relevant.
Provision assets through approved acquisition and acceptance. Establish owner, intended use, configuration baseline, support, license, supplier, warranty, inventory identifier, location, access, data class, logging, backup, and disposal plan. For cloud resources and software services, record account, Region, administrative owner, data processing, integrations, export, and termination behavior.
Asset assignment should connect to identity and role. On transfer or termination, recover devices and tokens, change ownership, revoke access, handle data, and update inventory. Orphaned systems and service accounts often outlive the person or project that created them.
Collect only what has a legitimate purpose. Record source, consent or authority where relevant, classification, owner, location, transformation, recipients, and retention. Data can spread into caches, indexes, logs, analytics, development copies, backups, messages, exports, AI embeddings, and supplier systems. A deletion request or retention rule must account for those derivatives and document unavoidable constraints.
Use data lineage to trace transformations and movement. Maintain integrity through validation, versioning, controlled change, reconciliation, and provenance. Separate authoritative systems from replicas and reports. Define who may correct a record and how corrections propagate.
Retention comes from law, regulation, contract, litigation hold, records schedule, business need, and risk. Longer is not always safer: unnecessary data expands breach impact, discovery cost, privacy risk, and storage. Shorter can violate duty or eliminate evidence. Legal holds suspend ordinary disposal for relevant material under authorized guidance. When retention ends, dispose through methods appropriate to media, encryption, remanence, copies, and supplier commitments, then retain proof suitable to the requirement.
Use access controls from classification, role, purpose, and need. Encrypt at rest and in transit with governed keys. Mask or tokenize when full values are unnecessary. Rights-management controls can restrict use after distribution in supported environments. DLP detects or blocks defined data movement; it needs accurate classification, sanctioned channels, tuned policies, incident ownership, and false-positive management. A CASB or cloud access control can add visibility and policy for cloud use but does not replace provider configuration and identity governance.
Scoping reduces compliance and breach surface by isolating regulated data and limiting where it can flow. Monitoring should detect anomalous access, bulk export, policy changes, unusual destinations, failed protections, and retention exceptions. Do not log sensitive data merely to monitor it.
| Need | Strong approach | Frequent mistake |
|---|---|---|
| New sensitive dataset | Owner, purpose, classification, lineage, handling, retention before ingestion | Store first and classify later |
| Analytics without direct identifiers | Minimize, mask/tokenize, restrict re-identification, validate utility | Copy the production dataset broadly |
| Prevent unsanctioned sharing | DLP plus identity, sanctioned channels, training, and response | Assume DLP detects every encoding and context |
| Supplier processing | Contract, purpose limitation, access, location, retention, return/destruction evidence | Rely only on the supplier's general policy |
| Media disposal | Method matched to media, data, reuse, and verification | Delete file names and assume data is gone |
A product team wants to copy customer-support records into a new analytics platform and retain them indefinitely “for future AI use.”