Asset Security

Worth 10% of the ISC2 CISSP (CISSP) exam. CertClue has 38 questions on this objective.

What this objective covers

Data Classification and Handling Requirements

Classification exists so that protection can be proportionate. Without it every piece of data is treated the same, which means you either overspend protecting trivia or underprotect the material that matters. The classification decision belongs to the data owner, who is a business person accountable for the asset, and it is based on the harm that disclosure, alteration or loss would cause. Once a label is assigned, a defined set of handling rules follows it everywhere: how it is stored, labelled, transmitted, shared and eventually destroyed.

Exam tip. The data owner classifies, the custodian implements. If an answer has IT or the security team choosing the classification level, it is wrong, because classification is a business judgement about business harm. Watch for aggregation questions where the correct answer is that the combined set needs a higher label than its parts.

Data Roles: Owner, Custodian, Controller and Processor

Asset Security questions are frequently about who is accountable rather than about any technology, and the roles have precise meanings that everyday job titles blur. The owner is a senior business person who is accountable for the asset and cannot delegate that accountability. The custodian is the technical caretaker who carries out the owner's instructions. Privacy law adds its own pair, controller and processor, which map onto the same idea of deciding versus doing. If you can place the person in the question into the right role, the answer usually follows immediately.

Exam tip. When a question describes someone running backups, applying permissions or maintaining the database, that is the custodian, however senior they sound. Accountability language, classification decisions and access approval always point to the owner. In privacy scenarios, the party that decided why the data was collected is the controller.

Data Remanence and Secure Media Destruction

Deleting a file usually removes the pointer to it, not the data, and even overwritten media can retain traces. That leftover representation is data remanence, and it is why disposal is a controlled security process rather than a housekeeping task. The sanitization method has to be chosen against two things at once: how sensitive the data was, and what the media is physically made of. The second half of that matters more than people expect, because the technique that reliably sanitizes a magnetic hard drive does nothing whatsoever to a solid state drive.

Exam tip. If the question involves a solid state drive and an option offers degaussing, that option is wrong. For the highest classification levels the expected answer is physical destruction rather than any form of overwrite, and remember that reformatting a drive is never an acceptable sanitization method.

Protecting Data at Rest, in Transit and in Use

Data exists in three states and each one needs a different protection technique, which is why questions in this area so often hinge on identifying the state first. Data at rest sits on storage and is protected by encryption and access control. Data in transit is moving across a network and is protected by transport encryption. Data in use is loaded into memory for processing, which is the hardest state to protect because the application generally needs it in the clear. Data loss prevention and rights management sit across all three, enforcing the handling rules that classification defined.

Exam tip. Identify the state before you pick the control. A stolen backup tape is data at rest and the answer is encryption of the media, while a sniffed session is data in transit and the answer is transport encryption. Note that full disk encryption is a very common wrong answer for scenarios where the attacker already has access to a running, unlocked system.

Practice questions

Free, with the answer and the reasoning. No account needed.

1. An organization introduces a four level data classification scheme. What is the PRIMARY benefit management should expect from it?

  • A. The volume of data the organization stores will be reduced
  • B. All data will receive an equally high standard of protection
  • C. Protection effort and cost can be applied in proportion to the sensitivity of the datacorrect
  • D. Encryption will no longer be required for the lower levels

Classification exists to make protection proportionate, so that the most sensitive information receives the tightest handling while ordinary records are not smothered in controls that cost more than the data is worth. Protecting everything equally is exactly what a scheme is designed to end, and it is the tempting answer because it sounds thorough, yet uniform protection either bankrupts the budget or drags the important material down to the standard of the trivial. Reducing stored volume is a benefit of retention management rather than of classification, though the two often travel together in a wider data governance effort. Nothing about assigning a lower classification automatically removes an encryption requirement, since the required controls at each level are a separate decision the organization makes. Classification is how security spending finds the places it actually matters.

Work the whole objective

The full ISC2 CISSP bank, the study notes behind these summaries, and a readiness score that tells you which objective to revise next. Free, no paid tier.

Take the free ISC2 CISSP practice test

The other ISC2 CISSP objectives