Chapter 2 of 810% of exam

Asset Security

Domain 2 covers knowing what information and assets you hold, classifying them, assigning ownership, and protecting data across its life cycle through to secure disposal. Questions often turn on who decides, and on which sanitization method fits which medium.

Inventory, classification and ownership

You cannot protect what you have not identified, so asset management begins with maintained inventories of hardware, software, services and data. Classification then reflects the impact of losing confidentiality, integrity or availability. Decisions about classification and use belong to the accountable owner, while custodians and administrators implement them.

Inventories
Maintain inventories of hardware, of software, services and systems, and of data; prioritize assets by classification and criticality.
NIST CSF 2.0 ID.AM-01/02/05/07
Information owner
The official with authority for specified information who sets the policies for its collection, processing, dissemination and disposal.
NIST SP 800-37 Rev. 2 App. D
FIPS 199 categorization
Rate potential impact (low, moderate, high) for confidentiality, integrity and availability; a system takes the highest value for each objective across its information types.
FIPS 199 §3

Data roles and privacy obligations

Privacy law assigns roles by who decides and who acts. Personal data stays personal data even when pseudonymised, and collection should be limited to what the purpose requires. These rules shape how data is collected, where it lives and how long it is kept.

Controller and processor
The controller determines the purposes and means of processing; the processor processes personal data on the controller's behalf.
GDPR Art. 4(7)–(8)
Pseudonymised data
Data that can be attributed to a person with additional information is still information about an identifiable person.
GDPR Art. 4(5); Recital 26
Data minimisation
Personal data must be adequate, relevant and limited to what is necessary for the purpose.
GDPR Art. 5(1)(c)
Retention example
HIPAA Security Rule documentation is retained for six years from creation or the date last in effect, whichever is later.
45 CFR §164.316(b)(2)(i)

Data states, controls and scoping

Protection must fit the data's state: at rest, in transit or in use. Control baselines are a starting point that is tailored to the system, including scoping out controls that genuinely do not apply, with the rationale recorded. End-of-life assets need a plan, because unsupported software stops receiving fixes.

Tailoring
Tailoring includes applying scoping considerations, selecting compensating controls and supplementing the baseline, with documented justification.
NIST SP 800-37 Rev. 2 Task S-2
End of support
When software reaches end-of-life, patches will never be released, so other risk responses such as isolation or replacement are required.
NIST SP 800-40 Rev. 4 §2
Data protection tools
The outline groups DRM, DLP and CASB as data protection methods chosen according to data state and location.
ISC2 CISSP Exam Outline 2.6

Remanence and sanitization

Deleted data often remains recoverable, so disposal and reuse require sanitization matched to the medium. NIST's 2025 revision keeps three methods, clear, purge and destroy, and stresses that techniques designed for magnetic disks can fail on flash and cloud storage.

Clear
Logical techniques through the normal interface that protect against simple, non-invasive recovery; not appropriate for hard copy.
NIST SP 800-88 Rev. 2 §3.1.1
Purge
Makes recovery infeasible even with state-of-the-art laboratory techniques while leaving the media reusable, e.g., dedicated sanitize commands or cryptographic erase; prefer it to clear when possible.
NIST SP 800-88 Rev. 2 §3.1.2
No degaussing flash
Degaussing should not be used on non-magnetic media such as SSDs.
NIST SP 800-88 Rev. 2 §3.1.2
Cloud storage
For logical or virtual storage, cryptographic erase may be the only viable purge option.
NIST SP 800-88 Rev. 2 §3.1.2
Destroy
Renders data unrecoverable and the media unusable; appropriate for all hard copy and most media.
NIST SP 800-88 Rev. 2 §3.1.3

Keep going: the full CISSP — Certified Information Systems Security Professional guide covers every section of the exam. CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Studying in order?

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.

Get the book — $24.99
Report