Asset Security
Domain 2 covers knowing what information and assets you hold, classifying them, assigning ownership, and protecting data across its life cycle through to secure disposal. Questions often turn on who decides, and on which sanitization method fits which medium.
Inventory, classification and ownership
You cannot protect what you have not identified, so asset management begins with maintained inventories of hardware, software, services and data. Classification then reflects the impact of losing confidentiality, integrity or availability. Decisions about classification and use belong to the accountable owner, while custodians and administrators implement them.
Data roles and privacy obligations
Privacy law assigns roles by who decides and who acts. Personal data stays personal data even when pseudonymised, and collection should be limited to what the purpose requires. These rules shape how data is collected, where it lives and how long it is kept.
Data states, controls and scoping
Protection must fit the data's state: at rest, in transit or in use. Control baselines are a starting point that is tailored to the system, including scoping out controls that genuinely do not apply, with the rationale recorded. End-of-life assets need a plan, because unsupported software stops receiving fixes.
Remanence and sanitization
Deleted data often remains recoverable, so disposal and reuse require sanitization matched to the medium. NIST's 2025 revision keeps three methods, clear, purge and destroy, and stresses that techniques designed for magnetic disks can fail on flash and cloud storage.
Keep going: the full CISSP — Certified Information Systems Security Professional guide covers every section of the exam. CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.