# CISSP Domain 2 — classify, own, then handle

Source: https://ai.techclick.in/blog_cissp_d2_asset_security
Markdown: https://ai.techclick.in/blog_cissp_d2_asset_security.md
Publisher: Techclick Infosec Pvt Ltd

CISSP Domain 2 manager lesson: classify information and assets, name owner vs custodian vs controller vs processor, set handling and retention, match controls to data states. Official ISC2 outline + well-known CBK. No invented exam percentages.

Quick answer

    FIRST  is almost never a DLP license. Identify the information and the asset, have the  owner  classify them, write  handling  that follows the label, then protect the data in each  state  — at rest, in transit, in use.  Retention  is keep-as-required (law, contract, mission). A  legal hold  suspends destruction. When the clock ends, sanitize for remanence:  Clear ,  Purge , or  Destroy  (NIST SP 800-88). The  custodian  implements. The  processor  only does what the  controller  instructs. Residual risk and exceptions stay with the owner, not with security-by-default.

   Say this out loud

   I do not protect “data.” I protect a classified asset, in a named state, for a named owner, until a named retention clock — or a legal hold — says stop.

## 1. Why classification comes before the tool

 Interview, 35 minutes in. “Payroll just exported last year’s files to a new SaaS HR tool. What does the security professional do  first ?” The engineer answers “turn on CASB and DLP.” Those are protection methods the outline names later (objective 2.6). They are not first.

 ISC2 Domain 2 — Asset Security — is listed at  10%  on the official April 2024 exam outline. That is the only exam percentage this page uses. The outline is asking whether you can identify and classify information and assets, provision them with an owner and an inventory, handle them, keep them for the right time, and pick controls that match the state of the data.

   Hero · the register sits next to the vault, not next to a SKU

   Notice: Public, Internal, and Restricted are handling instructions. The tablet is the owner’s decision. A DLP product without that register is decoration.

 Three reasons this domain fails people who are otherwise strong operators:

- FIRST / BEST are sequencing words. Classify and assign an owner before you buy a control. Handling follows the label.

- Accountability does not delegate. The custodian runs backups. The processor hosts the SaaS. The owner still classifies and still accepts residual risk.

- Delete is not destroy. Remanence is why “I emptied the Recycle Bin” is not a Domain 2 answer. Media type and classification pick the sanitization method.

   Hard words before the runbook

    Classification  — assigning a protection level from value, sensitivity, and impact if C, I, or A fails. Data classification and asset classification are both in objective 2.1.

    Owner  — business role accountable for the asset. Classifies it, approves access, accepts residual risk. Security advises; security is not the default owner.

    Custodian  — technical role that implements the owner’s decisions: backups, ACLs, encryption, sanitization jobs.

    Controller / processor  — privacy-law pair. The controller determines purposes and means of processing personal data. The processor processes on the controller’s documented instructions (GDPR Article 4, which Domain 1 already names as a privacy example).

    Handling  — how the classified thing is marked, stored, transported, shared, and disposed. Objective 2.2. A label with no handling rule is a sticker.

    Retention  — how long to keep the information or the asset (including End of Life and End of Support). Keep what law, contract, or mission requires — not “forever, just in case.”

    Remanence  — data that remains after ordinary deletion or reuse. The reason sanitization exists.

    Data states  — at rest, in transit, in use (objective 2.6). One file can be in more than one state in the same hour.

## 2. Mental model · labels, roles, lifecycle

 Hold three parts. Interviews fail when people treat classification as a government-only hobby, treat “owner” as the CISO, or treat the lifecycle as “backup then hope.”

   Journey · collect, classify, handle, destroy

   Read left to right. Collect without a purpose is a privacy miss. Destroy without a method and a certificate is a remanence miss. Classify sits between them on purpose.

### Part 1 · two classifications, one idea

 Objective 2.1 splits  data classification  and  asset classification . Same judgment, different object. Data is the information (payroll file, model weights, source code). The asset is the container or capability (laptop, SaaS tenant, encryption key, brand, trained model). An unclassified laptop that holds Restricted payroll is a handling failure, not a hardware mystery.

 Commercial shops typically use a short ladder such as Public → Internal → Confidential / Restricted. Government and many contractors use Unclassified / CUI → Confidential → Secret → Top Secret. The names are local. The rule is not: the owner sets the label from impact, and handling follows the label. Do not invent a “correct” four-word scheme for every firm — use the scheme the stem already lives in.

 When the scenario is a U.S. federal system,  FIPS 199  categorizes information and systems by potential impact —  Low, Moderate, High  — independently for confidentiality, integrity, and availability. The system’s overall category is the high-water mark of those three. That categorization then drives the control baseline you will later scope and tailor (objective 2.6).

#### Data classification

     What is the information worth if leaked, changed, or missing? Owner decides. Examples: customer PAN, source code, public blog draft.

#### Asset classification

     What is the thing that stores, processes, or is the information? Laptop, SaaS tenant, HSM, trained model, even a paper archive. Inventory it (2.3) as tangible or intangible.

#### Handling follows the label

     Marking, labeled media, locked storage, approved channels, escort rules, who can print, who can email outside. A Restricted file in a Public share is a handling break.

#### Provision with an owner

     Objective 2.3: ownership, inventory, asset management. No unnamed “shared drive.” No orphan SaaS. Intangible assets (licenses, keys, models, brand) belong on the same inventory as laptops.

### Part 2 · five roles, not two nicknames

 Objective 2.4 lists the roles in this order:  owners, controllers, custodians, processors, users/subjects . Owner and custodian are the classic CBK pair. Controller and processor are the privacy-law pair. Users use the data. Subjects are the people the personal data is about. Do not collapse all five into “IT.”

        Role  Decides / does  Does not

          Owner
         Classifies, approves access, sets handling and retention intent, accepts residual risk.
         Does not have to configure the ACL. Accountability does not move when the work is delegated.

          Controller
         Determines the purposes and means of processing personal data (GDPR Art. 4). Often the same organization as the owner, but it is a legal role.
         Cannot hide behind “the cloud vendor decided.”

          Custodian
         Implements: backups, encryption, access controls, media sanitization, inventory hygiene.
         Does not reclassify Restricted to Internal so the ticket is easier.

          Processor
         Processes personal data on documented instructions of the controller. Typical SaaS / payroll / email host.
         Does not set purposes. After the job, return or delete unless law says keep (GDPR recital / Art. 28 logic).

          User / subject
         User: handles data per the label. Subject: the person the personal data describes — rights attach here.
         A user is not the owner because they created a file. A subject is not a processor.

   Common trap

   Do not make the CISO the owner of every dataset. Security advises and implements. The business owner of payroll, or of the loan book, classifies. If nobody will claim ownership, stop provisioning — that is a 2.3 failure, not a reason for security to volunteer.

### Part 3 · the lifecycle is a clock, not a slogan

 Objective 2.4 walks the data: collection → location → maintenance → retention → remanence → destruction. Objective 2.5 adds  asset  retention: End of Life and End of Support. A vendor that stopped patching a scanner is an asset-retention problem even if the files on it are still inside their data-retention window.

   Flow 1 · data lifecycle the outline actually names

       Data lifecycle from collection to destruction

- Objective 2.4 · manage the data lifecycle Collect purpose first Location region, residency Maintain quality, access Retain law + mission Remanence what delete left Destroy Clear / Purge / Destroy Roles sit on every box: owner classifies · custodian implements · processor follows instructions Legal hold freezes the Retain → Destroy arrow. Location is a compliance control, not a data-center preference. Read left → right. Magenta border = remanence is the trap most engineers skip. Green = sanitization is a method, not a feeling. Say this out loud The owner classifies. The custodian implements. The controller sets purpose. The processor follows instructions. Users handle the label. Subjects have rights. Delete is not Destroy. ## 3. Decision flow · handle, retain, or destroy Decision · reuse vs destroy is not the first diamond Caption, not the art: you only reach Reuse vs Destroy after classification, retention, and legal hold. Skipping those is the engineer-brain miss. Flow 2 · from new data or media to a handling decision Decision flow from new information or media to retain, reuse, or destroy New file, SaaS export, laptop, or backup tape Identify asset + owner Owner classifies data + asset Apply handling for that label Still required by mission, law, or hold? yes Retain protect in all states no · clock ended Reuse the media after sanitization? yes · Clear or Purge Sanitize + reuse certificate on file no / high impact Destroy media Read top → bottom. Diamond = decision. Legal hold and statutory retention beat the recycle ticket. Method (Clear / Purge / Destroy) is chosen from classification + media type, not from habit. Collection without a purpose, or a location that ignores residency, is already a 2.4 miss — even if encryption is perfect. Indian teams will also hit the Digital Personal Data Protection Act, 2023 on location and purpose; the official CISSP outline’s named privacy example in Domain 1 is GDPR (plus CCPA, PIPL, POPIA). Apply the law the data subjects actually trigger. Do not invent a “this statute is X% of Domain 2.” ## 4. How to choose labels, states, and methods Use the tables. Classification picks handling. State picks the control family. Media type plus classification picks sanitization. Standards selection plus scoping and tailoring (2.6) pick which controls, not “every control in the catalog.” If the ticket looks like… Manager move Who signs New SaaS, new export, new AI training set. Identify the information, name the owner, classify, then pick handling and location. Owner. Security does not become owner by opening a PO. “Just make it Internal so we can email it.” Reclassification is an owner decision with a recorded reason — not a helpdesk convenience. Owner. Custodian refuses the silent downgrade. Retention calendar says delete; counsel says hold. Legal hold wins. Freeze destruction until the hold is released in writing. Counsel + owner. Custodian executes the freeze. Vendor announced End of Support on a scanner that still reads cheques. Asset retention (2.5). Treat as risk: replace, isolate, or accept with a dated exception. Asset owner. “It still boots” is not a treatment. Reuse SSDs that held Restricted customer files. Sanitize to the method the classification requires. Degaussing is a magnetic-media technique — do not assume it on flash. Owner accepts residual remanence risk if any. Keep the certificate. Data state (2.6) What it is Typical control family At rest Stored on disk, object store, backup, tape, phone, paper archive. Access control, encryption at rest, key custody, physical media control, backup encryption. In transit Moving across a network, API, email, courier, or sneakernet. TLS, IPsec, trusted channels, approved couriers, no public pastebins. In use Open in an app, in memory, on a screen, in a model’s context window. Need-to-know, endpoint control, DRM, session lock, confidential computing / memory protection where the stem requires it. Flow 3 · one payroll file, three states, three methods Payroll file at rest, in transit, and in use with matching controls Same classified file · different state · different control At rest Disk / object / backup Encrypt + ACL + keys Stolen laptop test CASB for the SaaS copy In transit API / email / sync TLS / approved channel DLP on the path No personal Gmail In use Excel / screen / model Need-to-know + DRM Session lock, watermark Hardest state to encrypt Read left → right. Outline 2.6 names DRM, DLP, and CASB as example protection methods — pick the one that matches the state and the channel, not all three as a reflex. ### Clear, Purge, Destroy — official NIST language Primary source: NIST SP 800-88 Rev. 2, Guidelines for Media Sanitization (September 2025; supersedes Rev. 1). Sanitization renders access to target data infeasible for a given level of effort. Method selection follows the sensitivity of the information. The well-known three methods — still the CBK set — are: Sanitization methods — match effort to classification Clear — logical techniques on user-addressable space (e.g. overwrite). Protects against simple, keyboard-level recovery. Media reusable. Purge — stronger techniques (block erase, cryptographic erase, and for some magnetic media degaussing) so laboratory recovery is infeasible. Media often reusable. Prefer when feasible for sensitive data. Destroy — physical techniques so recovery is infeasible and the media cannot store data again (shred, pulverize, incinerate, etc.). Cryptographic erase is a named 800-88 technique: destroy or render unrecoverable the keys that wrap the data. It only works if the data was encrypted with those keys before you started. Formatting a volume, emptying Trash, or degaussing an SSD “because that is what we did to HDDs” is not a method — it is a remanence gift. Scoping, tailoring, standards selection Objective 2.6: pick a standard (NIST, ISO, PCI — whichever the system already lives in), take the baseline that matches categorization, then scope (which controls can apply here) and tailor (add, remove, compensate, set parameters — and document why). NIST SP 800-53B is the official tailoring home for 800-53 baselines. Copying the entire catalog onto a wiki is not selection. ## 5. Runbook · Side A classify, B protect, C prove This is not a vendor console path. It is the Domain 2 operating path you walk on a new dataset, a new SaaS, a departing laptop, or an End-of-Support scanner. Each side cites one primary source. ### Side A · identify, own, classify (due diligence on the asset) Primary source: ISC2 outline 2.1–2.3 and FIPS 199 (when the stem is a federal-style categorization). #### Name the information and the asset What is at risk — file, database, model, paper archive, laptop, SaaS tenant, key? Tangible and intangible both go on the inventory (2.3). If it is not on the inventory, you cannot handle it.

- #### Name the owner — stop if you cannot Who in the business will classify this and accept residual risk? Security, the processor, and the helpdesk are not default owners. No owner → do not provision.

- #### Classify data and asset Owner assigns the label from impact to C, I, and A. Use the scheme the organization (or the stem) already has. For a federal system, record Low / Moderate / High per FIPS 199 and take the high-water mark.

- #### Record location and purpose Where may this live? Which region, which processor, which purpose? Collection without purpose, or a copy in a forbidden region, is already a 2.4 miss. GDPR (and any other law the subjects trigger) binds the controller, not the DLP dashboard.

### Side B · handle and protect by state

 Primary source: ISC2 outline 2.2 and 2.6 (handling requirements; data states; DRM / DLP / CASB as named methods).

- #### Write handling that the label can enforce Marking and labeling, who may store it where, who may print, which channel may leave the firm, how media travels. A Restricted label with a Public share is not a DLP problem yet — it is a handling-policy problem.

- #### Protect each state the data will actually enter At rest: encryption and access control. In transit: TLS or another approved channel. In use: need-to-know, DRM, session lock. One payroll file on a laptop is often all three in the same afternoon.

- #### Pick the method that matches the channel DLP watches data leaving a path. CASB sees the cloud / SaaS copy. DRM follows the file after it is opened. Buying all three because the stem said “sensitive” is not standards selection.

- #### Scope and tailor the baseline Select the standard the system lives in. Apply scoping (does this control even apply?). Tailor (compensate, parameterize, add). Write down why. A small internal wiki does not inherit a High baseline just because someone pasted 800-53.

### Side C · retain, sanitize, prove

 Primary source: ISC2 outline 2.4–2.5 and  NIST SP 800-88 Rev. 2 .

- #### Set retention from law, contract, and mission — then honor holds Keep what you must. Do not keep “just in case” past the policy. A legal hold freezes destruction until counsel releases it. Privacy minimization and statutory retention can pull in opposite directions — counsel plus the owner resolve that, not the backup admin.

- #### Treat End of Life / End of Support as asset retention When the vendor stops patching, the asset’s retention clock is ringing even if the files on it are still needed. Migrate, isolate, or accept with a dated owner signature. “It still scans” is not 2.5.

- #### Sanitize for remanence, then certify Choose Clear, Purge, or Destroy from classification + media type. Cryptographic erase only if the data was encrypted with recoverable-key destruction. Degauss magnetic media, not as a reflex on flash. Cloud copies you cannot physically shred often fall to crypto-shred plus contractual deletion — verify the processor actually did it.

- #### Keep the evidence Classification record, owner name, handling procedure, retention schedule, hold log, sanitization certificate, inventory update. NIST still publishes a sample certificate of sanitization. A Slack “wiped it” is not Domain 2 proof.

   Green path — you finished Domain 2 work when

   Asset and information are on the inventory. An owner is named. A label exists. Handling matches the label. Each live state has a control. Retention and any legal hold are written. When the clock ended, sanitization used a named method and left a certificate. The processor did not set the purpose.

## 6. Runtime path after the label is live

 Classification is not a one-time sticker at go-live. New copies, new processors, new regions, a merger, or an End-of-Support notice send you back to Side A. Domain 1 already taught Authorize → Monitor; Domain 2 is what you monitor: labels that drifted, shares that went public, backups that outlived the policy, media that left without a certificate.

   Proof · sanitization is a signed fact, not a wipe feeling

   Notice: the certificate is the care. The green screen is only useful if it matches that file and the inventory row is closed.

        After go-live you watch…  Because  Send back to

         Shadow copies (personal Drive, Slack export, laptop image)
         Location and handling broke silently.
         Side A (inventory + owner) then B (state controls).

         Processor adding a sub-processor or a new region
         Controller still owns purpose and location.
         Side A location + contract; do not “just enable CASB.”

         Retention clock or legal hold
         Destroy too early is spoliation; keep too late is a privacy and cost miss.
         Side C.

         Vendor EOS / hardware EOL
         Objective 2.5. Unpatched assets are still assets.
         Side C, then Domain 1 treatment if you will keep running it.

         Reclassification request
         Only the owner drops a label. Custodians execute the new handling.
         Side A. Record the reason.

## 7. Traps + proof checklist

        Stem pattern  What ISC2 is testing  Engineer trap  Manager move

         What do you do FIRST?
         2.1 / 2.3 sequencing.
         Buy DLP / CASB / a shredder.
         Identify the asset, name the owner, classify.

         Who decides the label or the access?
         Ownership (2.3, 2.4).
         CISO, admin, or processor decides.
         Data / asset owner. Custodian implements.

         SaaS / cloud copy
         Controller vs processor; location.
         “The vendor is the owner now.”
         Controller still sets purpose. Processor follows instructions. CASB if you need visibility into that copy.

         Laptop reuse / SSD / degauss
         Remanence + 800-88 method.
         Format, degauss flash, or skip the certificate.
         Clear / Purge / Destroy from classification + media. Crypto-erase only if keys die.

         Retention vs hold vs privacy delete
         2.4 retention vs legal process.
         Always delete, or always keep forever.
         Policy clock, unless a legal hold freezes it. Owner + counsel, not the backup admin.

         Open file on screen / in a model
         Data state: in use.
         Quote disk encryption and stop.
         At rest is done. In use needs need-to-know, DRM, session control.

         Paste the whole control catalog
         Scoping and tailoring (2.6).
         More controls = more secure.
         Select a standard, scope what applies, tailor and document.

   Pilot / interview proof checklist

- I can classify one real file and one real laptop I have touched, and name the owner of each.

- I can say owner / custodian / controller / processor / user / subject without mixing them.

- I can pick a handling rule from a label without naming a product first.

- I can put the same file in at rest, in transit, and in use and name one control each.

- I can say when a legal hold beats a retention calendar.

- I can choose Clear, Purge, or Destroy and say why degaussing an SSD is the trap.

- I did not quote a made-up “classification is X% of Domain 2.” Domain 2’s official weight is 10% of the whole exam — that is the only percentage this page uses.

   Interview angle

    Weak:  “Domain 2 is classify data and use DLP.”  Strong:  “I do not protect ‘data.’ I protect a classified asset for a named owner. Handling follows the label. The custodian implements; the processor does not set purpose. Retention is a clock plus legal hold. Destroy is a NIST method, not emptying Trash. Controls match the state — at rest, in transit, in use — after I have scoped and tailored a real baseline.”

## Knowledge check

   Six judgment items. Map each one to a FIRST/BEST stem, not a definition. Check answers, then reset and retry the misses.

       Q1
       Payroll exported last year’s files into a new SaaS HR tool. An engineer opens a purchase request for CASB and DLP. What does the security professional do FIRST?

           Approve DLP so no file can leave any channel
           Degauss the SaaS tenant, then allow the export
           Identify the information and the asset, name the owner, and classify before buying a protection method
           Make the CISO the data owner of all HR files so the sprint is not blocked

       Correct:  c . FIRST on new data or a new processor is 2.1 / 2.3 — identify, own, classify. CASB and DLP are 2.6 methods you pick after the label and the state. Re-read  Why classification comes first  and Side A.

       Q2
       A custodian and a processor disagree. The custodian wants the file marked Restricted. The SaaS vendor says it will treat everything as Internal to simplify sharing. Who is authorized to set the classification?

           The processor — they host the bits
           The data / asset owner — accountability does not move to the host or the admin
           Any user who created a copy
           The subject of the personal data, because GDPR always classifies files

       Correct:  b . Owners classify. Custodians implement. Processors follow instructions; they do not set the label. Subjects have rights; they are not the classification authority. Re-read  Mental model · roles .

       Q3
       The retention schedule says destroy the loan files after seven years. Counsel has issued a legal hold on the same files. The backup admin wants to run the usual purge job tonight. What is the Domain 2 judgment?

           The legal hold suspends destruction until it is released in writing
           Retention always wins — purge on the calendar date
           Move the files to a Public share so both teams can see they still exist
           The processor may delete them because cloud storage is out of scope

       Correct:  a . A hold freezes the Retain → Destroy arrow. Privacy minimization does not authorize spoliation. Public-share and “cloud is out of scope” are handling failures. Re-read  Decision flow  and Side C.

       Q4
       A Restricted payroll workbook is encrypted on a laptop disk. The analyst has it open in Excel on the train. Which Domain 2 reading is accurate?

           Only in transit applies, so only TLS matters
           At rest on the disk (encryption + ACL) and in use on the screen (need-to-know, DRM, session lock) — both states are live
           No state applies until the file is emailed
           Disk encryption also covers the in-use state, so the open window is out of scope

       Correct:  b . Objective 2.6 names at rest, in transit, and in use. An open file is in use even if the disk is encrypted. Re-read  How to choose · data states .

       Q5
       Finance wants to reuse SSDs that held Restricted customer data. An engineer says “we always degauss, the way we did the old HDDs, then reimage.” What is the BEST sanitization judgment?

           Degaussing is always enough for any media
           A quick format removes remanence — certificates are optional
           Degaussing is a magnetic-media technique; pick Purge (for example cryptographic erase, if the data was encrypted) or Destroy from NIST SP 800-88, based on classification, and keep the certificate
           Ship the drives to any recycler with no paperwork, because reuse is green

       Correct:  c . 800-88 method follows sensitivity and media type. Degaussing flash is the classic remanence trap. Crypto-erase requires that the data was encrypted. Proof is the certificate. Re-read Side C and the sanitization box.

       Q6
       After a FIPS 199-style categorization, a team pastes every control from a large catalog onto a small internal wiki and calls the system “compliant.” What did they skip?

           Buying DLP first, because DLP is always the High baseline
           Standards selection, then scoping and tailoring the baseline to this system — and documenting why
           Destroying the wiki so remanence cannot leak the catalog
           Making the processor the owner so the wiki vendor signs residual risk

       Correct:  b . Objective 2.6 is determine controls and compliance requirements: data states, scoping and tailoring, standards selection, then methods. More controls is not tailoring. Re-read the scoping callout in  How to choose .

       Check answers
       Reset

## Sources

- ISC2 — CISSP Certification Exam Outline (effective 15 April 2024). Domain 2 weight 10%. Objectives 2.1–2.6 are the spine of this lesson. No other exam percentages are claimed.

- NIST — FIPS 199, Standards for Security Categorization of Federal Information and Information Systems (Low / Moderate / High on C, I, and A; high-water mark).

- NIST — SP 800-88 Rev. 2, Guidelines for Media Sanitization (September 2025; supersedes Rev. 1). Sanitization = access to target data infeasible for a given level of effort; method follows sensitivity. Well-known CBK methods: Clear, Purge, Destroy; cryptographic erase is a named technique.

- NIST — SP 800-53B, Control Baselines for Information Systems and Organizations (baselines + tailoring / scoping guidance).

- EU — Regulation (EU) 2016/679 (GDPR) , Article 4: controller determines purposes and means; processor processes on behalf of the controller. Named privacy example on the CISSP outline (Domain 1.4).

- Well-known CBK (not an ISC2 percentage claim): commercial vs government label ladders; owner classifies / custodian implements; legal hold suspends destruction; remanence after ordinary delete; degaussing is a magnetic-media technique; DRM vs DLP vs CASB as channel-matched methods.

 Related:  Domain 1 · Risk Management  ·  Domain 3 · Architecture and Engineering  ·  All 8 domains map  ·  Domain 2 timed assessment  ·  8-week roadmap

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
