MTC Group
← All Study Guides

D2: Asset Security

CISSP (ISC2) study guide

Domain 2 covers the full lifecycle of information assets: classification, ownership, privacy protection, retention, and secure data handling, including the methods used to protect data at rest, in transit, and at destruction. It's a smaller domain (10% weight) but a common source of missed points because the exam is precise about roles (who is accountable vs. who does the day-to-day work) in ways that don't always match how organizations actually talk about these roles informally.

Key Concepts
  • Data owner vs. data custodian vs. data steward

    Owner is accountable (usually a business executive) for classification and protection decisions. Custodian performs the technical work (backups, access provisioning) under the owner's direction. Steward handles day-to-day data quality/content decisions, a role the exam introduced more recently and often tests separately from custodian.

  • Data states

    At rest (stored), in transit (moving across a network), and in use (actively processed in memory). Each state has different appropriate protections: encryption at rest and in transit is standard, while protecting data in use requires things like secure enclaves.

  • Data remanence

    Residual data left behind after supposed deletion. Clearing (overwrite) vs. purging (more thorough, resistant to lab-level recovery) vs. destroying (physical) are distinct sanitization levels with different assurance guarantees, especially relevant for SSDs vs. spinning disks.

  • Data classification schemes

    Government (Top Secret/Secret/Confidential/Unclassified) vs. commercial (Confidential/Private/Sensitive/Public): know both since the exam draws from either context.

Confusable Pairs
  • Clearing vs. purging vs. destroying

    Clearing removes data from user-facing view but may be recoverable with forensic tools; purging is designed to defeat those tools; destroying is physical. The exam tests which is "sufficient" for a given sensitivity level.

  • Data owner vs. system owner

    Data owner is accountable for the information itself; system owner is accountable for the hardware/platform the data lives on. A single system can host data belonging to multiple different data owners.

Practice D2 questions with instant feedback, free to start, no card required.

Start Free