Owner, Custodian, Controller, Processor: CISSP Data Classification, the Roles That Decide It, and the Handling Each Label Demands

Chris Rees
25+ years in IT · Pluralsight author, 4.6/5 across 2,000+ ratings

www.skillthropic.comA new head of data governance runs a discovery scan on the corporate file store and finds that 61% of documents are marked Confidential. The lunch menu is Confidential. The office move plan is Confidential. So are the pricing models a competitor would genuinely pay for, sitting in the same category with the same controls as the lunch menu. That is not a strict scheme; it is a scheme that has stopped conveying information. CISSP Domain 2 opens with classification because everything after it, handling, retention, destruction, depends on the label meaning something.
Two decisions, not one
The outline separates data classification from asset classification. Data classification grades information itself, in any form, by the impact of unauthorized disclosure, modification or loss. Asset classification grades the systems, devices, media and facilities that process or store it, and the rule is inheritance: an asset carries the highest classification of any data it handles. A laptop holding one Confidential file and a thousand Public ones is a Confidential asset, and it is stored, transported and destroyed as such.
Inheritance is also the logic of spillage: higher-classified data landing in a lower-classified system raises the whole system's classification until it is removed and the system verified clean, which is why a spill is an incident.
The label sets
| Government | Damage from disclosure | Commercial equivalent |
|---|---|---|
| Top Secret | exceptionally grave damage to national security | Confidential / Proprietary: the organization's most sensitive material |
| Secret | serious damage | Private: personal data whose disclosure harms individuals |
| Confidential | identifiable damage | Sensitive: internal material needing more than default care |
| Unclassified | no damage; may still be controlled (Sensitive but Unclassified, For Official Use Only) | Public: disclosure causes no harm |
The government sequence and its damage language are what the exam expects you to recognize. The commercial column is a convention, not a standard; organizations name their own levels, and a stem will happily use Restricted or Proprietary. What matters is the logic: levels ordered by impact, few of them, and a stated default for unlabeled data. Three or four levels is the practical ceiling; schemes with seven collapse because nobody can apply them consistently.
Over-classification is as damaging as under-classification, which is the point of the opening story. When most things carry the top label, the controls become unbearable, staff route around them, and the documents that genuinely need the label lose it in the crowd. The exam treats "default to the lowest defensible level" as correct and "when in doubt, mark it Confidential" as the failure.
What drives the grade
The criteria the outline names are value, sensitivity, age and regulation, and each is a question the owner asks.
- Value: what is lost commercially if this becomes public or is corrupted?
- Sensitivity: could disclosure cause distress, discrimination or physical risk to a person, or breach a promise to a customer?
- Regulation: does a law require particular protection? Personal, health and cardholder data and export-controlled technology arrive with their classification partly decided.
- Age: does the sensitivity decay? A quarterly result is market-sensitive until the announcement and public a minute later. Age is what makes declassification possible.
Two effects push a dataset above the grade of any record in it: aggregation, sensitivity arising from volume, as when a year of harmless shipment records reveals a customer's suppliers and margins, and inference, deducing protected facts from unprotected ones. Both are why an owner grades the collection, not just the row.
Who decides: the accountability chain
Classification is assigned by the data owner, a business role. Not the CISO, not the database administrator, and not the person who happened to create the file.
The data custodian operates the controls the owner specified: backups, permissions, encryption, retention enforcement. Custodians implement; they do not decide. The data steward is delegated by the owner for data quality, meaning and day-to-day classification questions; the steward advises, the owner stays accountable. The asset owner and system owner are the owner role applied to the item and the system, and an asset with no named owner is an unmanaged asset, however well configured.
The legal roles come from privacy law and sit on a different axis. The data controller determines the purposes and means of processing and carries the primary regulatory obligations. The data processor acts on the controller's documented instructions and has its own direct duties, including security and breach notification to the controller. The data subject is the individual the data is about, and their rights run against the controller. The exam's favorite trap is conflating owner with controller: owner is an internal accountability that decides classification and access; controller is a legal status that answers to a regulator. One organization is a controller for its own customer data and a processor for a client's, and who notifies the supervisory authority depends on which hat it is wearing.
From label to handling
Classification is a label; handling requirements are what the label means. Objective 2.2 turns each grade into concrete rules, and its most examinable idea is that handling rules exist so the person holding the data never has to make a judgment call. When a stem describes an employee choosing how to send a sensitive file, the missing control is a defined handling standard, not more training.
Marking is applied to the information; labeling is applied to the media or asset that carries it, and the second is the one organizations forget. A document gets a header and metadata that tooling can act on; a tape or drive gets a physical label with the classification and a unique identifier tied to an inventory record; a device gets an asset tag recording the highest classification it handles, because that tag governs its disposal. An unlabeled Confidential document is Confidential in policy and Public in practice.
Media in transit is where handling standards earn their existence: encrypted before dispatch with keys traveling separately, inventoried so a loss can be assessed, uniquely identified and tracked, moved by an approved carrier with a signed handover and a receipt on arrival, packaged tamper-evidently, and covered by a non-arrival action that triggers on a missed window. A courier is not a control. Handling must also follow copies and derivatives, which is where schemes leak: a production extract in a test database is a Restricted asset with Internal controls. The destruction column is its own objective, covered in data remanence and sanitization.
Three states, three controls
The outline asks for the control that protects data in each of its three states. Questions name the state and ask for the control, or name a control and ask which state it does nothing for.
| State | Where the data is | Primary control | What it does not cover |
|---|---|---|---|
| At rest | on disk, tape, in a database or a backup | encryption at rest plus access control | data being read by an authorized process |
| In transit | crossing a network | TLS, IPsec, VPN, end-to-end encryption | the endpoints on either side |
| In use | in memory, on screen, being processed | access control, memory protection, secure enclaves, DLP, screen and print policies | anything once written back to disk |
The trap is encryption at rest presented as an answer to a data-in-use problem. Full-disk encryption protects a stolen laptop that is powered off; it does nothing for the same laptop unlocked on a desk. Data in use is the hardest state to protect, which is why the exam pairs it with the newest controls, enclaves and confidential computing, alongside the oldest, access control and a clean desk. The models that formalize who may read and write at each level are in Bell-LaPadula, Biba and Clark-Wilson.
Declassification is a decision, not a deletion
Sensitivity decays, and a scheme that never lowers a grade silts up. Declassification lowers the grade on the owner's authority with a record of the decision. It does not delete the data, and it does not happen on a schedule unless the owner has set one: a quarterly result becoming Public at the moment of the announcement is that kind of pre-authorized transition. The owner, not the custodian, decides.
Four stems, decoded
- A database administrator classifies a new customer dataset as Internal because it is easy to manage that way. Wrong role. Classification is the data owner's decision; the DBA is a custodian and implements what the owner specifies.
- A laptop holds one Confidential spreadsheet and thousands of Public marketing files; the stem asks how it should be handled. As a Confidential asset. Assets inherit the highest classification they hold.
- A cloud provider processing a client's customer records suffers a breach, and the stem asks who notifies the supervisory authority. The controller, the client. The provider is a processor whose duty is to notify the controller without undue delay.
- An employee decides on her own how to send a Restricted report to a partner and picks an email attachment. The missing control is a handling standard that removes the judgment call, not more awareness training.
Key takeaways
- Data classification grades information; asset classification grades what holds it. Assets inherit the highest label, which is also the logic of spillage.
- Top Secret, Secret, Confidential, Unclassified by damage; Confidential, Private, Sensitive, Public commercially. Few levels, a stated default, over-classification treated as a failure.
- The owner decides, the custodian implements, the steward advises. Controller and processor are legal roles on a separate axis; the subject's rights run against the controller.
- Handling removes judgment. Marking on the information, labeling on the media, a matrix for storage, transmission, sharing, transport and destruction, contracts to carry it to third parties.
- At rest, in transit, in use each need a different control. Encryption at rest does nothing for an unlocked laptop; declassification is the owner's decision, not a deletion.
Identifying and classifying assets and establishing handling requirements are objectives 2.1 and 2.2 of CISSP Domain 2, Asset Security, 10% of the exam and the domain everything about retention, remanence and destruction depends on. The cloud data lifecycle is the same discipline applied to data you do not host. Work all 25 Domain 2 topics with our CISSP Domain 2 study guide.
#CISSP #ISC2 #DataClassification #AssetSecurity #DataOwner #DataHandling #DataGovernance #ExamPrep #InfoSec #CyberSecurity
Keep reading
Clear, Purge, Destroy: Data Remanence, Sanitization, and End-of-Life the CISSP Way
Deleted data is not gone, and the CISSP asks about the difference in a dozen ways. Domain 2 on what happens after the useful life of data and the assets that hold it: remanence and why deletion is a lie, the clear, purge and destroy ladder and which media each applies to, cryptographic erasure and the SSD problem, end-of-life versus end-of-support, and the ownership roles that decide who is accountable at every step.
Read CISSP deep divesSTRIDE, PASTA, DREAD, and Attack Trees: Threat Modeling the Way CISSP Tests It
Threat modeling questions on the CISSP are not about drawing diagrams. They are about knowing which method answers which question. STRIDE and the security property each letter attacks, data flow diagrams and trust boundaries, PASTA's seven stages, DREAD as a scoring rubric, attack trees with their AND and OR gates, and the attacker-centric versus asset-centric distinction that decides half the scenarios.
Read CISSP deep divesAdministrative, Criminal, Civil, Regulatory: CISSP Investigation Types, Burden of Proof, and What Makes Evidence Admissible
The first hour of an investigation decides which investigation types are still possible, and CISSP Domain 1 tests that direction relentlessly. The five investigation types with who leads each and the standard of proof it must meet, beyond reasonable doubt against preponderance of evidence, the four evidence types, the three tests for admissibility, best evidence and hearsay, chain of custody, and the legal landscape the outline names from intellectual property to export controls and transborder data flow.
ReadEnjoyed this? Get the AI security news that matters.
Join The AI Security Brief for the top AI security news, plus what's important to the C-suite. Free, straight to your inbox.
No spam. Unsubscribe anytime.
Own the whole asset lifecycle
Sanitization and end-of-life are the last steps of CISSP Domain 2, 10% of the exam. Work all 25 topics across six objectives, from classification and handling through provisioning, the data lifecycle, retention and the data security controls, with 60 practice questions.
Get the CISSP Domain 2 guide