Skip to content
ISC2 CISSP · CISSP

CISSP Domain 2: Asset Security

Domain 2.0: Asset Security · 10% of the exam

Everything that follows from knowing what you hold and what it is worth: all 6 objectives (2.1–2.6), from classifying information and assets through handling requirements, secure provisioning, the full data lifecycle including remanence and destruction, asset retention past end of support, and the controls and compliance requirements classification drives.

6 modules · 25 topics 99-page PDF 60 practice questions
Read a free sample By the author of 51 Pluralsight courses · 4.6/5 from 2,007 ratings
Best value
$29/ month

All study guides, current and every new one.

or own the whole exam
$129one-time · all 8 domains
or just this guide
$24.95one-time · lifetime access
  • Interactive online guide
  • Downloadable PDF
  • Lifetime updates
  • 30-day money-back guarantee

Secure checkout via Stripe · no account needed · instant access

10% of your exam score

Domain 2.0 is worth 10% of the CISSP exam. Walk in having mastered it, not hoping it doesn't come up.

Every objective, nothing extra

Built line by line from the official ISC2 CISSP objectives 2.1–2.6: 25 in-depth topics with worked scenarios and exam tips, in a 99-page guide you'll actually finish.

60 exam-style questions

Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.

The cert that changes what you're paid

CISSP is the management-track credential for security: five years of experience to hold it, eight domains wide, and the one most senior security job descriptions name by itself.

Serving, transitioning, or a military spouse?

CISSP appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →

Read a real excerpt, free

This is the actual opening of Module 2.1, Identifying & classifying assets, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.

Objective 2.1

Identify and classify information and assets

Grading information and the assets that hold it, the label sets the exam expects, who assigns them, and why schemes with too many levels fail.

Tomas Berg's job title at Aurora Logistics was Head of Data Governance, and his first week produced a number that made the classification problem concrete: 61% of documents in the corporate file store were marked Confidential. The lunch menu was Confidential. The office move plan was Confidential. So were the customs valuation models that a competitor would genuinely pay for.

A scheme in which most things carry the highest label is not a strict scheme. It is a scheme that has stopped conveying information, and the practical result is that nobody treats the label as meaningful — including for the documents where it matters.

Two related activities

ActivityApplies toDriven by
Data classificationInformation itself, in any form — a database, a report, a spreadsheet, a conversation recording.The impact of unauthorized disclosure, modification or loss.
Asset classificationThe systems, devices, media and facilities that process or store that information.The highest classification of any data the asset handles — classification flows up, never down.
Exam focus · An asset inherits the highest

A laptop that holds one Confidential file and a thousand Public ones is a Confidential asset, and is handled, transported and destroyed as such. This is the rule behind data spillage procedures: introducing higher-classified data into a lower-classified system raises the whole system's classification until it is properly remediated.

Label sets

GovernmentDamage from disclosureCommercial equivalent
Top SecretExceptionally grave damage to national security.Confidential / Proprietary — the organization's most sensitive material.
SecretSerious damage.Private — personal data whose disclosure harms individuals.
ConfidentialIdentifiable damage.Sensitive — internal material needing more than default care.
UnclassifiedNo damage; may still be controlled (e.g. “Sensitive but Unclassified”, “For Official Use Only”).Public — disclosure causes no harm.

The commercial column is a convention rather than a standard; organizations name their own levels. What the exam expects is that you recognise the government sequence and its damage language, understand that commercial schemes mirror the logic, and know that the number of levels should be small.

What drives a grading

CriterionQuestion it asks
Value to the organizationWhat is lost commercially if this becomes public or is corrupted?
Legal and regulatory obligationDoes a law require particular protection — personal data, health data, cardholder data, export-controlled technology?
Harm to individualsCould disclosure cause distress, discrimination or physical risk to a person?
Contractual commitmentHas a customer been promised specific handling?
Useful lifetimeDoes the sensitivity decay? A quarterly result is market-sensitive before publication and public afterwards.
Aggregation effectDo individually harmless records become sensitive in volume or combination?
The guide continues for 99 pagesKeep reading: unlock the full guide

Not ready to buy? Read it later.

We'll email you a free sample of this guide as a PDF, no purchase needed.

Try 3 sample questions

Pulled straight from the guide's 60-question bank. Tap an answer for instant feedback and the explanation.

From module 2.1 · Identifying & classifying assets

  1. 1. A laptop stores one Restricted file alongside a thousand Public files. What is the laptop's classification?

From module 2.2 · Information & asset handling

  1. 1. An employee improvises a method for sending a sensitive file to a customer. What control is missing?

From module 2.3 · Secure provisioning of assets

  1. 1. An outage is caused by an expired TLS certificate that no team had recorded or owned. What category of failure is this?

57 more questions like these are waiting inside.

What's inside

  • 25 in-depth topics across 6 modules, mapped to objectives 2.1–2.6
  • 60 exam-style practice questions with instant feedback
  • Full answer key explaining why every distractor is wrong
  • Clear, purge and destroy, and which method works on which medium
  • Why degaussing does nothing to an SSD
  • Complete CISSP acronym & key-term reference
  • 99-page downloadable PDF for offline study and printing
  • Lifetime updates as the exam evolves

The modules, mapped to the objectives

  1. 2.1

    Identifying & classifying assets

    Identify and classify information and assets

    10 Qs
    Data vs. asset classificationGovernment & commercial label setsImpact-based grading criteriaThe data owner's roleOver-classificationLabelling & marking
  2. 2.2

    Information & asset handling

    Establish information and asset handling requirements

    10 Qs
    Marking & labelling mediaStorage and transmission rulesCopying & printing controlsMedia in transitThird-party handling obligationsDeclassification
  3. 2.3

    Secure provisioning of assets

    Provision information and assets securely

    10 Qs
    Information & asset ownershipTangible vs. intangible inventoryAutomated discovery & reconciliationBaseline configuration at provisioningShadow IT & unmanaged cloudInventory through to disposal
  4. 2.4

    Data lifecycle management

    Manage data lifecycle

    10 Qs
    Owner, controller, custodian, processor, subjectCollection minimisation & purposeData location & jurisdictionRetention driven by law and needRemanence: clear, purge, destroyCryptographic erasure & degaussing
  5. 2.5

    Asset retention, EOL & EOS

    Ensure appropriate asset retention (e.g., End of Life (EOL), End of Support (EOS))

    10 Qs
    End of life vs. end of supportEOS as an inventory attributeGrowing residual risk after EOSCompensating controls for legacyExtended support contractsRetaining the means to read data
  6. 2.6

    Data security controls & compliance

    Determine data security controls and compliance requirements

    10 Qs
    Data at rest, in transit, in useScoping vs. tailoringStandards selectionData loss prevention (DLP)Digital rights management (DRM)Cloud access security broker (CASB)
Chris Rees

About the author

Chris Rees

Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.

More about Chris
All 8 CISSP domains

Sitting the whole exam? Get the Complete CISSP Collection.

Every domain of the exam, including this guide, for $129, one time.

See everything inside

Questions, answered

Do I need an account to buy?

No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.

Is this up to date with the real CISSP exam?

Yes. The guide is mapped module-by-module to the official ISC2 CISSP objectives (2.1–2.6), and lifetime updates are included, so as the exam evolves your guide does too.

What exactly do I get?

Instant access to the interactive online guide with all 60 practice questions, plus a 99-page PDF you can download, print, and keep forever.

Do I need the other domains too?

This guide covers Domain 2.0 (10% of the exam). To prepare for the whole exam, the Complete CISSP Collection bundles all 8 domains for $129, less than the price of three guides.

What if it isn't for me?

Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.

Who wrote it?

Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.

Be ready for 10% of the exam, for $24.95

Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.

Get the guide

Share this guide