CISSP Domain 2: Asset Security
Domain 2.0: Asset Security · 10% of the exam
Everything that follows from knowing what you hold and what it is worth: all 6 objectives (2.1–2.6), from classifying information and assets through handling requirements, secure provisioning, the full data lifecycle including remanence and destruction, asset retention past end of support, and the controls and compliance requirements classification drives.
All study guides, current and every new one.
- Interactive online guide
- Downloadable PDF
- Lifetime updates
- 30-day money-back guarantee
Secure checkout via Stripe · no account needed · instant access
10% of your exam score
Domain 2.0 is worth 10% of the CISSP exam. Walk in having mastered it, not hoping it doesn't come up.
Every objective, nothing extra
Built line by line from the official ISC2 CISSP objectives 2.1–2.6: 25 in-depth topics with worked scenarios and exam tips, in a 99-page guide you'll actually finish.
60 exam-style questions
Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.
The cert that changes what you're paid
CISSP is the management-track credential for security: five years of experience to hold it, eight domains wide, and the one most senior security job descriptions name by itself.
Serving, transitioning, or a military spouse?
CISSP appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →
Read a real excerpt, free
This is the actual opening of Module 2.1, Identifying & classifying assets, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.
Identify and classify information and assets
Grading information and the assets that hold it, the label sets the exam expects, who assigns them, and why schemes with too many levels fail.
Tomas Berg's job title at Aurora Logistics was Head of Data Governance, and his first week produced a number that made the classification problem concrete: 61% of documents in the corporate file store were marked Confidential. The lunch menu was Confidential. The office move plan was Confidential. So were the customs valuation models that a competitor would genuinely pay for.
A scheme in which most things carry the highest label is not a strict scheme. It is a scheme that has stopped conveying information, and the practical result is that nobody treats the label as meaningful — including for the documents where it matters.
Two related activities
| Activity | Applies to | Driven by |
|---|---|---|
| Data classification | Information itself, in any form — a database, a report, a spreadsheet, a conversation recording. | The impact of unauthorized disclosure, modification or loss. |
| Asset classification | The systems, devices, media and facilities that process or store that information. | The highest classification of any data the asset handles — classification flows up, never down. |
A laptop that holds one Confidential file and a thousand Public ones is a Confidential asset, and is handled, transported and destroyed as such. This is the rule behind data spillage procedures: introducing higher-classified data into a lower-classified system raises the whole system's classification until it is properly remediated.
Label sets
| Government | Damage from disclosure | Commercial equivalent |
|---|---|---|
| Top Secret | Exceptionally grave damage to national security. | Confidential / Proprietary — the organization's most sensitive material. |
| Secret | Serious damage. | Private — personal data whose disclosure harms individuals. |
| Confidential | Identifiable damage. | Sensitive — internal material needing more than default care. |
| Unclassified | No damage; may still be controlled (e.g. “Sensitive but Unclassified”, “For Official Use Only”). | Public — disclosure causes no harm. |
The commercial column is a convention rather than a standard; organizations name their own levels. What the exam expects is that you recognise the government sequence and its damage language, understand that commercial schemes mirror the logic, and know that the number of levels should be small.
What drives a grading
| Criterion | Question it asks |
|---|---|
| Value to the organization | What is lost commercially if this becomes public or is corrupted? |
| Legal and regulatory obligation | Does a law require particular protection — personal data, health data, cardholder data, export-controlled technology? |
| Harm to individuals | Could disclosure cause distress, discrimination or physical risk to a person? |
| Contractual commitment | Has a customer been promised specific handling? |
| Useful lifetime | Does the sensitivity decay? A quarterly result is market-sensitive before publication and public afterwards. |
| Aggregation effect | Do individually harmless records become sensitive in volume or combination? |
Not ready to buy? Read it later.
We'll email you a free sample of this guide as a PDF, no purchase needed.
Try 3 sample questions
Pulled straight from the guide's 60-question bank. Tap an answer for instant feedback and the explanation.
From module 2.1 · Identifying & classifying assets
1. A laptop stores one Restricted file alongside a thousand Public files. What is the laptop's classification?
From module 2.2 · Information & asset handling
1. An employee improvises a method for sending a sensitive file to a customer. What control is missing?
From module 2.3 · Secure provisioning of assets
1. An outage is caused by an expired TLS certificate that no team had recorded or owned. What category of failure is this?
57 more questions like these are waiting inside.
What's inside
- 25 in-depth topics across 6 modules, mapped to objectives 2.1–2.6
- 60 exam-style practice questions with instant feedback
- Full answer key explaining why every distractor is wrong
- Clear, purge and destroy, and which method works on which medium
- Why degaussing does nothing to an SSD
- Complete CISSP acronym & key-term reference
- 99-page downloadable PDF for offline study and printing
- Lifetime updates as the exam evolves
The modules, mapped to the objectives
- 2.110 Qs
Identifying & classifying assets
Identify and classify information and assets
Data vs. asset classificationGovernment & commercial label setsImpact-based grading criteriaThe data owner's roleOver-classificationLabelling & marking - 2.210 Qs
Information & asset handling
Establish information and asset handling requirements
Marking & labelling mediaStorage and transmission rulesCopying & printing controlsMedia in transitThird-party handling obligationsDeclassification - 2.310 Qs
Secure provisioning of assets
Provision information and assets securely
Information & asset ownershipTangible vs. intangible inventoryAutomated discovery & reconciliationBaseline configuration at provisioningShadow IT & unmanaged cloudInventory through to disposal - 2.410 Qs
Data lifecycle management
Manage data lifecycle
Owner, controller, custodian, processor, subjectCollection minimisation & purposeData location & jurisdictionRetention driven by law and needRemanence: clear, purge, destroyCryptographic erasure & degaussing - 2.510 Qs
Asset retention, EOL & EOS
Ensure appropriate asset retention (e.g., End of Life (EOL), End of Support (EOS))
End of life vs. end of supportEOS as an inventory attributeGrowing residual risk after EOSCompensating controls for legacyExtended support contractsRetaining the means to read data - 2.610 Qs
Data security controls & compliance
Determine data security controls and compliance requirements
Data at rest, in transit, in useScoping vs. tailoringStandards selectionData loss prevention (DLP)Digital rights management (DRM)Cloud access security broker (CASB)

About the author
Chris Rees
Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.
More about ChrisSitting the whole exam? Get the Complete CISSP Collection.
Every domain of the exam, including this guide, for $129, one time.
See everything insideQuestions, answered
Do I need an account to buy?
No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.
Is this up to date with the real CISSP exam?
Yes. The guide is mapped module-by-module to the official ISC2 CISSP objectives (2.1–2.6), and lifetime updates are included, so as the exam evolves your guide does too.
What exactly do I get?
Instant access to the interactive online guide with all 60 practice questions, plus a 99-page PDF you can download, print, and keep forever.
Do I need the other domains too?
This guide covers Domain 2.0 (10% of the exam). To prepare for the whole exam, the Complete CISSP Collection bundles all 8 domains for $129, less than the price of three guides.
What if it isn't for me?
Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.
Who wrote it?
Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.
Be ready for 10% of the exam, for $24.95
Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.
Get the guide