This is the content of Assets Security of CISSP®

This domain 2 is worth 10% of the grade to be achieved

Domain 2 of CISSP®

Content updated according to the new official programme for 2024

Description
2.1Identify and classify Information and assets
2.1.1Data Classification
2.1.2Asset Classification
2.2Establish information and asset handling requirements
2.3Provision resources securely
2.3.1Information and asset ownership
2.3.2Asset inventory (eg, tangible, intangible)
2.3.3Asset management
2.4Manage data lifecycle
2.4.1Data roles (ie, owners, controllers, custodians, processors, users/subjects)
2.4.2Data collection
2.4.3Data location
2.4.4Data maintenance
2.4.5Data retention
2.4.6Data remanence
2.4.7Data Destruction
2.5Ensure appropriate asset retention (eg, End-of-Life (EOL), End-of-Support (EOS)
2.6Determine Data security controls and compliance requirements
2.6.1Data states (eg, in use, in transit, at rest)
2.6.2Scoping and tailoring
2.6.3Standards Selection
2.6.4Data protection methods (eg,Digital Rights Management (DRM),Data Loss Prevention (DLP), Cloud Access Security Broker (CASB)

Ready to Start?