CISSP - Asset Security (10% of the exam) - Section 2.2

Establish information and asset handling requirements covering marking, labelling, storage, and destruction.

Establish handling requirements that govern the marking, labelling, storage, and secure destruction of information and assets according to their classification. Recognise when data handling practices are inadequate and select the correct destruction method - degaussing, shredding, or cryptographic erasure - for a given media type.

data handlinglabellingstoragesecure destruction

Practice question for this objective

Free sampleAsset Securitymedium

A regional bank is rolling out a new four-tier data classification scheme. The CISO has approved the policy, but business unit managers are pushing back on the operational burden of marking every document. As the security manager leading the rollout, what should you do FIRST to ensure marking and labelling requirements take hold across the bank?

  • AEngage data owners to confirm classification criteria and define handling and labelling procedures tied to each tier Correct
  • BDeploy an automated classification and labelling tool across all endpoints to enforce marking technically
  • CIssue a memo from the CISO requiring all staff to label documents within thirty days or face disciplinary action
  • DSchedule mandatory awareness training so every employee understands the new classification tiers
Recognise that handling and labelling requirements must be defined with data owners before technical or administrative enforcement. Information handling requirements, including marking and labelling, are derived from classification. Classification is owned by the data owner, so the security manager's first move is to work with owners to confirm the criteria for each tier and the handling procedures that follow. Tooling, training, and sanctions are downstream controls that only work when they enforce an agreed standard.

Why A is correct: Asset handling and labelling derive from classification, which is the data owner's accountability. Confirming criteria and procedures with the owners produces an enforceable, business-aligned standard before any tool, audit, or training is layered on top.

Why B is wrong: Automated tooling is valuable later, but deploying it before data owners have agreed on classification criteria and labelling conventions produces inconsistent or wrong labels at scale. Technical enforcement of an unresolved policy disagreement is a classic over-technical CISSP trap.

Why C is wrong: An enforcement memo without agreed criteria or procedures produces inconsistent labels and resentment, and it bypasses the data owner's accountability for classification. Sanctions belong at the end of the rollout, not the start.

Why D is wrong: Training is necessary but premature: staff cannot be trained on procedures that have not yet been defined with data owners. Training delivered against draft criteria has to be repeated, which damages credibility of the programme.

See more CISSP practice questions, answers explained.

Exam traps in Asset Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • Continue using the existing cabinet but add a sign-out log so any access to the higher tier drives is recorded

    Why it is wrong: A sign-out log adds accountability but does not provide the segregated storage controls the higher tier requires. Mixing tiers in one container relies on procedure where the standard calls for physical separation matched to the sensitivity.

  • Perform a single-pass overwrite of the entire drive surface with zeros and document the completion log for the vendor.

    Why it is wrong: A single overwrite is the textbook answer for legacy magnetic media, which tempts candidates, but it is ineffective on flash storage because wear-levelling spares blocks the overwrite cannot reach, leaving recoverable customer data on the SSD.

  • The principle of separation of duties, because the same person both created the report and labelled it as internal.

    Why it is wrong: Separation of duties addresses fraud and collusion risks in process design rather than label inheritance. Candidates may reach for this familiar control phrase when the real issue is aggregation and inheritance.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.