CISSP - Asset Security (10% of the exam) - Section 2.1

Identify and classify information and assets, including data classification and asset classification.

Define data and asset classification schemes based on sensitivity levels and criticality, and explain how government and commercial classification hierarchies differ. Apply classification labels to information and assets so that appropriate protective controls are consistently enforced.

data classificationasset classificationsensitivity levelscriticality

Practice question for this objective

Free sampleAsset Securitymedium

An information security manager is briefing executives on the difference between data classification and asset classification within the new information security policy. Which statement most accurately captures the relationship between them?

  • AData classification establishes the sensitivity and criticality of information, and asset classification ensures the systems, media, and components that handle that information receive at least equivalent protection. Correct
  • BAsset classification is performed first and the resulting label is automatically inherited by every data set processed on that asset.
  • CData classification is a regulatory obligation while asset classification is a purely voluntary engineering exercise without compliance relevance.
  • DData classification covers personal information only, while asset classification covers everything else including intellectual property and trade secrets.
Explain that data classification drives asset classification so that containers and processing systems receive protection commensurate with the data they handle. A defensible scheme classifies information first based on business impact, then propagates that requirement onto the assets that store, process, or transmit it. An asset normally inherits the highest classification of any data it touches, which is why aggregation and commingling are explicit considerations in the policy. This linkage prevents the common gap where well-classified data is handled on under-protected hardware or media.

Why A is correct: Data is classified by impact attributes, then asset classification propagates that protection requirement onto the containers, media, and processing components so that controls remain consistent across the whole information lifecycle.

Why B is wrong: Inheritance flows in the opposite direction. Candidates may pick this because hardware is more visible than data, but the asset typically inherits the highest classification of the data it processes, not the other way round.

Why C is wrong: Both activities support regulatory and contractual obligations such as data protection law and PCI DSS scoping. The distinction between mandatory and voluntary here is invented and would mislead any audit conversation.

Why D is wrong: Data classification covers all information types including intellectual property and operational data, not just personal data. This option blends a privacy mindset with classification and is a common misconception.

See more CISSP practice questions, answers explained.

Exam traps in Asset Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • Block the SaaS vendors at the corporate proxy and require marketing to use the on-premises analytics platform instead.

    Why it is wrong: A hard block protects the perimeter but ignores a legitimate business need, will likely be circumvented through personal devices or networks, and does nothing to bring the unknown assets and data flows under management.

  • The storage volume of the data set and the cost of the underlying media used to retain it.

    Why it is wrong: Storage cost is an operational consideration that may influence retention tiering but does not express the business impact of disclosure or loss. Candidates may pick this when conflating data lifecycle management with classification.

  • Reset each laptop to its factory image, sign a disposal log, and return the devices to the leasing company for resale in the secondary market.

    Why it is wrong: A factory reset does not reliably remove cached data on all storage types and is not an evidence-grade sanitisation step; for regulated patient data, this would not satisfy disposal requirements and exposes the hospital to breach risk.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.