CISSP - Asset Security - Section 2.1

Identify and classify information and assets, including data classification and asset classification.

Define data and asset classification schemes based on sensitivity levels and criticality, and explain how government and commercial classification hierarchies differ. Apply classification labels to information and assets so that appropriate protective controls are consistently enforced.

data classificationasset classificationsensitivity levelscriticality

Practice question for this objective

Free sampleAsset Securitymedium

An information security manager is briefing executives on the difference between data classification and asset classification within the new information security policy. Which statement most accurately captures the relationship between them?

  • AData classification establishes the sensitivity and criticality of information, and asset classification ensures the systems, media, and components that handle that information receive at least equivalent protection. Correct
  • BAsset classification is performed first and the resulting label is automatically inherited by every data set processed on that asset.
  • CData classification is a regulatory obligation while asset classification is a purely voluntary engineering exercise without compliance relevance.
  • DData classification covers personal information only, while asset classification covers everything else including intellectual property and trade secrets.
Explain that data classification drives asset classification so that containers and processing systems receive protection commensurate with the data they handle. A defensible scheme classifies information first based on business impact, then propagates that requirement onto the assets that store, process, or transmit it. An asset normally inherits the highest classification of any data it touches, which is why aggregation and commingling are explicit considerations in the policy. This linkage prevents the common gap where well-classified data is handled on under-protected hardware or media.

Why A is correct: Data is classified by impact attributes, then asset classification propagates that protection requirement onto the containers, media, and processing components so that controls remain consistent across the whole information lifecycle.

Why B is wrong: Inheritance flows in the opposite direction. Candidates may pick this because hardware is more visible than data, but the asset typically inherits the highest classification of the data it processes, not the other way round.

Why C is wrong: Both activities support regulatory and contractual obligations such as data protection law and PCI DSS scoping. The distinction between mandatory and voluntary here is invented and would mislead any audit conversation.

Why D is wrong: Data classification covers all information types including intellectual property and operational data, not just personal data. This option blends a privacy mindset with classification and is a common misconception.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Asset Security objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.