CISSP - Asset Security (10% of the exam) - Section 2.4

Manage the data lifecycle including data roles, collection, location, maintenance, retention, remanence, and destruction.

Describe the data lifecycle stages - collection, location, maintenance, retention, and destruction - and clarify the distinct responsibilities of data owners, data controllers, and data processors. Recognise data remanence risks and apply appropriate controls to prevent residual data from surviving intended destruction.

data ownersdata controllersdata processorsdata remanencedata lifecycle

Practice question for this objective

Free sampleAsset Securitymedium

A multinational manufacturer is establishing a data classification scheme and is debating the difference between data sensitivity and data criticality. Which statement best describes how these two attributes drive different control choices?

  • ASensitivity and criticality are interchangeable terms that both express the harm caused by unauthorised disclosure of the data.
  • BSensitivity is assigned by the data custodian based on storage cost, while criticality is assigned by the data owner based on regulatory class.
  • CSensitivity applies only to structured data in databases, while criticality applies only to unstructured data such as documents and media files.
  • DSensitivity reflects the impact if confidentiality is lost, while criticality reflects the impact on the business if the asset becomes unavailable or corrupted. Correct
Distinguish data sensitivity from data criticality and recognise that each attribute drives different security and resilience controls. Sensitivity expresses the harm caused if confidentiality is compromised and feeds into labelling, access control, and handling rules. Criticality expresses the harm to the business if the data or asset is unavailable or its integrity is lost, and feeds into recovery objectives and resilience planning. A payroll file may be highly sensitive but only moderately critical, while a real-time control signal may be low sensitivity yet highly critical, which is why the two attributes are tracked separately in a mature classification scheme.

Why A is wrong: This conflates the two concepts. Many candidates treat the words as synonyms because both relate to impact, but sensitivity speaks to disclosure harm while criticality speaks to availability and operational impact.

Why B is wrong: Both attributes are owner-led judgements aligned to business impact, not storage cost or regulatory class alone. Candidates may confuse this with role responsibilities, but classification ownership rests with the data owner in both cases.

Why C is wrong: Both attributes apply to any information asset regardless of structure. The structured or unstructured nature affects discovery and tagging mechanisms, not the attribute itself.

Why D is correct: Sensitivity is a confidentiality concept used to determine handling and labelling controls, whereas criticality is an availability and integrity concept used to drive recovery objectives and resilience controls. The two attributes can differ for the same asset.

See more CISSP practice questions, answers explained.

Exam traps in Asset Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • Approve the donation after verifying the factory reset completes successfully on each tablet

    Why it is wrong: A factory reset is not a recognised sanitisation method for media that held cardholder data. Residual data can often be recovered, so verifying the reset succeeded does not raise the assurance to the level the data classification requires.

  • Enable customer-managed encryption keys for the new cloud storage account and rotate them on a quarterly schedule.

    Why it is wrong: Customer-managed keys are a strong technical control and tempt candidates because they look like a definitive answer, but they do not by themselves establish whether the cross-border transfer is lawful, which is the prior question the data owner must resolve.

  • Wait until the engine reaches end-of-support and then accept the risk through a formal exception until migration funding is approved.

    Why it is wrong: Deferring action and pre-committing to a risk acceptance treats the EOS milestone as the trigger; CISSP expects planning to start when EOS is announced so that exposure does not begin on day one, and an exception is a last resort, not a first action.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.