CISSP - Asset Security - Section 2.6

Determine data security controls and compliance requirements including data states, scoping and tailoring, standards selection, and data protection methods.

Determine data security controls for data at rest, in transit, and in use by scoping and tailoring selected standards to the organisation's environment. Choose between DRM, DLP, and CASB tools based on where the data resides and what protection outcome is required.

data statesscoping and tailoringDRMDLPCASB

Practice question for this objective

Free sampleAsset Securitymedium

A pharmaceutical research firm is decommissioning a server room that held mixed media: solid-state drives with clinical trial data, magnetic tapes from legacy backups, and several optical discs containing draft patents. The CIO wants a single destruction method applied to all media to simplify the project. As the asset security lead, what is the BEST response?

  • AAgree, and use a cross-cut shredder rated for optical media, since shredding physically destroys all three media types
  • BPush back and select a destruction method per media type aligned to the data classification and recognised sanitisation guidance Correct
  • CAgree, and degauss everything in a single pass because degaussing is media-agnostic and irreversible
  • DAgree, and incinerate all media together in a certified facility because incineration is recognised as the highest assurance method
Destruction methods must be selected per media type and aligned to data classification, not chosen for operational convenience. Recognised sanitisation guidance, including NIST SP 800-88, defines destruction methods by media type because different media respond differently to clearing, purging, and destruction. Magnetic media can be degaussed, solid-state media generally cannot, and optical media require physical destruction. A risk-led security manager aligns the method to both the media and the data classification rather than accepting a one-size-fits-all approach that may leave residual data recoverable.

Why A is wrong: Although shredding can be applied broadly, a single shredder rated for optical discs may not meet the particle-size requirements for SSDs holding regulated clinical trial data, and applying one method to all media without verifying suitability defeats the purpose of media-specific destruction standards.

Why B is correct: Sanitisation guidance such as NIST SP 800-88 maps destruction techniques to media type and data sensitivity. Choosing per-media methods aligned to classification is the defensible answer for regulated clinical and patent data, even if it adds project complexity.

Why C is wrong: Degaussing only works on magnetic media. It has no effect on solid-state drives or optical discs, so applying it as a universal method would leave high-sensitivity data recoverable on the non-magnetic media.

Why D is wrong: Incineration is highly effective, but committing to a single method without considering cost, environmental permits, transport custody, and whether each media type actually needs that level of assurance is poor risk management. The method must match the classification, not the convenience of a single process.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Asset Security objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.