CISSP - Asset Security - Section 2.3

Provision information and assets securely through information and asset ownership, asset inventory, and asset management.

Describe how asset ownership, asset inventory, and asset management practices collectively ensure that both tangible and intangible assets are provisioned securely throughout their lifecycle. Use an asset inventory as the authoritative record for driving access control, patch management, and retirement decisions.

asset inventoryasset ownershipasset managementtangible and intangible assets

Practice question for this objective

Free sampleAsset Securitymedium

An engineering firm holds patent filings, proprietary CAD models, and a portfolio of registered trademarks. A new security manager notes that physical laptops and servers are tracked in detail but the intellectual property itself appears nowhere in the asset register. Senior management asks how this should be addressed. What is the BEST recommendation?

  • ATreat the existing endpoint inventory as sufficient because the intellectual property is stored on those tracked devices.
  • BMove all intellectual property to an encrypted file share so that a single technical control protects it consistently.
  • CRely on the legal team's patent and trademark registers as the authoritative record for security purposes.
  • DExtend the inventory to record intangible assets such as patents, designs, and trademarks, each with a named owner and classification. Correct
Include intangible assets such as intellectual property in the asset inventory with ownership and classification so they receive appropriate protection. An asset register limited to hardware misses much of what the organisation needs to protect. Intellectual property, source code, datasets, trademarks, and brand are intangible assets whose value can exceed the devices that host them. Recording them with owners, classifications, and dependencies lets the security programme apply proportionate controls, scope incidents accurately, and align with legal and regulatory obligations specific to those asset types.

Why A is wrong: Tracking the container is not the same as tracking the asset; the same CAD model may exist on many endpoints, in backups, and with partners, so device-level inventory cannot drive classification, retention, or licensing decisions about the underlying information asset.

Why B is wrong: Centralising on an encrypted share is a reasonable handling control, but it presumes a governance baseline that does not yet exist; without an inventory and owners, the share's access decisions, retention, and incident scope remain undefined.

Why C is wrong: Legal registers track filing status and renewals, not the security attributes the organisation needs, such as classification, custodianship, handling rules, and dependency on supporting systems, so they cannot substitute for the security asset inventory.

Why D is correct: Asset security covers tangible and intangible assets alike. Recording intellectual property in the register with ownership and classification allows the firm to apply appropriate protection, value risk exposure, and meet legal obligations around patents and trademarks.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Asset Security objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.