CISSP · CISSP

CISSP Domain 2: Asset Security

Data classification, ownership, and asset handling requirements tested on CISSP Domain 2.

36 cards · basic cards · AI-written, checked twice. Edit anything.

Study this set free Get FlashKeepers for iPhone
What is the primary goal of information classification in asset security?
To assign sensitivity levels to data that determine how it must be protected, stored, and handled based on its value and risk.
Name four common data classification levels used in organizations.
Public, Internal, Confidential, and Restricted (or Secret). Specific names vary by organization.
What does the data owner role involve?
Setting classification levels, defining access permissions, approving data use, and ensuring compliance with policies.
What is the primary responsibility of a data custodian?
Implementing the data owner's protection requirements, managing day-to-day storage, backup, and access control enforcement.
Define personally identifiable information (PII).
Information that can be used to identify an individual, such as name, Social Security number, date of birth, email, or financial account details.
What is protected health information (PHI)?
Health data that can identify an individual, regulated under HIPAA, including medical records, treatment history, and insurance claims.
What does data stewardship require?
Accountability for data quality, proper handling, and compliance with regulations and organizational policies throughout the data lifecycle.
What is a data controller under GDPR?
The entity that determines the purposes and means of processing personal data.
What is a data processor under GDPR?
An entity that processes personal data on behalf of and under instruction from a data controller.
What is the purpose of a data retention policy?
To specify how long each type of data must be kept before approved deletion, balancing legal/operational needs with privacy.
What is data minimization?
A privacy principle requiring collection and retention of only the minimum personal data necessary for a stated purpose.
What does purpose limitation mean?
Personal data collected for one purpose cannot be used for an unrelated purpose without additional consent or legal authority.
What is an asset inventory in information security?
A documented record of all organizational data assets, their classification, location, owner, and protection requirements.
What is data labeling?
Marking assets with visible or embedded classification levels so handling requirements are clear to anyone who accesses the data.
What encryption level is typically required for confidential or restricted data?
Strong encryption (AES-256 or equivalent) both in transit and at rest.

21 more cards in the app