by MTC Group, LLC
CISSP D2: Asset Security
Domain 2 covers the full lifecycle of information assets: classification, ownership and data roles, handling, retention, and remanence and destruction, plus the controls used to protect data in each state (at rest, in transit, in use). It's a smaller domain (10% weight) but a common source of missed points, in our experience, because the formal role definitions (who is accountable vs. who does the hands-on work) are precise in ways that don't always match how organizations talk about these roles informally.
Data owner vs. data custodian vs. data steward
Owner is accountable: an organizational official with authority for specified information who sets the policies for its generation, collection, processing, dissemination, and disposal (NIST treats owner and steward as one role). Custodian is responsible for the storage and safeguarding of the data. Where a separate data steward role exists, it maintains data names, business definitions, and integrity rules, and improves data quality within an assigned subject area.
Data states
At rest (not being processed or transmitted, located on disks, storage networks, or databases), in transit (moving across a network), and in use (actively processed in memory). Encryption is the standard protection at rest and in transit (TLS and IPsec for transmission), while protecting data in use, called confidential computing, relies on hardware features such as trusted execution environments (secure enclaves).
Data remanence
Residual data left behind after supposed deletion. Clearing (logical techniques, such as overwriting) vs. purging (defeats state-of-the-art laboratory recovery) vs. destroying (media no longer usable) are distinct sanitization methods with different assurance, and media type matters: on flash-based devices such as SSDs, spare cells and wear leveling mean overwriting cannot reach all areas where data was stored.
Data classification schemes
Government: Executive Order 13526 defines three classification levels, Top Secret (exceptionally grave damage to national security), Secret (serious damage), and Confidential (damage), and no other terms may be used for classified information. For other federal information, FIPS 199 assigns a potential impact level of low, moderate, or high. Know both contexts.
Clearing vs. purging vs. destroying
Clearing protects only against simple, non-invasive recovery through the same interface available to the user; purging makes recovery infeasible even with state-of-the-art laboratory techniques while leaving the media reusable; destroying also defeats laboratory recovery but leaves the media unusable. Which is "sufficient" depends on the sensitivity of the data: for moderate sensitivity data an owner may accept the risk of clearing, knowing some data may still be retrievable.
Data owner vs. system owner
Data (information) owner is accountable for the information itself; system owner is responsible for the procurement, development, operation, maintenance, and disposal of the system the data lives on. They may or may not be the same person, and a single system can host information belonging to multiple different information owners.
- [1]
- [2]
- [3]
- [4]
- [5]
- [6]
- [7]
- [8]
- [9]
- [10]
- [11]
- [12]
- [13]
- [14]
- [15]
- [16]
- [17]
Practice D2 questions with instant feedback, free to start, no card required.
Start Free© 2026 MTC Group, LLC. All rights reserved. InfoSec ExamPrep™ and the InfoSec ExamPrep logo are trademarks of MTC Group, LLC.
For personal exam preparation only. Printed from examprep.mtcgroupllc.com.