CISSP Mastery · Module 2 / 8
Domain 2: Asset Security
From classification to destruction — know your data. Domain 2 frames ownership, privacy, and lifecycle controls so every other domain can safely build on top of the right assets.
Your progress
Domain 2 of 8 25%
10%
Exam weight
Data
Core lens
2 / 8
Domain focus
Privacy
GDPR · CCPA · HIPAA
Open preview · Domain overview
What Domain 2 is really about
Asset Security is where the CISSP forces you to speak the language of data. Before a control can be picked, you must know: who owns the data, how sensitive it is, where it lives, and how long it is allowed to live there.
Domain 2 sits between the governance mindset of Domain 1 and the access control mechanics of Domain 5. Get the data layer right and every downstream control stacks cleanly on top of it.
-
Data-centric thinking
Security starts at the data layer. Classification, labeling, and handling standards drive every downstream control (IAM, crypto, operations, disposal).
-
Ownership & accountability
CISSP loves role clarity. Data Owner (business) approves classification; Data Custodian (IT) enforces controls; users consume within the boundaries set by both.
-
Privacy as a first-class citizen
GDPR, CCPA, HIPAA, PIPEDA, LGPD — every privacy regime maps to the same vocabulary: lawful basis, purpose limitation, minimization, retention, subject rights.
-
Lifecycle, not snapshot
Assets are managed from create → store → use → share → archive → destroy. The exam tests lifecycle phases the way it tests the CIA triad in Domain 1.
Quick check
Domain 2 quiz
One question at a time — instant feedback. Pair it with the diagrams and Pro-Tip callouts above.
Quiz progress
Question 1 of 5
1.What is the PRIMARY purpose of an enterprise data retention schedule?
Exam Pro-Tip
Pro-Tip: Retention schedules align legal, regulatory, and business lifecycle requirements.
2.During a legal hold, what should records teams do FIRST?
Exam Pro-Tip
Pro-Tip: Legal holds override normal disposal timelines for the affected dataset.
3.Collecting only required personal data for a process reflects which principle?
Exam Pro-Tip
Pro-Tip: Minimization reduces privacy risk and limits breach impact.
4.When tailoring a control baseline to an organization, the BEST approach is to:
Exam Pro-Tip
Pro-Tip: Tailoring is risk-based and context-specific, not checklist maximalism.
5.Which statement BEST contrasts GDPR and CCPA/CPRA at a high level?
Exam Pro-Tip
Pro-Tip: Both strengthen privacy, but they differ in legal framing and obligations.
Your score: 0 / 5
Ready for Domain 3?
Module 2 covers classification, ownership, and the data lifecycle — the foundation every later domain builds on. Review the diagrams, finish the quick check, then continue through the remaining domains. All eight modules are free to study; the Final Mock Exam adds randomized questions and diagnostics when you are ready.