CISSP · Domain 2
Asset Security
About 10% of the exam
Data Classification
- Purpose: protection matched to sensitivity, value, criticality
- Owner classifies, not IT
- Classify at creation, reclassify when needed
- Government
- Top secret, secret, confidential, unclassified
- Commercial
- Confidential, private, internal, public
Data Lifecycle
- Create
- Store
- Use
- Share
- Archive
- Destroy
- Classify at create
- Secure at every stage
- Destroy is a controlled step, not deletion
Ownership and Roles
- Owner
- Business, classifies, approves access
- Custodian
- IT or security, implements controls
- User
- Uses data per policy
- Controller
- Decides purpose and means
- Processor
- Acts on the controller's instructions
- DPO
- Oversees privacy compliance
Data Handling Principles
- Need to know
- Least privilege
- Data minimization
- Purpose limitation
- Accuracy
- Retention limitation
- Secure disposal
Data Security Controls
Administrative
- Policies and procedures
- Awareness and training
- Contracts and NDAs
- Classification scheme
Technical
- Access control
- Encryption
- DLP
- Tokenization and masking
- Logging and monitoring
Physical
- Locks and guards
- CCTV
- Secure areas
- Environmental controls
Properties protected: confidentiality, integrity, availability, authenticity, non-repudiation
Data Protection Techniques
- Encryption
- At rest and in transit
- Tokenization
- Replace value with a token
- Masking
- Hide part of the data
- Anonymization
- Irreversibly remove identity
- Pseudonymization
- Reversible under control
- Hashing
- Integrity check
- Digital signature
- Integrity plus origin plus non-repudiation
Data States and Controls
At rest
- Disk and file encryption
- Access control
- Backups and redundancy
- TPM and self-encrypting drives
In use
- Least privilege
- Application controls
- Masking on screen
- Secure enclaves
In motion
- TLS
- IPsec and VPN
- Secure email
- Secure file transfer
Retention and Disposal
- Clear
- Purge
- Destroy
- Retain only as long as business, legal or regulatory need requires
- Legal hold overrides the schedule
- Clear
- Overwrite, reuse inside the organization
- Purge
- Degauss or crypto erase, leaves the organization
- Destroy
- Shred, pulverize, incinerate
Data remanence: deleting a file leaves the data on the media
Data Loss Prevention
- Discovers, monitors, protects sensitive data
- Identifies by pattern, label, fingerprint, context
- Actions: warn, block, quarantine, encrypt, log
- Covers rest, use and motion
Privacy Core Concepts
- Data subject
- The individual the data is about
- Lawful basis
- Consent, contract, legal duty, legitimate interest
- Purpose limitation
- Use only for the stated purpose
- Storage limitation
- Keep no longer than needed
GDPR Rapid Recall
- 72 hour breach notification to the regulator
- Right to erasure
- Data portability
- Privacy by design and by default
- Fines up to 4% of global turnover
Storage Security
Types
- DAS
- Direct attached
- NAS
- File level over the network
- SAN
- Block level dedicated network
- Cloud
- Provider managed
Controls
- Access control
- Encryption
- Backups and snapshots
- Replication
- Monitoring
Mobile and Removable Media
Mobile devices
- Encryption
- MDM or UEM
- Strong authentication
- Remote wipe
- App control
Removable media
- Authorization to use
- Encryption
- Malware scanning
- Use restrictions
- Auditing
Cloud Data Security
- Provider secures the cloud, customer secures what is in it
- Customer owns classification, access, encryption decisions
- Customer owns retention, disposal, configuration
- Contract defines where data may live
Reference strip
Key terms
- PII
- Personally identifiable information
- PHI, ePHI
- Protected health information
- CHD
- Cardholder data
- NDA
- Non disclosure agreement
Recovery terms
- RTO
- Recovery time objective
- RPO
- Recovery point objective
- SLA
- Service level agreement
Masking family
- Masking
- Hide part, static or dynamic
- Tokenization
- Swap for a meaningless token
- Anonymization
- Identity gone for good
- Pseudonymization
- Identity recoverable with a key
Sanitization by destination
- Reused internally
- Clear
- Leaving the organization
- Purge
- End of life
- Destroy
Baselines and scoping
- Baseline
- Minimum control set for a class
- Scoping
- Remove controls that do not apply
- Tailoring
- Adjust controls to the environment
Quick exam traps
- Trap: Encrypt first, classify later
- Trap: The IT administrator is the data owner
- Trap: Deleting a file destroys the data
- Trap: The cloud provider owns your data
- Trap: Backups are automatically secure
- Trap: Confidentiality and privacy are the same thing
- Trap: Anonymized data can be re-identified with a key
cybercertprep.com · original revision sheet written from the public body of knowledge