All domains

Domain 2 · 10% of the exam

Asset Security

Security professionals must understand the importance of asset security and the different measures that can be used to protect assets throughout their life cycle. This includes not only technical controls but also physical security measures, disaster recovery planning, and privacy considerations.

Learning objectives

  • Identify, classify, and categorize information assets.
  • Explain the importance of treating information as an asset.
  • Differentiate the IT asset management lifecycle from the data security lifecycle.
  • Relate the data states of in use, in transit, and at rest to the data lifecycle.
  • Relate the different roles that people and organizations have with respect to data.
  • Describe the different security control types and categories.
  • Explain the use of data security standards and baselines to meet organizational compliance requirements.

Key topics

  • Provision Information & Assets Securely
  • Information & Asset Handling
  • Manage Data Life Cycle
  • Appropriate Asset Retention
  • Data Security Controls & Compliance

Lessons

Ordered the way the course presents them. Work top to bottom, or jump to whatever you need.

  1. 01Data Remanence - DefinitionData remanence is defined as the residual data remaining on some sort of object after the data has been deleted or erased.2 slides · 1 min read
  2. 02Data RetentionInformation and data should be kept only for as long as it is required, no more, and no less. For various types of data, certain industry standards, laws and regulations define retention periods, when such external requirements are not set, it is the…4 slides · 1 min read
  3. 03Data in TransitData in transit refers to data that is actively being transmitted from one location to another, typically across a network or the internet.5 slides · 2 min read
  4. 04Data in Transit - Description of Risk and RecommendationsThe risks associated with data in motion are the same as those associated with data at rest. These include:3 slides · 2 min read
  5. 05Data MaintenanceThroughout its life cycle, data is accessed, viewed, processed, or used in various ways. Maintaining the confidentiality, integrity and availability of the data is key in maintaining the data and its intended purposes. Data maintenance requires…3 slides · 1 min read
  6. 06Baseline (USGCB) and Baseline Security System ISKEF00002 slides · 1 min read
  7. 07Scoping and TailoringWhen choosing to implement security frameworks, baselines, or standards, organizations may decide to implement only specific parts through the process of scoping and tailoring.3 slides · 2 min read
  8. 08Data at RestData at rest refers to information that is not being actively processed or transmitted and that is stored on a persistent storage medium.3 slides · 1 min read
  9. 09Standards SelectionOrganizations use security standards to assess security programs and risks, improve defenses, and meet regulatory requirements across various industries and jurisdictions.2 slides · 1 min read
  10. 10Generally Accepted PrinciplesThis section introduces some generally accepted principles that address information security from a high-level viewpoint that can provide comprehensive guidance to organizations.5 slides · 2 min read
  11. 11Information Asset InventoryData or information assets are considered intangible sets of ideas, numbers, values, or relationships that are the lifeblood of the digital organization.5 slides · 4 min read
  12. 12Link and End-to-End EncryptionData are encrypted on a network using either link or end-to-end encryption. In general, link encryption is performed by service providers, such as a data communications provider on a frame relay network. Link encryption encrypts all the data along a…4 slides · 1 min read
  13. 13Data CollectionData collection is the first step in the data life cycle. This step includes the creation and acquisition of new content and the update of existing content.3 slides · 1 min read
  14. 14End of Life and End of SupportEnd of life and end of support for IT systems is generally discussed in terms of the hardware, software, and business processes that have to be either decommissioned, replaced, or taken on as technological orphans and supported with in-house resources.3 slides · 2 min read
  15. 15Data LocationWAZ TVRZ TAW/3 slides · 1 min read
  16. 16Case Study - Facebook and Cambridge AnalyticaCase studyThe Cambridge Analytica scandal, which unfolded in 2018, marked a significant privacy breach with global ramifications. At the core of the incident was the unauthorized access and exploitation of personal data from approximately 87 million Facebook users.4 slides · 2 min read
  17. 17Possible Responses (Case Study - Facebook and Cambridge Analytica)Case study answersPossible Responses (Case Study: Facebook and Cambridge Analytica)3 slides · 1 min read
  18. 18The Data Security Life CycleAll ideas, data, information, or knowledge can be thought of as going through six major sets of activities throughout its lifetime.9 slides · 4 min read
  19. 19Case Study - SolarwindsCase studyThe Solar Winds cyberattack, discovered in December 2020, was a sophisticated supply chain attack that targeted the Solar Winds Orion software, a widely used IT infrastructure monitoring and management tool.5 slides · 2 min read
  20. 20Classification and CategorizationOnce we have an inventory of assets, understanding the value of those assets becomes the next step as it will drive asset classification, which, in turn, will drive the protection of those assets throughout their life cycle.9 slides · 2 min read
  21. 21Information Asset OwnershipAn information asset is data with value to the organization, and identifying an asset owner ensures accountability for protection and proper maintenance.3 slides · 2 min read
  22. 22Data Classification and Categorization PolicyA data classification and categorization policy is a formal set of guidelines for categorizing data, defining handling procedures, and assigning roles and responsibilities.4 slides · 3 min read