2.2 Information & Asset Handling

CISSP Domain 2 ยท 2.2

Information & Asset Handling at a glance

Classification identifies how sensitive or important information and assets are.

Handling requirements translate that classification into practical rules for how information and assets may be accessed, stored, shared, transported and eventually disposed of.

๐Ÿท๏ธ

Classify

Understand the sensitivity and importance of the information or asset.

WHAT is it?
๐Ÿ“‹

Define Requirements

Establish how that classification must be protected.

HOW must it be treated?
๐Ÿ›ก๏ธ

Handle

Apply those requirements wherever the information or asset goes.

Are the rules being followed?

Classification becomes handling

๐Ÿท๏ธ Classification โ†’ How sensitive or important is it?
๐Ÿ‘ค Access โ†’ Who may use it?
๐Ÿ’พ Storage โ†’ Where may it be kept?
๐Ÿ“ค Transmission โ†’ How may it be sent?
๐Ÿค Sharing โ†’ Who may receive it?
๐Ÿ“ฆ Transport โ†’ How must physical assets or media move?
๐Ÿ—‘๏ธ Disposal โ†’ How must it eventually be removed?
1 What are Handling Requirements? Rules for protecting information and assets in practice

Handling requirements specify what users, systems and organisations are permitted or required to do with particular information and assets.

Requirements should reflect factors such as:

Classification Sensitivity Criticality Business Need Legal Requirements Regulation Contracts Organisational Policy
Example

A public marketing brochure may be freely emailed and published on the internet.

A database export containing customer personal information may require restricted access, approved storage and protected transmission.

Different classifications lead to different handling requirements.
Core principle

The more sensitive or critical the information or asset, the stronger its handling requirements are likely to be.

Classification vs Handling

Classification WHAT is it?
Handling HOW must I treat it?
Classification Confidential
Handling Restricted access ยท approved storage ยท protected sharing

Classification creates the requirement. Handling applies it.

2 Handling Throughout the Information Lifecycle Protection follows the information

Handling requirements should apply wherever information exists during its lifecycle.

๐Ÿ“ Create / Receive โ†’ Identify and classify appropriately
๐Ÿ‘ค Use โ†’ Limit use to authorised purposes
๐Ÿ’พ Store โ†’ Use appropriate storage locations
๐Ÿ“ค Share โ†’ Send only to authorised recipients
๐Ÿ“ฆ Transport โ†’ Protect physical assets and media
๐Ÿ—‘๏ธ Dispose โ†’ Remove information appropriately
Protection follows the data

Moving information from a corporate database into a spreadsheet does not automatically reduce its sensitivity.

3 Access and Use Who is allowed to handle the information?

Handling requirements should establish who may access information and for what legitimate purpose.

Useful questions

Who needs access?

Access should reflect legitimate business responsibilities.

What may they do?

Viewing information does not necessarily imply permission to modify, copy, export or delete it.

For how long?

Temporary business requirements may justify temporary rather than permanent access.

For what purpose?

Authorised access should be used for authorised business purposes.

Example

An employee has legitimate access to customer records in order to resolve customer complaints.

That does not automatically permit them to download the entire customer database for personal analysis.

๐Ÿ”‘ Need-to-Know and Least Privilege Access should match legitimate responsibilities
Need-to-Know

A person receives access to information needed to perform their authorised responsibilities.

Think: Which INFORMATION do you need?

Least Privilege

A person receives only the privileges needed to perform authorised tasks.

Think: What ACTIONS do you need to perform?

Example

A payroll employee needs access to salary records.

They may need permission to view and update specific payroll information.

They do not therefore automatically require database-administrator privileges.

Detailed access-control models are covered later in CISSP Domain 5. Here, the important idea is that information-handling permissions should reflect classification and legitimate business need.

4 Marking and Labelling Tell handlers what protection applies

Labels or markings can communicate classification and handling expectations to people and systems.

Document Header Document Footer Email Classification Metadata File Label Media Label Database Tag
Example

A report is visibly marked:

CONFIDENTIAL โ€” INTERNAL AUTHORISED RECIPIENTS ONLY

The visible marking helps users recognise that unrestricted forwarding is inappropriate.

Remember

Classification determines the category.

Labelling or marking communicates it.

5 Storage Requirements Where may the information be kept?

Classification may determine which storage locations are permitted.

Corporate Systems

Approved repositories may provide appropriate security controls.

Endpoints

Local device storage may require additional protection or may be prohibited for some information.

Cloud Storage

Only approved cloud services may be suitable for certain classifications.

Removable Media

USB drives and portable storage can create additional loss and disclosure risk.

Backups

Backup copies still contain the same underlying information.

Physical Records

Paper records may require locked or access-controlled storage.

Example

A confidential customer report is downloaded from an approved corporate application.

The employee saves another copy in a personal cloud-storage account so they can work from home.

The copy remains confidential even though its storage location has changed.
Copies inherit the risk

Creating another copy of sensitive information creates another location that must be protected.

6 Transmission Requirements How may information be sent?

Handling requirements should establish acceptable ways to transmit sensitive information.

Possible channels include

Email File Transfer Collaboration Platform API Messaging Physical Courier Removable Media

Important questions

Is the channel approved?

Sensitive data should use channels suitable for its classification.

Is the recipient authorised?

A secure transmission method does not make an unauthorised recipient acceptable.

Is protection required during transmission?

Appropriate technical protections may be required according to policy and data sensitivity.

Example

A confidential spreadsheet is encrypted before being emailed.

Unfortunately, it is sent to the wrong external customer.

Encryption does not correct an incorrect recipient decision.

Encryption and detailed protection of data in transit are covered more deeply in later CISSP domains, including Domain 2.6 and Domain 3.

7 Sharing Information Authorised sharing still needs control

Information may legitimately need to be shared with colleagues, customers, suppliers, regulators or other organisations.

Before sharing, ask:

Is the recipient authorised?
Do they genuinely need the information?
Is there a legal or contractual basis for sharing?
Are appropriate protections in place?
Can less information be shared?
Example

A supplier needs employee names and business email addresses to provide a service.

The supplier does not require salary, home address or medical information.

Share what is required rather than automatically sending the entire employee dataset.
๐Ÿค External and Third-Party Handling Protection requirements continue outside your organisation

Sending information to a supplier does not make its classification disappear.

External handling requirements may therefore need to be supported by:

Contracts Confidentiality Agreements Access Restrictions Approved Transfer Methods Retention Requirements Deletion Requirements
Example

An organisation sends confidential customer information to a specialist analytics supplier.

The supplier should be subject to appropriate requirements for how that information is accessed, stored, used, shared and eventually removed.

External location does not remove internal accountability

Organisations should understand how information continues to be protected when third parties handle it.

๐Ÿ–จ๏ธ Copying, Printing and Exporting Every additional copy creates additional exposure

Handling policies may restrict how sensitive information can be copied, printed, downloaded or exported.

Printing

Printed documents may be forgotten at shared printers or left in unsecured locations.

Downloading

Local copies may leave centrally managed repositories.

Copy / Paste

Information may move into another application with different protections.

Screenshots

Screenshots create new copies that may be stored or shared separately.

Exporting

Database exports can transform centrally controlled information into portable files.

Photographs

Mobile devices can create uncontrolled copies of sensitive displays or documents.

Example

A customer database is strongly protected by role-based access controls.

An authorised employee exports 100,000 customer records into a spreadsheet and stores it on their desktop.

The protection around the database does not automatically protect the exported copy.
๐Ÿ“„ Handling Physical Documents Information security is not limited to digital data

Information printed on paper remains information and may require protection according to its classification.

Secure Storage Controlled Printing Clear Desk Secure Transport Secure Disposal Access Restrictions
Example

A confidential employee report is printed for a meeting.

After the meeting it is left overnight on a desk accessible to cleaning contractors.

The information has been mishandled even though no computer system was compromised.
Think beyond computers

CISSP information security includes physical as well as digital manifestations of information.

๐Ÿ’ฝ Removable Media Portable information creates portable risk

Removable media can make large quantities of information easy to copy and transport.

Examples

USB Drives Portable SSDs Memory Cards Backup Media Optical Media

Handling considerations

  • whether removable media is permitted at all;
  • which classifications may be stored on it;
  • whether organisationally approved media must be used;
  • appropriate protection of stored information;
  • physical custody and transport;
  • inventory or accountability where appropriate;
  • sanitisation before reuse or disposal.
Example

A user copies restricted business information onto their personal USB drive so they can work from another computer.

Convenience does not override handling requirements.
8 Physical Transport Protect assets while they move between locations

Physical media and assets may require protection during transportation.

Packaging

Is the asset protected appropriately from damage or unauthorised access?

Courier

Is the delivery method appropriate for the asset's sensitivity?

Tracking

Does the organisation need evidence of where the asset is?

Chain of custody

For especially sensitive material, is accountability for possession required?

Recipient verification

Will the asset be released only to an authorised recipient?

Example

Backup media containing highly sensitive information is transported to an off-site storage location.

Appropriate handling requirements should cover the media while it is in transit, not just while it is stored at either endpoint.

โ˜๏ธ Cloud and SaaS Handling Easy sharing can create easy disclosure

Cloud collaboration platforms make information easy to store, copy and share.

Handling requirements should therefore address questions such as:

Is the cloud service approved?
Which classifications may be stored there?
Who can access the workspace?
Can users create public links?
Can external users be invited?
What happens to downloaded copies?
Example

A project team uploads confidential architecture documents to an approved collaboration platform.

One user changes the sharing setting to "Anyone with the link".

Using an approved platform does not remove the need for appropriate access and sharing settings.
๐Ÿ  Remote and Mobile Working Handling requirements travel with the information

Working outside an organisation's normal premises creates different handling risks.

Home Working Hotels Airports Trains Cafรฉs Customer Sites

Consider:

  • visibility of screens;
  • physical security of devices;
  • printed documents;
  • conversations in public places;
  • approved storage;
  • loss or theft;
  • secure disposal when away from the office.
Example

An employee reviews confidential acquisition plans on a laptop while sitting in an airport lounge.

Another traveller can clearly see the screen.

Confidentiality can be compromised without any technical attack.
๐Ÿ—ฃ๏ธ Verbal Information Conversations can disclose sensitive information too

Handling requirements can apply to information communicated verbally as well as information stored in documents or systems.

Example

Two employees discuss details of a confidential security incident in a crowded lift.

No file has been shared and no system has been accessed.

Sensitive information can still be disclosed to unauthorised people.
Information is information regardless of format

Digital, physical and verbal forms may all require appropriate handling.

9 Downgrading and Declassification Protection requirements can change

Information does not necessarily require the same classification or handling requirements forever.

Downgrading

Moving information to a lower classification or sensitivity level when authorised conditions are met.

Declassification

Removing a classification when the information no longer requires that protection, where the applicable framework permits it.

Example

Quarterly financial results are highly sensitive before official publication.

Once the organisation publishes the results through authorised channels, much of the same information becomes public.

Users should not downgrade information simply for convenience

Classification changes should follow authorised organisational procedures.

10 Disposal and Sanitisation Handling continues until information is safely removed

Sensitive information can remain recoverable after users believe they have deleted it.

Handling requirements should therefore specify appropriate disposal or sanitisation when information or media is no longer required.

Clear

Apply an appropriate sanitisation method so target data cannot be recovered through normal system interfaces or standard recovery techniques.

Purge

Apply stronger sanitisation intended to make recovery infeasible even using more advanced techniques.

Destroy

Physically render the media unusable when destruction is the appropriate sanitisation outcome.

Delete is not the same as sanitise

Removing a file from a directory does not necessarily make the underlying information unrecoverable.

Data remanence and destruction are covered in much greater detail in CISSP objective 2.4. This section establishes their relationship with information handling.

Example handling matrix

Organisations normally document handling requirements associated with their classification scheme.

The following is an illustrative example only.

Handling ActivityPublicInternalConfidentialRestricted
Public disclosurePermittedNoNoNo
Internal accessPermittedAuthorised usersBusiness needStrict need-to-know
External sharingPermittedControlledAuthorised onlyExceptional / highly controlled
StorageGeneral approved locationsApproved corporate storageApproved protected storageHighly controlled storage
TransmissionNormal channelsApproved channelsProtected approved channelsStrongly controlled methods
DisposalNormal disposalOrganisation policySecure disposalStrong sanitisation / destruction as required
Illustrative โ€” not universal

Actual handling requirements must come from the organisation's own policies and applicable legal, regulatory and contractual obligations.

๐Ÿ“ข Worked example: Public Information Low confidentiality does not mean no security

Consider an approved product brochure published on the company website.

Access

Public access is intentional.

Sharing

Unrestricted distribution is generally appropriate.

Storage

Strong confidentiality restrictions may not be necessary.

Integrity

The organisation still needs to prevent unauthorised modification of the official brochure.

Public โ‰  worthless

Public information may still require integrity and availability protection.

๐Ÿ‘ฅ Worked example: Confidential Customer Information Follow the classification through its handling requirements
Classification

Confidential.

Access

Limit to personnel with a legitimate business need.

Storage

Store only in appropriately approved corporate repositories.

Transmission

Use approved protected transmission methods according to policy.

External Sharing

Share only with authorised parties and under appropriate conditions.

Printing

Protect printed copies and avoid leaving them unattended.

Disposal

Use an appropriate secure disposal process when copies are no longer required.

The classification follows the information

Moving the customer information from a database to email, paper or a spreadsheet does not make it less confidential.

๐Ÿ” Worked example: Cryptographic Private Key Highly restricted asset handling

A production private signing key represents a highly sensitive security asset.

Access

Very small number of appropriately authorised identities.

Storage

Use strongly protected approved key-storage mechanisms.

Copying

Uncontrolled copies should not be created.

Sharing

Private keys should not simply be emailed or placed in general collaboration repositories.

Lifecycle

Appropriate processes should govern generation, use, backup, rotation, revocation and destruction.

The handling requirements reflect the consequence of compromise.
๐Ÿ‘ค Who establishes and implements handling requirements? Business accountability and operational implementation
Information / Asset Owner

Helps determine appropriate classification, business requirements and acceptable handling according to organisational policy.

Custodian

Implements and operates protection mechanisms in accordance with established requirements.

User

Handles information according to the rules and permissions associated with their authorised role.

Security Function

Provides security requirements, advice, controls, monitoring and governance support.

Example

HR determines that employee medical information requires strong protection.

Technology teams configure an approved repository with appropriate access restrictions.

HR employees then use the information according to the established handling rules.

โš™๏ธ Handling Exceptions Business need does not mean silently ignoring the rule

Occasionally, a legitimate business requirement may conflict with a standard handling rule.

Example

Policy normally prohibits sensitive information on removable media.

A regulated offline system requires an authorised data transfer using removable media.

The organisation should use an authorised exception or risk process rather than simply ignoring the handling policy.

An exception process may consider:

Business Justification Risk Approval Compensating Controls Time Limit Review
โš ๏ธ Common mistakes Handling concepts people frequently misunderstand
"Classification and handling are the same thing."

Classification identifies the protection category. Handling requirements determine what may be done with the information.

"Once information leaves the database, its classification no longer applies."

Copies generally retain the sensitivity of the information they contain.

"Encryption means I can send the information to anyone."

Technical protection does not make an unauthorised recipient authorised.

"An approved cloud service means anything can be uploaded."

Organisations may permit different classifications in different services or configurations.

"A user who can view something can automatically download it."

Different actions may require different permissions and handling requirements.

"Paper documents are not cybersecurity."

Sensitive information remains sensitive when printed.

"Deleting a file securely destroys the data."

Normal deletion does not necessarily sanitise the underlying storage media.

"Sharing with a supplier means the supplier decides how to protect it."

External handling requirements should be established according to the organisation's risk, contracts and applicable obligations.

"A screenshot is not a copy."

A screenshot may create another instance of sensitive information that requires protection.

"Users can lower a classification if it makes their work easier."

Downgrading or declassification should follow authorised procedures.

"Security should always use the strictest possible handling rule."

Controls should be appropriate to classification, business need, policy and risk rather than unnecessarily restrictive.

CISSP Exam Perspective

Let classification drive the handling decision

Handling questions often present a situation involving sensitive information and ask what should happen next.

Start by understanding the classification and organisational requirements rather than immediately selecting a technical product.

๐Ÿท๏ธ Classification clues

Sensitive Restricted Confidential Critical Label

๐Ÿ‘ค Access clues

Authorised Business Need Need-to-Know Permission

๐Ÿ’พ Storage clues

Cloud USB Local Copy Backup Repository

๐Ÿ“ค Sharing clues

Email Third Party External Recipient Transfer

๐Ÿ“ฆ Physical clues

Media Courier Paper Transport Storage

๐Ÿ—‘๏ธ Disposal clues

Delete Sanitise Purge Destroy Reuse
CISSP shortcut

Ask: "What is the classification, and what does organisational policy say may be done with information at that classification?"

๐Ÿ“ Practice scenarios Apply handling requirements

Scenario 1

A document is classified as Confidential.

What should determine how it may be stored and shared?

The organisation's handling requirements for that classification, together with applicable legal, regulatory and contractual obligations.

Scenario 2

A user exports sensitive information from an approved database into a spreadsheet.

Does the classification disappear?

No. The exported information should continue to be handled according to its sensitivity.

Scenario 3

Confidential information is encrypted and emailed to an unauthorised external recipient.

Was the handling appropriate?

No. Encryption does not make an unauthorised recipient authorised.

Scenario 4

An employee prints a sensitive report and leaves it beside a shared printer.

What type of handling issue occurred?

Inadequate physical protection of classified information.

Scenario 5

A user saves customer data to their personal cloud-storage account.

What principle applies?

Information should only be stored in locations permitted for its classification and organisational requirements.

Scenario 6

A supplier needs 10 customer records to investigate a support issue. The employee sends the complete database.

What handling principle was ignored?

Share only information required for the authorised business purpose.

Scenario 7

A classified document has been officially approved for public publication.

What may need to happen?

Its classification and handling requirements may be formally changed according to authorised procedures.

Scenario 8

Sensitive data on a storage device is no longer required.

Is deleting the files necessarily sufficient?

No. Appropriate media sanitisation may be required according to the sensitivity of the information and organisational policy.

Scenario 9

A user is authorised to view a restricted document but takes a screenshot and sends it to their personal email.

Why is this a problem?

Authorisation to view information does not automatically imply authorisation to create uncontrolled copies or send them externally.

Scenario 10

A backup tape containing confidential information is transported to an off-site facility.

When do the handling requirements apply?

During storage, transport and use โ€” not just at the original location.

Scenario 11

Two employees discuss confidential customer information loudly on a train.

Has information handling been compromised?

Potentially yes. Sensitive information can be disclosed verbally as well as electronically.

Scenario 12

Policy prohibits sensitive data on USB drives, but a specialist offline system requires one for an approved transfer.

What is the best approach?

Use the organisation's authorised exception and risk process with appropriate compensating controls rather than quietly ignoring the policy.

Scenario 13

An approved SaaS platform permits users to create anonymous public sharing links.

Does platform approval mean confidential information can be shared publicly?

No. Individual sharing settings must still comply with information handling requirements.

Scenario 14

An employee takes a photograph of a restricted architecture diagram displayed on a meeting-room screen.

What has happened?

A new copy of restricted information has been created and now needs appropriate protection.

Information Handling memory aid

Access Who may USE it?
Store Where may it LIVE?
Transmit How may it TRAVEL?
Share Who may RECEIVE it?
Copy May another COPY exist?
Dispose How must it END?

Access. Store. Send. Share. Dispose.

The question to ask every time

1 What is the CLASSIFICATION?
2 Who is AUTHORISED?
3 What does POLICY allow?
4 Is the METHOD appropriate?

Classification โ†’ Requirement โ†’ Handling

Key takeaways

CISSP objective 2.2 focuses on establishing information and asset handling requirements.

Classification identifies the protection category, while handling requirements define how information or assets should actually be treated.

Classification tells you WHAT it is. Handling tells you HOW to treat it.

Handling requirements may cover access, use, marking, storage, transmission, sharing, copying, physical transport, sanitisation and disposal.

Sensitive information should normally be accessed only for legitimate authorised business purposes.

A user's permission to view information does not automatically imply permission to download, copy, modify or redistribute it.

Information retains its sensitivity when copied into another format or location.

Exporting a database into a spreadsheet does not make the information less confidential.

Printed documents, conversations, screenshots and photographs can all contain sensitive information and therefore require appropriate handling.

External sharing should consider recipient authorisation, business need, contractual requirements and appropriate protection.

Using an approved cloud service does not automatically make every sharing configuration appropriate.

Removable media can create additional risk because information becomes highly portable.

Physical assets and media may require controls during transport as well as storage.

Classification may legitimately change over time, but downgrading or declassification should follow authorised processes.

Normal file deletion does not necessarily sanitise the underlying storage medium.

Handling requirements should be proportionate rather than automatically applying maximum restrictions to every asset.

Most importantly: once you know how sensitive or important something is, make sure its protection follows it everywhere it goes.

๐Ÿ“š Sources & Further Reading Authoritative references