2.2 Information & Asset Handling
Information & Asset Handling at a glance
Classification identifies how sensitive or important information and assets are.
Handling requirements translate that classification into practical rules for how information and assets may be accessed, stored, shared, transported and eventually disposed of.
Classify
Understand the sensitivity and importance of the information or asset.
WHAT is it?Define Requirements
Establish how that classification must be protected.
HOW must it be treated?Handle
Apply those requirements wherever the information or asset goes.
Are the rules being followed?Classification becomes handling
1 What are Handling Requirements? Rules for protecting information and assets in practice
Handling requirements specify what users, systems and organisations are permitted or required to do with particular information and assets.
Requirements should reflect factors such as:
A public marketing brochure may be freely emailed and published on the internet.
A database export containing customer personal information may require restricted access, approved storage and protected transmission.
Different classifications lead to different handling requirements.The more sensitive or critical the information or asset, the stronger its handling requirements are likely to be.
Classification vs Handling
Classification creates the requirement. Handling applies it.
2 Handling Throughout the Information Lifecycle Protection follows the information
Handling requirements should apply wherever information exists during its lifecycle.
Moving information from a corporate database into a spreadsheet does not automatically reduce its sensitivity.
3 Access and Use Who is allowed to handle the information?
Handling requirements should establish who may access information and for what legitimate purpose.
Useful questions
Access should reflect legitimate business responsibilities.
Viewing information does not necessarily imply permission to modify, copy, export or delete it.
Temporary business requirements may justify temporary rather than permanent access.
Authorised access should be used for authorised business purposes.
An employee has legitimate access to customer records in order to resolve customer complaints.
That does not automatically permit them to download the entire customer database for personal analysis.
๐ Need-to-Know and Least Privilege Access should match legitimate responsibilities
A person receives access to information needed to perform their authorised responsibilities.
Think: Which INFORMATION do you need?
A person receives only the privileges needed to perform authorised tasks.
Think: What ACTIONS do you need to perform?
A payroll employee needs access to salary records.
They may need permission to view and update specific payroll information.
They do not therefore automatically require database-administrator privileges.
Detailed access-control models are covered later in CISSP Domain 5. Here, the important idea is that information-handling permissions should reflect classification and legitimate business need.
4 Marking and Labelling Tell handlers what protection applies
Labels or markings can communicate classification and handling expectations to people and systems.
A report is visibly marked:
CONFIDENTIAL โ INTERNAL AUTHORISED RECIPIENTS ONLY
The visible marking helps users recognise that unrestricted forwarding is inappropriate.
Classification determines the category.
Labelling or marking communicates it.
5 Storage Requirements Where may the information be kept?
Classification may determine which storage locations are permitted.
Approved repositories may provide appropriate security controls.
Local device storage may require additional protection or may be prohibited for some information.
Only approved cloud services may be suitable for certain classifications.
USB drives and portable storage can create additional loss and disclosure risk.
Backup copies still contain the same underlying information.
Paper records may require locked or access-controlled storage.
A confidential customer report is downloaded from an approved corporate application.
The employee saves another copy in a personal cloud-storage account so they can work from home.
The copy remains confidential even though its storage location has changed.Creating another copy of sensitive information creates another location that must be protected.
6 Transmission Requirements How may information be sent?
Handling requirements should establish acceptable ways to transmit sensitive information.
Possible channels include
Important questions
Sensitive data should use channels suitable for its classification.
A secure transmission method does not make an unauthorised recipient acceptable.
Appropriate technical protections may be required according to policy and data sensitivity.
A confidential spreadsheet is encrypted before being emailed.
Unfortunately, it is sent to the wrong external customer.
Encryption does not correct an incorrect recipient decision.Encryption and detailed protection of data in transit are covered more deeply in later CISSP domains, including Domain 2.6 and Domain 3.
7 Sharing Information Authorised sharing still needs control
Information may legitimately need to be shared with colleagues, customers, suppliers, regulators or other organisations.
Before sharing, ask:
A supplier needs employee names and business email addresses to provide a service.
The supplier does not require salary, home address or medical information.
Share what is required rather than automatically sending the entire employee dataset.๐ค External and Third-Party Handling Protection requirements continue outside your organisation
Sending information to a supplier does not make its classification disappear.
External handling requirements may therefore need to be supported by:
An organisation sends confidential customer information to a specialist analytics supplier.
The supplier should be subject to appropriate requirements for how that information is accessed, stored, used, shared and eventually removed.
Organisations should understand how information continues to be protected when third parties handle it.
๐จ๏ธ Copying, Printing and Exporting Every additional copy creates additional exposure
Handling policies may restrict how sensitive information can be copied, printed, downloaded or exported.
Printed documents may be forgotten at shared printers or left in unsecured locations.
Local copies may leave centrally managed repositories.
Information may move into another application with different protections.
Screenshots create new copies that may be stored or shared separately.
Database exports can transform centrally controlled information into portable files.
Mobile devices can create uncontrolled copies of sensitive displays or documents.
A customer database is strongly protected by role-based access controls.
An authorised employee exports 100,000 customer records into a spreadsheet and stores it on their desktop.
The protection around the database does not automatically protect the exported copy.๐ Handling Physical Documents Information security is not limited to digital data
Information printed on paper remains information and may require protection according to its classification.
A confidential employee report is printed for a meeting.
After the meeting it is left overnight on a desk accessible to cleaning contractors.
The information has been mishandled even though no computer system was compromised.CISSP information security includes physical as well as digital manifestations of information.
๐ฝ Removable Media Portable information creates portable risk
Removable media can make large quantities of information easy to copy and transport.
Examples
Handling considerations
- whether removable media is permitted at all;
- which classifications may be stored on it;
- whether organisationally approved media must be used;
- appropriate protection of stored information;
- physical custody and transport;
- inventory or accountability where appropriate;
- sanitisation before reuse or disposal.
A user copies restricted business information onto their personal USB drive so they can work from another computer.
Convenience does not override handling requirements.8 Physical Transport Protect assets while they move between locations
Physical media and assets may require protection during transportation.
Is the asset protected appropriately from damage or unauthorised access?
Is the delivery method appropriate for the asset's sensitivity?
Does the organisation need evidence of where the asset is?
For especially sensitive material, is accountability for possession required?
Will the asset be released only to an authorised recipient?
Backup media containing highly sensitive information is transported to an off-site storage location.
Appropriate handling requirements should cover the media while it is in transit, not just while it is stored at either endpoint.
โ๏ธ Cloud and SaaS Handling Easy sharing can create easy disclosure
Cloud collaboration platforms make information easy to store, copy and share.
Handling requirements should therefore address questions such as:
A project team uploads confidential architecture documents to an approved collaboration platform.
One user changes the sharing setting to "Anyone with the link".
Using an approved platform does not remove the need for appropriate access and sharing settings.๐ Remote and Mobile Working Handling requirements travel with the information
Working outside an organisation's normal premises creates different handling risks.
Consider:
- visibility of screens;
- physical security of devices;
- printed documents;
- conversations in public places;
- approved storage;
- loss or theft;
- secure disposal when away from the office.
An employee reviews confidential acquisition plans on a laptop while sitting in an airport lounge.
Another traveller can clearly see the screen.
Confidentiality can be compromised without any technical attack.๐ฃ๏ธ Verbal Information Conversations can disclose sensitive information too
Handling requirements can apply to information communicated verbally as well as information stored in documents or systems.
Two employees discuss details of a confidential security incident in a crowded lift.
No file has been shared and no system has been accessed.
Sensitive information can still be disclosed to unauthorised people.Digital, physical and verbal forms may all require appropriate handling.
9 Downgrading and Declassification Protection requirements can change
Information does not necessarily require the same classification or handling requirements forever.
Moving information to a lower classification or sensitivity level when authorised conditions are met.
Removing a classification when the information no longer requires that protection, where the applicable framework permits it.
Quarterly financial results are highly sensitive before official publication.
Once the organisation publishes the results through authorised channels, much of the same information becomes public.
Classification changes should follow authorised organisational procedures.
10 Disposal and Sanitisation Handling continues until information is safely removed
Sensitive information can remain recoverable after users believe they have deleted it.
Handling requirements should therefore specify appropriate disposal or sanitisation when information or media is no longer required.
Apply an appropriate sanitisation method so target data cannot be recovered through normal system interfaces or standard recovery techniques.
Apply stronger sanitisation intended to make recovery infeasible even using more advanced techniques.
Physically render the media unusable when destruction is the appropriate sanitisation outcome.
Removing a file from a directory does not necessarily make the underlying information unrecoverable.
Data remanence and destruction are covered in much greater detail in CISSP objective 2.4. This section establishes their relationship with information handling.
Example handling matrix
Organisations normally document handling requirements associated with their classification scheme.
The following is an illustrative example only.
| Handling Activity | Public | Internal | Confidential | Restricted |
|---|---|---|---|---|
| Public disclosure | Permitted | No | No | No |
| Internal access | Permitted | Authorised users | Business need | Strict need-to-know |
| External sharing | Permitted | Controlled | Authorised only | Exceptional / highly controlled |
| Storage | General approved locations | Approved corporate storage | Approved protected storage | Highly controlled storage |
| Transmission | Normal channels | Approved channels | Protected approved channels | Strongly controlled methods |
| Disposal | Normal disposal | Organisation policy | Secure disposal | Strong sanitisation / destruction as required |
Actual handling requirements must come from the organisation's own policies and applicable legal, regulatory and contractual obligations.
๐ข Worked example: Public Information Low confidentiality does not mean no security
Consider an approved product brochure published on the company website.
Public access is intentional.
Unrestricted distribution is generally appropriate.
Strong confidentiality restrictions may not be necessary.
The organisation still needs to prevent unauthorised modification of the official brochure.
Public information may still require integrity and availability protection.
๐ฅ Worked example: Confidential Customer Information Follow the classification through its handling requirements
Confidential.
Limit to personnel with a legitimate business need.
Store only in appropriately approved corporate repositories.
Use approved protected transmission methods according to policy.
Share only with authorised parties and under appropriate conditions.
Protect printed copies and avoid leaving them unattended.
Use an appropriate secure disposal process when copies are no longer required.
Moving the customer information from a database to email, paper or a spreadsheet does not make it less confidential.
๐ Worked example: Cryptographic Private Key Highly restricted asset handling
A production private signing key represents a highly sensitive security asset.
Very small number of appropriately authorised identities.
Use strongly protected approved key-storage mechanisms.
Uncontrolled copies should not be created.
Private keys should not simply be emailed or placed in general collaboration repositories.
Appropriate processes should govern generation, use, backup, rotation, revocation and destruction.
๐ค Who establishes and implements handling requirements? Business accountability and operational implementation
Helps determine appropriate classification, business requirements and acceptable handling according to organisational policy.
Implements and operates protection mechanisms in accordance with established requirements.
Handles information according to the rules and permissions associated with their authorised role.
Provides security requirements, advice, controls, monitoring and governance support.
HR determines that employee medical information requires strong protection.
Technology teams configure an approved repository with appropriate access restrictions.
HR employees then use the information according to the established handling rules.
โ๏ธ Handling Exceptions Business need does not mean silently ignoring the rule
Occasionally, a legitimate business requirement may conflict with a standard handling rule.
Policy normally prohibits sensitive information on removable media.
A regulated offline system requires an authorised data transfer using removable media.
The organisation should use an authorised exception or risk process rather than simply ignoring the handling policy.An exception process may consider:
โ ๏ธ Common mistakes Handling concepts people frequently misunderstand
Classification identifies the protection category. Handling requirements determine what may be done with the information.
Copies generally retain the sensitivity of the information they contain.
Technical protection does not make an unauthorised recipient authorised.
Organisations may permit different classifications in different services or configurations.
Different actions may require different permissions and handling requirements.
Sensitive information remains sensitive when printed.
Normal deletion does not necessarily sanitise the underlying storage media.
External handling requirements should be established according to the organisation's risk, contracts and applicable obligations.
A screenshot may create another instance of sensitive information that requires protection.
Downgrading or declassification should follow authorised procedures.
Controls should be appropriate to classification, business need, policy and risk rather than unnecessarily restrictive.
Let classification drive the handling decision
Handling questions often present a situation involving sensitive information and ask what should happen next.
Start by understanding the classification and organisational requirements rather than immediately selecting a technical product.
๐ท๏ธ Classification clues
๐ค Access clues
๐พ Storage clues
๐ค Sharing clues
๐ฆ Physical clues
๐๏ธ Disposal clues
Ask: "What is the classification, and what does organisational policy say may be done with information at that classification?"
๐ Practice scenarios Apply handling requirements
Scenario 1
A document is classified as Confidential.
What should determine how it may be stored and shared?
The organisation's handling requirements for that classification, together with applicable legal, regulatory and contractual obligations.
Scenario 2
A user exports sensitive information from an approved database into a spreadsheet.
Does the classification disappear?
No. The exported information should continue to be handled according to its sensitivity.
Scenario 3
Confidential information is encrypted and emailed to an unauthorised external recipient.
Was the handling appropriate?
No. Encryption does not make an unauthorised recipient authorised.
Scenario 4
An employee prints a sensitive report and leaves it beside a shared printer.
What type of handling issue occurred?
Inadequate physical protection of classified information.
Scenario 5
A user saves customer data to their personal cloud-storage account.
What principle applies?
Information should only be stored in locations permitted for its classification and organisational requirements.
Scenario 6
A supplier needs 10 customer records to investigate a support issue. The employee sends the complete database.
What handling principle was ignored?
Share only information required for the authorised business purpose.
Scenario 7
A classified document has been officially approved for public publication.
What may need to happen?
Its classification and handling requirements may be formally changed according to authorised procedures.
Scenario 8
Sensitive data on a storage device is no longer required.
Is deleting the files necessarily sufficient?
No. Appropriate media sanitisation may be required according to the sensitivity of the information and organisational policy.
Scenario 9
A user is authorised to view a restricted document but takes a screenshot and sends it to their personal email.
Why is this a problem?
Authorisation to view information does not automatically imply authorisation to create uncontrolled copies or send them externally.
Scenario 10
A backup tape containing confidential information is transported to an off-site facility.
When do the handling requirements apply?
During storage, transport and use โ not just at the original location.
Scenario 11
Two employees discuss confidential customer information loudly on a train.
Has information handling been compromised?
Potentially yes. Sensitive information can be disclosed verbally as well as electronically.
Scenario 12
Policy prohibits sensitive data on USB drives, but a specialist offline system requires one for an approved transfer.
What is the best approach?
Use the organisation's authorised exception and risk process with appropriate compensating controls rather than quietly ignoring the policy.
Scenario 13
An approved SaaS platform permits users to create anonymous public sharing links.
Does platform approval mean confidential information can be shared publicly?
No. Individual sharing settings must still comply with information handling requirements.
Scenario 14
An employee takes a photograph of a restricted architecture diagram displayed on a meeting-room screen.
What has happened?
A new copy of restricted information has been created and now needs appropriate protection.
Information Handling memory aid
Access. Store. Send. Share. Dispose.
The question to ask every time
Classification โ Requirement โ Handling
Key takeaways
CISSP objective 2.2 focuses on establishing information and asset handling requirements.
Classification identifies the protection category, while handling requirements define how information or assets should actually be treated.
Classification tells you WHAT it is. Handling tells you HOW to treat it.
Handling requirements may cover access, use, marking, storage, transmission, sharing, copying, physical transport, sanitisation and disposal.
Sensitive information should normally be accessed only for legitimate authorised business purposes.
A user's permission to view information does not automatically imply permission to download, copy, modify or redistribute it.
Information retains its sensitivity when copied into another format or location.
Exporting a database into a spreadsheet does not make the information less confidential.
Printed documents, conversations, screenshots and photographs can all contain sensitive information and therefore require appropriate handling.
External sharing should consider recipient authorisation, business need, contractual requirements and appropriate protection.
Using an approved cloud service does not automatically make every sharing configuration appropriate.
Removable media can create additional risk because information becomes highly portable.
Physical assets and media may require controls during transport as well as storage.
Classification may legitimately change over time, but downgrading or declassification should follow authorised processes.
Normal file deletion does not necessarily sanitise the underlying storage medium.
Handling requirements should be proportionate rather than automatically applying maximum restrictions to every asset.
Most importantly: once you know how sensitive or important something is, make sure its protection follows it everywhere it goes.
๐ Sources & Further Reading Authoritative references
- ISC2 โ CISSP Certification Exam Outline
View official CISSP exam outline - NIST SP 800-53 Rev. 5 โ Security and Privacy Controls for Information Systems and Organizations
View NIST publication - NIST โ Media Protection
View NIST media-protection guidance - NIST SP 800-88 Rev. 2 โ Guidelines for Media Sanitization
View NIST media-sanitisation guidance
