2.6 Data Security Controls

CISSP Domain 2 ยท 2.6

Data Security Controls at a glance

Data needs different protection depending on what it is, where it is, what is happening to it and which security or compliance requirements apply.

Effective data security therefore starts by understanding the data, determining its state and applicable requirements, and then selecting controls that appropriately reduce the risk.

๐Ÿ’พ

At Rest

Data stored on disks, databases, backups or other repositories.

Where is it STORED?
โ†”๏ธ

In Transit

Data moving between systems, users, applications or networks.

Where is it MOVING?
โš™๏ธ

In Use

Data actively being processed by applications and systems.

How is it being PROCESSED?

Data Security Control thinking flow

๐Ÿท๏ธ Classify โ†’ What kind of data is it?
๐Ÿ“ Locate โ†’ Where does it exist?
๐Ÿ”„ State โ†’ Is it at rest, in transit or in use?
๐Ÿ“œ Requirements โ†’ Which business, legal, contractual or regulatory rules apply?
๐ŸŽฏ Scope โ†’ Which systems and processes are affected?
๐Ÿ›ก๏ธ Controls โ†’ What protection is appropriate?
โœ… Validate โ†’ Are the requirements actually being met?
1 What are Data Security Controls? Measures that protect information according to its requirements

Data security controls are safeguards used to protect information against threats such as unauthorised disclosure, modification, destruction or inappropriate use.

Controls may be:

Administrative Technical Physical Preventive Detective Corrective

Examples include:

Encryption Access Control DLP DRM CASB Masking Tokenisation Monitoring Physical Security Policies
Start with the requirement, not the product

The objective is not to deploy as many security technologies as possible.

Controls should address the sensitivity, risk, state and applicable requirements of the data.

2 The Three Data States At rest ยท In transit ยท In use

One of the most important concepts in CISSP Domain 2 is recognising that data exists in different states and that each state introduces different security considerations.

๐Ÿ’พ Data at Rest

Data stored on persistent or other storage rather than actively moving between systems.

Database Hard Drive Backup USB Cloud Storage
โ†”๏ธ Data in Transit

Data moving between users, systems, applications or network locations.

HTTPS API Call Email File Transfer Network Traffic
โš™๏ธ Data in Use

Data actively being processed, manipulated or consumed by a system or application.

Application Memory CPU Processing User Editing Database Query Analytics

Data States memory aid

At Rest STORED
In Transit MOVING
In Use PROCESSING

Stored. Moving. Processing.

3 Data at Rest Protect information while it is stored

Data at rest includes information stored in locations such as:

Databases File Systems Laptops Mobile Devices Cloud Storage Backups Archives Removable Media

Typical protection considerations

Encryption

Protect stored information against unauthorised disclosure.

Access Control

Restrict which users, applications and services may access it.

Physical Security

Protect devices and storage media against theft or unauthorised access.

Data Masking

Obscure sensitive values where full information is not required.

Tokenisation

Replace sensitive values with substitute tokens where appropriate.

Integrity Protection

Detect unauthorised or accidental modification where required.

Example

A laptop contains confidential customer information.

The laptop is stolen from a train.

Appropriate full-disk encryption can substantially reduce the risk that someone obtaining the physical device can read the stored data, assuming the encryption and credentials remain secure.

Encryption does not replace access control

Once an authorised user has unlocked the system, other controls still determine what that user may access and do.

4 Data in Transit Protect information while it moves

Data in transit is information moving between systems, devices, networks or users.

Examples

Web Traffic Email API Calls Database Connections File Transfers VPN Traffic Cloud Connections

Protection may include

TLS VPN IPsec Secure Protocols Authentication Integrity Protection
Example

A customer submits their payment information through a website.

The information travels from the customer's browser to the web application.

Appropriate transport protection can help prevent interception or unauthorised modification while the information is moving.
Protect the whole path

A secure connection between the customer and web server does not automatically protect every connection that occurs later between the application, API, database and external services.

Secure network protocols are covered more deeply in CISSP Domain 4 and cryptographic mechanisms in Domain 3.

5 Data in Use Protect information while systems actively process it

Data in use is actively being processed by an application, operating system, processor or user.

This can be particularly challenging because a system normally needs usable access to information in order to process it.

Access Control

Restrict which identities and processes may access information.

Application Security

Prevent applications from exposing or manipulating information inappropriately.

Process Isolation

Limit inappropriate access between executing processes.

Memory Protection

Reduce unauthorised access to data held during processing.

DLP

Monitor or control how sensitive information is being used.

Masking

Display only the information required for a particular purpose.

Example

A database is encrypted at rest.

When an authorised application queries a customer record, the application needs access to usable data in order to process the request.

Protecting storage does not automatically protect every situation in which the decrypted data is being used.
Data in use is often the forgotten state

Encrypting storage and network traffic is important, but data also needs protection while applications and users actively process it.

๐Ÿ”„ Data constantly changes state The same information may move through all three states within seconds
๐Ÿ’พ Database โ†’ Data at REST
โ†”๏ธ Query Response โ†’ Data in TRANSIT
โš™๏ธ Application โ†’ Data in USE
โ†”๏ธ API โ†’ Data in TRANSIT again
๐Ÿ’พ Logging System โ†’ Data at REST again
Protect transitions as well as locations

Data security should consider the complete processing flow rather than looking at one database or one network connection in isolation.

Data states compared

StateSimple meaningExamplePossible controls
At RestStoredDatabase or backupEncryption, access control, physical protection
In TransitMovingAPI requestTLS, secure protocols, VPN, integrity protection
In UseBeing processedCustomer record loaded by an applicationAccess control, application security, process and memory protection
6 Determine Security and Compliance Requirements Why does this data need protection?

Data security requirements may originate from several different sources.

Business Requirements

The organisation may need particular information protected to support its objectives.

Legal Requirements

Laws may create obligations relating to information protection.

Regulatory Requirements

Regulators may establish requirements relevant to particular data or sectors.

Contractual Requirements

Customers and partners may require specified protections.

Industry Standards

Applicable standards may establish security expectations.

Internal Policy

Organisational policies translate requirements into internal expectations.

Example

An application processes payment-card information.

Its security requirements may reflect:

  • business risk;
  • contractual obligations;
  • applicable payment-card standards;
  • internal security policies;
  • relevant legal and privacy requirements.
Compliance is one input into security

Meeting a particular compliance requirement does not automatically prove that every relevant security risk has been addressed.

From requirement to control

๐Ÿ“œ Requirement โ†’ What must be achieved?
๐ŸŽฏ Scope โ†’ Where does it apply?
๐Ÿ“š Standard โ†’ Which framework or standard helps define protection?
๐Ÿ›ก๏ธ Control โ†’ How will the requirement be met?
๐Ÿ” Assessment โ†’ Is the control operating as intended?
7 Scoping Determine where the requirement applies

Scoping determines which systems, applications, data, people, processes, locations and technologies fall within the boundary of a particular security or compliance requirement.

Which data is relevant?
Which systems store or process it?
Which systems transmit it?
Which users and administrators have access?
Which third parties are involved?
Which supporting components can affect its security?
Example

An organisation identifies a database containing regulated information.

Scoping only the database itself may be insufficient.

Relevant scope may also include:

  • the application accessing it;
  • administrative workstations;
  • backup systems;
  • network connections;
  • cloud services;
  • third parties handling copies.
Incorrect scope creates false confidence

A control cannot reliably protect a system or data flow that was accidentally excluded from consideration.

๐ŸŽฏ Reduce Scope by Architecture โ€” not by Assumption Smaller scope can be useful when legitimately engineered

Organisations may sometimes reduce the number of systems exposed to sensitive information through architecture and segmentation.

Example

Instead of allowing dozens of business systems to store payment-card information, an organisation centralises that information within a dedicated payment platform.

Other systems receive only the minimum information they require.

Reducing unnecessary handling of sensitive data can reduce both attack surface and compliance complexity.
You cannot reduce scope simply by declaring something out of scope

The architecture and actual data flows must support the scoping decision.

8 Tailoring Adapt controls to the real environment

Security-control frameworks may provide a baseline or starting set of controls.

Tailoring adapts that starting point to the organisation, system, technology, environment and risk.

Tailoring may involve

Scoping Considerations Compensating Controls Control Parameters Additional Controls Control Enhancements Implementation Detail
Example

A security-control baseline requires physical protection for certain infrastructure.

One system operates entirely within a cloud service and has no organisation-owned physical server.

Tailoring considers how the underlying security objective applies in the actual environment and which responsibilities are handled by the cloud provider or customer.

Tailoring โ‰  ignoring inconvenient controls

Tailoring should be reasoned, documented and consistent with applicable requirements and risk.

Scoping vs Tailoring

Scoping WHERE does it apply?
Tailoring HOW should it apply here?

Scope the boundary. Tailor the controls.

9 Standards Selection Select standards appropriate to the requirement and environment

Organisations may use recognised security standards and control frameworks to help establish appropriate data-security requirements.

Selection should reflect factors such as:

Legal Requirement Regulation Industry Customer Requirement Contract Risk Technology Jurisdiction

Examples of relevant standards and frameworks

ISO/IEC 27001 / 27002

Information-security management and control guidance.

NIST SP 800-53

Extensive catalogue of security and privacy controls.

PCI DSS

Security requirements relevant to payment-card environments.

Organisational Standards

Internal technical standards can translate broader requirements into consistent implementation.

Select what is applicable

The objective is not to apply every security standard in existence to every system.

๐Ÿ“‹ Control Baselines A starting point for control selection

A control baseline provides an initial set of controls that can then be evaluated and tailored for the particular environment.

๐Ÿ“‹ Baseline โ†’ Start with an established control set
๐ŸŽฏ Scope โ†’ Determine applicability
โš™๏ธ Tailor โ†’ Adapt controls appropriately
โž• Supplement โ†’ Add controls where risk requires
โœ… Approve โ†’ Document the resulting control set
A baseline is a starting point โ€” not the end of risk analysis
10 Data Loss Prevention (DLP) Detect and control inappropriate use or movement of sensitive data

Data Loss Prevention technologies help identify sensitive information and monitor or control how it is stored, used and transmitted.

DLP can address several data states

๐Ÿ’พ Data at Rest

Discover sensitive files stored in repositories or endpoints.

โ†”๏ธ Data in Transit

Detect sensitive information being transmitted through monitored channels.

โš™๏ธ Data in Use

Monitor endpoint actions such as copying or moving sensitive information.

Possible DLP actions

Detect Alert Warn User Block Quarantine Log Encrypt
Example

An employee attempts to email a spreadsheet containing thousands of customer records to a personal email account.

DLP identifies sensitive patterns within the attachment and blocks the transmission.

DLP is not just "block everything"

DLP policy should reflect business processes, classification and risk so that legitimate work can continue while inappropriate data movement is controlled.

๐Ÿ” How DLP recognises sensitive information Content and context can both matter

Different DLP implementations can use multiple techniques to determine whether information is sensitive.

Keywords Patterns Regular Expressions Classification Labels Document Fingerprints File Type Context Destination
Context example

Sending a confidential document to an approved internal repository may be acceptable.

Sending the same document to a personal file-sharing account may trigger a DLP response.

The data may be identical while the destination changes the risk.
โš–๏ธ DLP False Positives and False Negatives Detection controls require tuning
False Positive

Legitimate information is incorrectly identified as violating DLP policy.

False Negative

Sensitive information that should have been detected passes without being identified.

Controls need tuning

Excessive false positives can encourage users to ignore warnings, while false negatives allow actual sensitive-data movement to go undetected.

11 Digital Rights Management (DRM) Control what authorised recipients may do with digital content

Digital Rights Management applies controls to digital information that can continue to govern how the content may be used after it has been distributed.

DRM may restrict actions such as

View Edit Copy Print Forward Save Expire
Example

A confidential strategy document is sent to an external adviser.

DRM controls allow the adviser to view it but prevent ordinary printing and forwarding, and access expires after the engagement.

Access does not always mean unlimited rights

A recipient may legitimately be allowed to view information without being allowed to copy, print or redistribute it.

๐Ÿ”‘ DRM vs Access Control Who gets access vs what they may do afterwards
Access Control

Determines whether an identity is permitted to access a resource.

DRM

Can impose ongoing usage restrictions on the protected digital content.

Easy distinction

Access Control Can you OPEN it?
DRM What may you DO with it?
12 Cloud Access Security Broker (CASB) Visibility and policy control around cloud-service use

A Cloud Access Security Broker provides security capabilities around an organisation's use of cloud services.

Depending on the implementation, CASB capabilities can help provide:

Visibility

Understand which cloud services users are accessing.

Data Protection

Apply policies to sensitive information being placed into cloud services.

Policy Enforcement

Control actions based on user, service, device or data context.

Threat Protection

Identify suspicious activity associated with cloud-service use.

Example

An employee attempts to upload a confidential customer dataset to an unapproved cloud-storage service.

A cloud-security control identifies the service and data sensitivity and prevents the upload according to organisational policy.

CASB is particularly associated with cloud visibility and control

It helps organisations apply security policy in environments where users access cloud services outside traditional on-premises boundaries.

DLP vs DRM vs CASB

TechnologyThinkPrimary idea
DLPStop inappropriate data movementIdentify sensitive information and detect or prevent inappropriate use or transmission.
DRMControl usage rightsRestrict what authorised recipients may do with protected digital information.
CASBControl cloud useProvide visibility and policy enforcement around access to cloud services.

DLP ยท DRM ยท CASB memory aid

DLP Where is the DATA going?
DRM What can you DO with the file?
CASB What CLOUD service are you using?

DLP = DATA ยท DRM = RIGHTS ยท CASB = CLOUD

13 Encryption Protect confidentiality by making information unreadable without the appropriate key

Encryption is one of the most important technical controls for protecting sensitive information.

At Rest

Disk, file, database and backup encryption may protect stored data.

In Transit

Secure protocols can encrypt information moving between systems.

Example

A database is encrypted at rest and communications to the application use encrypted transport.

An administrator with excessive database privileges can still query customer records through authorised system interfaces.

Encryption does not eliminate the need for access control.
Encryption primarily addresses confidentiality

Depending on the mechanism, additional or integrated controls may be required to provide integrity and authentication.

Algorithms, cryptographic key lifecycle, PKI and cryptographic architecture belong primarily in CISSP Domain 3.

๐Ÿ”‘ Encryption is only as useful as its Key Management Protect the means of decrypting the data
Bad example

A database backup is strongly encrypted.

The decryption key is saved in a text file beside the backup.

The encryption exists technically, but the surrounding protection is weak.
CISSP thinking

When encryption is selected as a control, consider the complete cryptographic lifecycle rather than merely whether an "encrypt" checkbox is enabled.

14 Tokenisation Replace sensitive values with substitute tokens

Tokenisation replaces a sensitive value with a substitute value or token.

Systems that do not require the original sensitive value may use the token instead.

๐Ÿ’ณ Sensitive Value โ†’ Original information
๐Ÿ”„ Tokenisation โ†’ Replace with substitute token
๐ŸŽŸ๏ธ Token โ†’ Used by systems that do not require original value
Example

An application does not need to store a customer's actual card number after the initial payment process.

It stores a token representing that payment instrument instead.

Fewer systems therefore need direct access to the original sensitive value.
๐Ÿ†š Encryption vs Tokenisation Both can protect data, but they work differently
Encryption

Transforms data cryptographically so that the original can be recovered using appropriate cryptographic key material.

Tokenisation

Substitutes the sensitive value with a token and relies on an appropriate tokenisation system or mapping where retrieval is required.

Neither is automatically "better"

The appropriate technique depends on the business process, data, architecture and security requirements.

15 Data Masking Reveal only the information that needs to be visible

Data masking obscures or replaces sensitive information so that users or systems do not receive the complete original value.

Display masking

Original: 4929 1234 5678 9999

Displayed: **** **** **** 9999

Test-data example

Developers need realistic customer data structures but do not require real customer identities.

Sensitive fields can be appropriately masked or replaced before the dataset is used in development.

Do not reveal more than the task requires

A customer-service employee may need the last four digits of an account number without needing the complete value displayed on screen.

โœ‚๏ธ Reduce Exposure of Sensitive Data Sometimes the best control is to minimise where the original data exists

Security becomes easier when fewer users and systems require direct access to sensitive information.

๐Ÿ’Ž Sensitive Data โ†’ Central protected location
๐ŸŽŸ๏ธ Token โ†’ Used by systems requiring reference only
๐ŸŽญ Masked Value โ†’ Used where partial visibility is sufficient
Reduce unnecessary exposure

The fewer locations containing the original sensitive information, the fewer locations need the strongest associated controls.

๐Ÿ‘ค Access Control as a Data Security Control Protect data according to authorised business need

Data security should control both:

Who can access it?

Identity, role and business need matter.

What can they do?

View, modify, copy, export and delete may require different permissions.

Example

A call-centre employee may need to view a customer's address.

They do not necessarily require permission to export the entire customer database.

Detailed access-control models and technologies are covered in CISSP Domain 5.

โœ… Integrity Controls Data security is not only about confidentiality

Data-security controls should also consider whether information can be modified improperly.

Access Control Hashing Digital Signatures Validation Change Control Logging Versioning
Example

Published software is available publicly.

Confidentiality is not the goal โ€” users are supposed to download it.

Integrity and authenticity may be extremely important because users need confidence that the software has not been maliciously modified.
โšก Availability Controls Protected data also needs to be usable when required

Data-security requirements should consider what happens if authorised users cannot access important information.

Backups Replication Resilience Redundancy Recovery Access Continuity
Example

Medical information is perfectly encrypted and restricted from unauthorised access.

A system failure makes the information unavailable to clinicians during an emergency.

Strong confidentiality controls do not compensate for unacceptable loss of availability.
๐Ÿงฑ Use Layered Data Protection Do not depend on one control
๐Ÿท๏ธ Classification โ†’ Identify sensitive data
๐Ÿ‘ค Access Control โ†’ Limit who may access it
๐Ÿ” Encryption โ†’ Protect confidentiality
๐Ÿšง DLP โ†’ Control inappropriate movement
๐Ÿ‘๏ธ Monitoring โ†’ Detect suspicious activity
๐Ÿ’พ Recovery โ†’ Maintain availability
No single control protects data against every threat

Effective data protection normally combines multiple safeguards addressing different risks and failure modes.

๐Ÿ‘๏ธ Monitoring and Logging Understand how sensitive data is being accessed

Preventive controls should often be complemented by monitoring capable of identifying unusual or inappropriate activity.

Useful events might include

Data Export Mass Download Permission Change External Sharing Failed Access Administrative Access DLP Alert Unusual Query
Example

A user normally accesses 20 customer records per day.

The same account suddenly downloads 250,000 customer records shortly before midnight.

Appropriate monitoring may identify the behaviour even if the account technically had permission to access the records.
โ˜๏ธ Data Security in Cloud Services Cloud changes responsibility โ€” not the need for security

Moving data to a cloud provider does not remove the organisation's need to understand how that information is protected.

Questions include

Which party configures access?
Who manages encryption keys?
Where is the information stored?
Which logs are available?
Can data be shared publicly?
How is data removed when the service ends?
Understand shared responsibility

The provider may protect infrastructure while the customer remains responsible for areas such as data classification, identities, permissions and configuration depending on the service model.

16 Selecting the Right Data Security Control Match protection to risk and requirement
What is the classification?

Understand sensitivity and criticality.

What state is the data in?

At rest, in transit or in use?

What threat are we addressing?

Disclosure, modification, loss, exfiltration or misuse?

What requirements apply?

Business, legal, contractual, regulatory or policy?

What already protects the data?

Understand existing controls before adding more.

What residual risk remains?

Does the proposed control reduce risk sufficiently?

CISSP mindset

Do not select encryption simply because a question contains the word "data."

First understand the problem the control is supposed to solve.

Which control solves which problem?

ProblemPossible control
Stolen laptop exposes stored dataEncryption at rest
Network traffic may be interceptedEncrypted transport
User emails confidential file externallyDLP
Recipient should view but not freely copy a documentDRM
Organisation needs visibility of cloud-service useCASB / cloud security controls
Help desk only needs last four digitsData masking
Application does not need original sensitive identifierTokenisation
User should not access entire datasetAccess control
โš ๏ธ Understand Control Limitations Security technologies solve particular problems, not every problem
Encryption

Does not automatically prevent an authorised but malicious user from reading information through an application.

DLP

Cannot guarantee identification of every possible sensitive-data movement and requires appropriate policy and tuning.

DRM

Can restrict supported digital actions but cannot eliminate every possible way information might be captured or disclosed.

CASB

Provides useful cloud security capabilities but does not eliminate the need for secure cloud configuration, identity controls and provider governance.

Masking

Does not automatically protect underlying source data if users or systems retain another path to the original value.

โš ๏ธ Common mistakes Data-security assumptions that often lead to poor decisions
"Encryption solves data security."

Encryption is important, but access control, integrity, availability, monitoring and handling controls may still be required.

"If a database is encrypted, authorised users cannot steal its data."

Applications and authorised users generally need access to usable information. Encryption at rest does not prevent every form of misuse.

"Data only needs protection at rest and in transit."

Data in use is also explicitly part of the CISSP objective.

"TLS protects the complete application."

TLS can protect a communication channel but does not automatically secure endpoints, application logic or stored data.

"DLP means backup."

DLP is Data Loss Prevention, focused on identifying and controlling sensitive-data use and movement. It is not a backup technology.

"DLP only monitors network traffic."

DLP capabilities may address data at rest, in transit and in use.

"DRM and DLP are the same."

DLP focuses on inappropriate data use or movement, while DRM focuses on usage rights associated with protected digital content.

"CASB is just another firewall."

CASB is particularly associated with visibility and policy controls around cloud-service use.

"Being compliant means the data is secure."

Compliance demonstrates alignment with particular requirements. Risk may still exist outside those requirements.

"Scoping means excluding systems we do not want assessed."

Scope should reflect the real applicability of the requirement and actual data flows.

"Tailoring means removing inconvenient controls."

Tailoring should adapt controls appropriately based on applicability, environment and risk.

"Apply every security standard to every system."

Standards should be selected according to applicable requirements, environment and business need.

"Tokenisation and encryption are identical."

Encryption cryptographically transforms information, while tokenisation substitutes sensitive values with tokens through a different architecture.

"Masked information means the source data no longer needs protection."

The original underlying information may still exist elsewhere and require strong protection.

"Cloud providers are responsible for all data security."

Responsibility depends on the service model and agreement. Customers commonly retain significant responsibilities for their own data, identities and configurations.

"The strongest technical control is always the best answer."

Controls should be proportionate to the business requirement, data, threat, risk and applicable obligations.

CISSP Exam Perspective

Identify the state, requirement and problem before choosing the control

CISSP questions in this area often describe sensitive information and ask which protection is most appropriate.

First determine:

  1. what data is involved;
  2. which state it is in;
  3. what requirement applies;
  4. what threat or problem is being addressed;
  5. which control most directly addresses that problem.

๐Ÿ’พ Rest clues

Stored Database Disk Backup Archive

โ†”๏ธ Transit clues

Network Email API Transfer TLS

โš™๏ธ Use clues

Memory Processing Application User Query

๐Ÿšง DLP clues

Exfiltration Email USB Upload Sensitive Data

๐Ÿ“„ DRM clues

Copy Print Forward Expiry Usage Rights

โ˜๏ธ CASB clues

Cloud Service SaaS Shadow IT Cloud Upload Cloud Visibility

๐ŸŽฏ Scope clues

Boundary Applicable Environment Data Flow

โš™๏ธ Tailoring clues

Baseline Compensating Control Parameters Adapt

๐Ÿ“š Standards clues

Compliance Industry Contract Requirement
CISSP shortcut

What data? What state? What requirement? What threat? What control?

๐Ÿ“ Practice scenarios Apply data-security-control thinking

Scenario 1

Customer records are stored within a database.

Which data state applies?

Data at rest.

Scenario 2

Customer information moves from a web application to an API.

Which state applies during the transfer?

Data in transit.

Scenario 3

An application loads a customer's record into memory while processing a request.

Which state applies?

Data in use.

Scenario 4

A stolen laptop contains highly sensitive information.

Which control can significantly reduce disclosure risk from the stored data?

Appropriate encryption at rest, together with suitable authentication and key protection.

Scenario 5

An employee tries to email thousands of customer records to a personal account.

Which technology is particularly relevant?

Data Loss Prevention.

Scenario 6

An external consultant may view a confidential document but should not normally print or forward it.

Which technology is particularly relevant?

Digital Rights Management.

Scenario 7

Security wants greater visibility into employees uploading data to SaaS applications.

Which technology is particularly relevant?

A Cloud Access Security Broker or equivalent cloud-security capability.

Scenario 8

A customer-service employee needs only the final four digits of a payment card displayed.

Which technique is particularly suitable?

Data masking.

Scenario 9

Several applications need to reference a payment instrument but do not need the original card number.

Which technique may reduce exposure of the original sensitive value?

Tokenisation.

Scenario 10

An organisation applies a recognised security-control baseline.

It then adjusts applicability, parameters and compensating controls for its particular system.

What process is occurring?

Tailoring.

Scenario 11

A compliance programme identifies which applications, databases, networks and service providers process the relevant regulated data.

What process is this?

Scoping.

Scenario 12

A team excludes a server from compliance scope because assessing it would be expensive.

The server actually processes the regulated information.

Is this valid scoping?

No. Scope should reflect actual applicability and data flows rather than convenience.

Scenario 13

A database is strongly encrypted at rest.

An administrator has excessive privileges and exports all records.

Why did encryption not prevent this?

Encryption at rest does not replace appropriate access control for authorised system use.

Scenario 14

DLP produces thousands of alerts about legitimate documents every day.

What issue is likely present?

Excessive false positives and insufficient policy tuning.

Scenario 15

An organisation complies fully with one industry standard but discovers a serious security risk not addressed by that standard.

Can the organisation ignore it because it is compliant?

No. Compliance with one set of requirements does not automatically eliminate other security risks.

Scenario 16

Data is encrypted while stored and while transmitted.

A vulnerable application exposes the decrypted data while processing it.

Which data state has become the weakness?

Data in use.

Scenario 17

A company applies the maximum possible security controls to all information regardless of classification.

Is this necessarily the best approach?

No. Controls should be proportionate to requirements, sensitivity, risk and business needs.

Scenario 18

An organisation centralises sensitive payment data and allows other business applications to use tokens instead of storing the original values.

What security benefit can this provide?

Fewer systems directly handle the original sensitive data, reducing unnecessary exposure and potentially simplifying security scope.

Data Security Control memory aid

Classification WHAT is the data?
State WHERE is it now?
Requirement WHAT must we achieve?
Scope WHERE does the requirement apply?
Control HOW will we protect it?
Assessment DOES it actually work?

Understand. Scope. Protect. Validate.

Technology memory aid

Encryption Make data UNREADABLE
DLP Control where data GOES
DRM Control what users may DO
CASB Control CLOUD use
Masking Hide what users don't NEED
Tokenisation Replace sensitive data with a SUBSTITUTE

Encrypt. Monitor. Restrict. Minimise.

Key takeaways

CISSP objective 2.6 covers data states, scoping and tailoring, standards selection, data-security controls and compliance requirements.

Data exists in three important states: at rest, in transit and in use.

Data at rest is stored.

Data in transit is moving between systems or locations.

Data in use is actively being processed.

The same information may move through all three states during a single business transaction.

Protecting one data state does not automatically protect the others.

Encryption can protect data at rest and in transit, but access controls and application protections are still needed when authorised systems use the information.

Security requirements can originate from business, legal, regulatory, contractual, industry and organisational sources.

Scoping determines where a requirement applies.

Tailoring adapts an appropriate baseline or control set to the actual system, environment and risk.

Tailoring should not simply be used to remove inconvenient controls.

Standards should be selected according to relevant requirements rather than indiscriminately applying every available framework.

DLP helps detect and control inappropriate storage, use or movement of sensitive information.

DLP can operate across data at rest, in transit and in use.

DRM helps restrict how authorised recipients can use protected digital information.

CASB provides visibility and policy-control capabilities around organisational use of cloud services.

Masking reduces unnecessary visibility of sensitive values.

Tokenisation allows some systems to operate using substitute values instead of directly storing the original sensitive information.

Encryption is extremely important but does not replace access control, monitoring, integrity controls or appropriate key management.

Compliance should be treated as an important security requirement rather than evidence that every possible security risk has disappeared.

Data-security controls should be selected according to the actual problem being addressed.

Most importantly: understand the data, understand its state, understand the requirement, and then select controls that protect it throughout the complete processing flow.

CISSP Domain 2 Complete

Asset Security

You have reached the end of CyberPrepHub's Asset Security learning section.

Domain 2 follows information and assets from identification and classification through handling, ownership, lifecycle management, retention and technical protection.

Classification Asset Handling Ownership Asset Inventory Data Lifecycle Retention EOL & EOS Data States DLP DRM CASB Data Protection

The Domain 2 story

2.1 Classify What do we HAVE and how important is it?
2.2 Handle How should we TREAT it?
2.3 Manage Who OWNS it and where is it?
2.4 Lifecycle What happens throughout its LIFE?
2.5 Retain Should we still KEEP it?
2.6 Protect Which CONTROLS protect it?

Know it. Classify it. Manage it. Protect it. Retire it.

๐Ÿ“š Sources & Further Reading Authoritative references