7.5 Resource & Media Protection 

CISSP Domain 7 · Security Operations

7.5 Resource & Media Protection

Information does not become safe simply because it is stored on an organisation's equipment.

Data may exist on servers, laptops, backup tapes, removable drives, mobile devices, cloud storage, printed documents and many other forms of media.

Security Operations must protect that information throughout its operational life - while it is stored, when it is moved and when the media is eventually reused, returned or disposed of.

💾

Manage

Know which media exists, what it contains and how it should be handled.

KNOW THE MEDIA
🔐

Protect

Apply physical, logical and cryptographic safeguards according to information sensitivity.

PROTECT THE DATA
♻️

Sanitise

Prevent sensitive information from remaining accessible when media leaves its current use.

REMOVE THE DATA SAFELY
Current CISSP 7.5 Scope

Apply Resource Protection

Media Management

Control media throughout its operational lifecycle, including access, storage, handling, transport, reuse and disposal.

Media Protection Techniques

Apply appropriate physical, logical and cryptographic safeguards to protect information stored on media.

Data at Rest / Data in Transit

Protect information according to whether it is being stored or transmitted.

7.5 Official Scope

MEDIA Manage it
PROTECTION Secure it
AT REST Protect stored data
IN TRANSIT Protect moving data

The Big Idea

Resource protection should follow the information wherever it goes.

Identify → What Media Exists?
Classify → How Sensitive Is the Information?
Protect → Apply Appropriate Controls
Use → Control Access & Handling
Move → Protect During Transport
Retire → Sanitise / Destroy

Resource Protection Flow

IDENTIFY Know it exists
CLASSIFY Know its sensitivity
PROTECT Apply controls
TRACK Maintain accountability
SANITISE Remove safely
Media

What Counts as Media?

Media is anything on which information can be recorded, stored or printed.

Magnetic
Hard Drives Magnetic Tape
Solid State
SSD USB Flash Memory Cards
Optical
CD DVD Blu-ray
Mobile
Phones Tablets Portable Devices
Backup
Tapes Backup Drives Snapshots
Paper
Printouts Reports Records
Embedded Storage
Printers Copiers Network Devices IoT
Cloud / Logical Storage
Object Storage Virtual Disks Snapshots Managed Databases
Do not think only "USB stick". Media can exist almost anywhere information is stored.
📄 Digital & Non-Digital Media Media protection applies beyond electronic storage
Digital Media
SSD Hard Drive USB Tape
Non-Digital Media
Printed Reports Paper Records Microfilm
Example

A printed payroll report containing employee salary information still requires:

Controlled Access Secure Storage Appropriate Disposal
Information sensitivity does not disappear when data becomes paper.
Official 7.5 Topic 1

Media Management Lifecycle

Acquire → Authorised Media Enters Organisation
Identify → Inventory / Ownership
Classify → Determine Protection Requirement
Mark → Apply Handling Information
Store → Protect at Rest
Use → Control Access
Transport → Protect Movement
Reuse / Retire → Sanitise
Dispose → Release / Destroy Safely

Media Lifecycle

IDENTIFY What is it?
LABEL How should it be handled?
STORE Protect it
USE Control it
MOVE Track it
SANITISE Remove data

Media Inventory & Accountability

Sensitive media should be managed so the organisation understands what exists and who is responsible for it.

Unique Identification

Assign an identifier where appropriate.

Owner / Custodian

Establish who is responsible for its handling.

Contents

Understand the type and sensitivity of information stored.

Location

Know where sensitive media is held.

Lifecycle State

Active, stored, transferred, retired or pending destruction.

Movement

Track important transfers where required.

Media you cannot account for is media you cannot confidently protect.
🏷️ Media Marking Communicate applicable handling and distribution requirements

Media markings can help people recognise that particular handling, storage or distribution requirements apply.

Example

Backup media containing highly sensitive information may be labelled according to the organisation's classification and handling procedures.

Balance usability and disclosure

Labels themselves should be designed appropriately so that the marking does not unnecessarily disclose sensitive information about the contents.

Classification determines protection. Marking helps communicate handling.
Media Protection

Media Access

Access to sensitive media should be limited to authorised people, roles, devices and processes.

Physical Access

Locks, controlled rooms, secure cabinets and authorised personnel.

Logical Access

Authentication, access control and permissions on digital media.

Cryptographic Protection

Encryption can protect information if the media is lost or accessed outside authorised systems.

Accountability

Check-out, return or transfer records may be appropriate for sensitive media.

Possession of the media should not automatically mean access to the information.
Media at Rest

Secure Media Storage

Physical Security

Restrict access to rooms, cabinets and storage facilities.

Environmental Protection

Protect media against temperature, humidity, water, fire and other damaging conditions where relevant.

Encryption

Protect sensitive digital information against unauthorised disclosure.

Access Logging

Record access to highly sensitive repositories where appropriate.

Separation

Store particularly sensitive media within appropriately controlled areas.

Inventory

Periodically confirm that expected media remains accounted for.

Media Movement

Media Transport

Physical media may need to move between offices, data centres, suppliers, backup locations or storage facilities.

Authorisation

Ensure movement is permitted.

Encryption

Protect digital information if the media is lost or intercepted.

Physical Packaging

Use appropriate protective or tamper-evident packaging when required.

Tracking

Maintain accountability for sensitive media during movement.

Approved Courier

Use suitable transportation mechanisms according to sensitivity and policy.

Receipt

Confirm that the intended recipient received the media.

Physical Media Transport

AUTHORISE May it leave?
PROTECT Encrypt / package
TRACK Where is it?
CONFIRM Who received it?
🔗 Media Tracking vs Forensic Chain of Custody Similar accountability idea - different purpose
Media Tracking

Operational control showing where sensitive organisational media is and who possesses it.

Chain of Custody

Formal evidence-handling history used to establish the custody and handling of investigative evidence.

Sensitive-media tracking ≠ automatically forensic chain of custody.
High-Risk Media

Removable Media

Removable media is portable and easy to connect to different systems, which makes it useful operationally but also creates security risk.

Data Loss

Sensitive information can be copied and physically removed.

Malware

Untrusted media can introduce malicious software.

Loss / Theft

Small portable devices are easily misplaced or stolen.

Uncontrolled Copies

Information may be duplicated outside managed repositories.

Unknown Provenance

Security teams may not know where the device has previously been connected.

Bypassing Controls

Removable storage may circumvent normal network-based data controls.

🔌 USB Media Controls Allow according to business need and risk
Disable Where Unnecessary Approved Devices Only Device Control Encryption Malware Scanning Read-Only Use DLP Logging
Scenario

An employee finds an unknown USB drive in the car park.

They connect it to their corporate laptop to discover:

who owns it.

Unknown removable media should not be casually connected to trusted systems.

Media Use Restrictions

Organisations may restrict the type of media that can be used with particular systems.

High-security workstation

Policy:

No personally owned removable storage.

Authorised transfer

Data may be exported only to:

organisation-managed encrypted media.

Media use should reflect business need, classification and risk.
Official 7.5 Topic 2

Media Protection Techniques

Encryption

Protect information from unauthorised disclosure if storage is accessed or lost.

Access Control

Restrict who or what can use the media.

Physical Protection

Secure media against theft, damage and unauthorised handling.

Device Control

Control which portable storage devices may connect to systems.

Data Loss Prevention - DLP

Detect or restrict inappropriate transfer of sensitive information.

Integrity Protection

Detect inappropriate modification where required.

Write Protection

Prevent modification where media should be read-only.

Malware Scanning

Check removable or exchanged media before trusted use where appropriate.

Backup

Maintain recoverable copies while applying equivalent protection to the backup media.

Sanitisation

Remove sensitive information before reuse or disposal.

Protection Follows Classification

Information → Classify
Classification → Handling Requirements
Handling Requirements → Media Controls
Public brochure

May require: minimal confidentiality controls.

Customer payment records

May require:

Encryption Restricted Access Controlled Transport Secure Sanitisation
Protect according to sensitivity - not according to the physical size of the device.
Official 7.5 Topic 3

Data at Rest vs Data in Transit

Data at Rest

Information stored on media rather than actively moving between systems.

Database Disk Backup USB Cloud Storage

STORED

Data in Transit

Information being transmitted between systems, devices, networks or services.

Web Session API Traffic Email Transfer VPN Traffic Database Connection

MOVING

Data States

AT REST Stored
IN TRANSIT Moving
🧠 What About Data in Use? An important data state even though 7.5 explicitly names rest and transit

Data in use is information currently being processed or actively used by a system.

Example

An encrypted customer database is opened by an authorised application.

The information may need to exist in usable form while:

the application processes it.

Three Data States

REST Stored
TRANSIT Moving
USE Processing
Encryption at rest does not automatically protect information while an authorised application has decrypted it for use.
Stored Information

Protecting Data at Rest

Full-Disk Encryption

Protect an entire storage volume against offline access.

File / Folder Encryption

Protect selected information.

Database Encryption

Protect database files, tables, columns or other stored data depending on the implementation.

Cloud Storage Encryption

Protect stored cloud objects, volumes, backups and snapshots.

Access Control

Restrict which identities can read or modify stored information.

Physical Protection

Protect the storage device itself.

Key Management

Protect the cryptographic keys required to decrypt the information.

Monitoring

Detect inappropriate access to sensitive repositories.

At Rest

ENCRYPT Stored data
RESTRICT Access
PROTECT Keys
MONITOR Use
💻 Full-Disk Encryption Excellent against some threats - not every threat
Lost laptop - powered off

Disk is strongly encrypted.

Attacker removes the drive and attempts to read it.

Full-disk encryption can provide strong protection against this offline access scenario.

Compromised laptop - user logged in

Operating system has already unlocked the encrypted volume.

Malware runs with the user's privileges.

Disk encryption alone may not prevent access to information already available through the running system.

Encryption protects against specific threats. It does not replace access control and endpoint security.

Encryption Is Only as Useful as Its Key Management

Strong Algorithm + Exposed Key
Result → Confidentiality May Be Lost
Generation

Create keys appropriately.

Storage

Protect keys from unauthorised access.

Distribution

Deliver keys securely when necessary.

Access

Limit which identities and systems can use them.

Rotation

Replace keys according to applicable requirements.

Revocation / Destruction

Remove keys when they should no longer provide access.

Encrypt the data. Protect the key.
Moving Information

Protecting Data in Transit

TLS

Protect application communications such as HTTPS and other TLS-enabled services.

IPsec

Protect communications at the IP layer.

VPN

Establish protected communication across untrusted networks.

SSH

Protect remote administrative communications.

Secure File Transfer

Protect files while they are transferred between systems.

Authentication

Verify the identity of communication endpoints where required.

Integrity Protection

Detect inappropriate modification during transmission.

Certificate Validation

Ensure encrypted communications establish trust with the intended endpoint.

In Transit

AUTHENTICATE Who is endpoint?
ENCRYPT Hide contents
INTEGRITY Detect modification
↔️ Encryption at Rest ≠ Encryption in Transit Protecting one state does not automatically protect another
Database

Disk: encrypted.

Connection from application to database: unencrypted.

The database is protected:

while stored.

But information may be exposed:

while moving across the network.

Protect every relevant data state.
🌐 Private Network ≠ Encrypted Network Network location and cryptographic protection are different controls
Internal database connection

Traffic remains entirely within: the corporate data centre.

Does that automatically mean: the traffic is encrypted?

No.

Internal ≠ encrypted. Private ≠ confidential.

Where Does Encryption Begin and End?

When evaluating data in transit, do not ask only:

"Is encryption enabled?"

Ask:

Where Does Encryption Start? Where Does It Terminate? Who Can Decrypt? What Happens Afterwards?
Example
User → TLS → Load Balancer
Load Balancer → Plaintext → Application Server
Encryption to the front door does not automatically mean encryption throughout the entire path.
Often Forgotten

Backup Media Needs Protection Too

Backups may contain complete copies of highly sensitive production information.

Encryption

Protect confidential backup contents.

Access Control

Restrict who can retrieve or restore backups.

Physical Protection

Secure backup tapes or devices.

Off-Site Transport

Protect media while moving to external storage.

Integrity

Protect against unauthorised modification.

Retention

Apply approved retention and disposal requirements.

Backup = another copy of the data. Another copy = another asset to protect.
🗄️ Encrypted Production ≠ Encrypted Backup Do not assume protection automatically follows the copy
Production database

Storage encryption: enabled.

Backup export

Stored as: unencrypted backup file.

Evaluate protection of every copy, including archives and backups.

Printed Information

Printing

Restrict sensitive printing according to business need.

Collection

Prevent sensitive documents from being left unattended at printers.

Storage

Use appropriate locked or controlled storage.

Transport

Protect documents when moved.

Disposal

Destroy sensitive paper using an appropriate method.

Common failure

Confidential customer report remains:

unattended in a shared printer tray.

🖨️ The Printer May Contain Data Too Do not focus only on the printed sheet

Modern printers, scanners and multifunction devices may contain internal storage used for:

Print Jobs Scanned Documents Address Books Configuration
End of lease

Multifunction printer is returned to supplier.

Internal storage was never: sanitised.

Look for storage inside devices that do not immediately look like storage devices.
Media End of Life

Media Sanitisation

Sanitisation makes access to target information on media infeasible for an appropriate level of effort.

It becomes important before media is:

Reused Reassigned Returned Sold Recycled Disposed Released Outside Organisational Control

Before Media Leaves

WHAT DATA? Sensitivity
WHAT MEDIA? Technology
WHERE NEXT? Reuse or disposal
METHOD? Appropriate sanitisation
VALIDATE? Was it effective?
🗑️ Delete ≠ Sanitise Removing the reference to data may not remove the underlying data
User action

Delete file.

File Entry → Marked Available
Underlying Storage → Data May Remain
User deletion ≠ secure data removal.
💽 Formatting ≠ Automatically Sanitisation The method must be suitable for the media and required assurance

Reformatting or reinstalling an operating system should not automatically be treated as sufficient sanitisation for sensitive information.

"Looks empty" ≠ "data cannot be recovered."
Essential CISSP Sanitisation Concepts

Clear · Purge · Destroy

Clear

Apply logical sanitisation techniques appropriate for reuse within the intended environment and required assurance.

LOGICAL SANITISATION

Purge

Apply a stronger sanitisation process intended to make recovery infeasible even using more advanced recovery techniques.

STRONGER SANITISATION

Destroy

Render the media unusable so that it cannot be used again as storage media.

MEDIA NO LONGER REUSABLE

Sanitisation

CLEAR Logical sanitisation
PURGE Stronger sanitisation
DESTROY Media unusable

Choose the Method According to the Media

Sanitisation is not a single universal command that works equally well for every storage technology.

Magnetic Media

Requires methods appropriate to magnetic storage technology.

Solid-State Storage

Requires methods appropriate to flash-memory architecture and device behaviour.

Optical Media

May require physical destruction where suitable logical sanitisation is unavailable.

Paper

Requires an appropriate physical destruction process.

Cloud Storage

Requires consideration of logical deletion, provider architecture, encryption keys, snapshots, backups and contractual controls.

Sanitisation method should match: DATA SENSITIVITY + MEDIA TYPE + DISPOSITION.
🔑 Cryptographic Erase Render encrypted data inaccessible by sanitising the required cryptographic key material
Media → Data Stored Encrypted
Data Access → Requires Cryptographic Key
Sanitise Key → Encrypted Data Becomes Inaccessible
Cryptographic erase depends on sound encryption

The effectiveness of the approach depends on factors such as whether the target data was actually encrypted with suitable cryptography and whether relevant copies of the required key material remain.

Crypto erase targets access through the key rather than physically destroying every storage location.
Current NIST Emphasis

Validate Sanitisation

Performing a sanitisation procedure is not the end of the process.

Organisations should obtain appropriate assurance that the selected sanitisation approach was completed effectively.

Select Method → Suitable for Media + Data
Perform → Sanitisation
Validate → Was It Effective?
Record → Disposition Evidence
"We ran the tool" is weaker assurance than "we validated the sanitisation outcome."
🔨 Physical Destruction Appropriate when media will not be reused and required sanitisation warrants destruction

Appropriate destruction techniques depend on the media technology and applicable organisational requirements.

Shredding Disintegration Crushing Other Approved Destruction Processes
Physically damaged ≠ necessarily sanitised to the required level.
Use an approved method appropriate for the actual media.

Data Remanence

Data remanence is the possibility that residual representations of information remain after ordinary deletion or attempted removal.

Scenario

Organisation deletes customer files from an old drive.

Drive is sold.

New owner uses recovery software and retrieves:

previous customer information.

Data remanence is why ordinary deletion is not the same as sanitisation.
Disposition Decision

Reuse vs Release vs Destroy

Internal Reuse

Media remains under organisational control but may move to a different purpose or user.

External Release

Media leaves organisational control through return, resale, donation, recycling or other disposition.

Destruction

Media will no longer be usable as storage media.

Where the media is going next influences the required sanitisation assurance.
Modern Media Protection

Cloud & Logical Media

In cloud environments, organisations may not physically possess the storage media containing their information.

Logical Deletion

Understand what occurs when a resource or object is deleted.

Snapshots

Copies may exist independently of the original workload.

Backups

Provider or customer backups may retain data after primary deletion.

Encryption Keys

Key management can play an important role in protecting or cryptographically erasing information.

Provider Responsibility

Physical media sanitisation may be performed by the cloud provider.

Contracts

Agreements should address applicable data-return, deletion and media handling expectations.

Cloud changes who controls the physical media. It does not remove the need for media protection.
☁️ "Delete" in the Cloud Requires Context Logical resources can have multiple underlying copies
Customer

Deletes: virtual disk.

Questions may include:

Are Snapshots Left? Are Backups Left? Who Controls Physical Storage? What Does Provider Policy Say? Which Encryption Keys Exist?
Logical deletion and physical-media sanitisation are not necessarily the same event.

Third-Party Media Handling

Organisations sometimes rely on suppliers for:

Off-Site Backup Document Destruction Hardware Disposal Device Leasing Cloud Storage Data Centre Services

Security requirements may therefore include:

Contractual Requirements

Define expected handling and protection.

Authorised Personnel

Restrict access to sensitive material.

Transport Controls

Protect media while it is moved.

Destruction Requirements

Specify appropriate sanitisation or destruction.

Evidence

Obtain appropriate records of disposition where required.

Oversight

Assess whether supplier practices meet organisational requirements.

Outsourced disposal ≠ outsourced accountability.
📜 Certificate of Destruction Useful evidence - not magical proof by itself

A disposal provider may produce documentation showing which media was processed and how.

Certificate exists ≠ supplier controls never need assessment.
Documentation supports accountability. Vendor governance establishes confidence in the process.
Practical Scenario

The Lost Backup Drive

An employee transports a backup drive between two offices.

The drive is lost on a train.

Scenario A

Drive: unencrypted.

Contains: customer information.

Loss may expose the information directly.

Scenario B

Drive: strongly encrypted.

Key: managed separately.

Physical media is lost, but confidentiality protection is substantially stronger.

Assume portable media may be lost. Protect the information accordingly.
Insider Scenario

Copying Customer Data to USB

Employee → Accesses Customer Database
Export → CSV File
USB → Copies File
Employee Leaves → Data Leaves Organisation

Possible Controls

Least Privilege Device Control DLP Approved Media Only Encryption Monitoring
Network security alone may not prevent data leaving on physical media.
Data State Scenario

The Encrypted Database

Database Disk → Encrypted at Rest
Application Connection → Unencrypted Network Traffic
Database Query → Customer Data Traverses Network
At-rest protection does not compensate for an unprotected transmission channel.
Endpoint Scenario

Stolen Laptop

A laptop is stolen from an employee's car.

Controls
Full-Disk Encryption Strong Authentication Screen Lock Endpoint Management Remote Response Capability
Physical loss of a device should not automatically equal disclosure of its stored information.
Hidden Media Scenario

The Leased Office Copier

A company replaces a multifunction copier after five years.

It is returned to the leasing company.

Security discovers the copier contains internal storage that may hold:

Scanned Documents Previous Print Jobs Address Information
Include embedded storage in asset retirement and media sanitisation processes.
Backup Scenario

The Forgotten Tape

A data centre closes.

All servers are securely wiped.

Six boxes of old backup tapes remain in:

a storage cupboard.

Retiring primary systems does not automatically retire every copy of their data.
Cloud Scenario

The Deleted Virtual Machine

VM → Deleted
Snapshot → Still Exists
Backup → Still Exists
Deleting the workload ≠ deleting every copy of its information.
Disposal Scenario

Old Employee Laptop

An organisation plans to donate old laptops to charity.

IT performs:

a quick operating-system reinstall.

The devices previously stored:

confidential business information.

Reinstallation should not automatically be treated as adequate sanitisation.
Classify Data → Determine Required Assurance
Identify Media → Choose Appropriate Method
Sanitise → Validate
Release → Only After Successful Process
Cryptographic Erase Scenario

Encrypted Cloud Storage

An organisation stores sensitive information encrypted using controlled cryptographic keys.

Stored Data → Encrypted
Access → Requires Key
Disposition → Appropriate Key Sanitisation
Remaining Ciphertext → Inaccessible Without Required Key Material
Cryptographic erase can be especially relevant where organisations do not directly control every physical storage location.
🎓 CISSP Scenarios Recognise the resource or media-protection principle being tested
Scenario 1

A USB drive can be connected to and removed from a computer.

What type of media?

Removable media.

Scenario 2

A confidential report is printed on paper.

Does media protection still apply?

Yes.

Scenario 3

An organisation assigns identifiers and custodians to backup tapes.

Which activity?

Media management and accountability.

Scenario 4

Sensitive media is stored in a locked controlled facility.

Which protection?

Physical media protection.

Scenario 5

An encrypted drive is lost during transport.

Which control primarily protects its confidentiality?

Encryption.

Scenario 6

Security needs to know which employee currently possesses a sensitive backup device.

Which concept?

Media accountability / tracking.

Scenario 7

Does normal media tracking automatically constitute forensic chain of custody?

Answer?

No.

Scenario 8

A user plugs an unknown USB device into a production server.

Primary concern?

Uncontrolled removable-media use.

Scenario 9

The organisation permits only registered encrypted USB devices.

Which protection technique?

Removable-media / device control.

Scenario 10

Security prevents customer records being copied to removable storage.

Which technology may help?

DLP and device control.

Scenario 11

A database file sits on an SSD.

Which data state?

Data at rest.

Scenario 12

Customer information is being transmitted between an application and database.

Which data state?

Data in transit.

Scenario 13

An application has decrypted information into memory for processing.

Which broader data-state concept?

Data in use.

Scenario 14

A laptop drive is encrypted but malware running as the logged-in user reads files normally.

Why?

At-rest encryption does not replace endpoint and access controls once authorised decryption is available.

Scenario 15

Database storage is encrypted but the network connection is plaintext.

Which gap?

Data-in-transit protection.

Scenario 16

Security uses TLS to protect application traffic.

Which data state is primarily being protected?

Data in transit.

Scenario 17

Traffic travels only across the internal network.

Does this prove the traffic is encrypted?

No.

Scenario 18

TLS terminates at the load balancer and backend traffic is unencrypted.

What should the architect understand?

Where encryption begins and ends.

Scenario 19

The organisation encrypts data with a strong algorithm but stores the key beside it with unrestricted access.

Primary weakness?

Key management.

Scenario 20

Production data is encrypted but backup exports are plaintext.

Which issue?

The backup copy lacks equivalent protection.

Scenario 21

A backup tape contains an entire customer database.

Should it receive weaker controls than production?

No, protection should reflect the sensitivity of the data.

Scenario 22

An employee deletes confidential files before selling a drive.

Is ordinary deletion enough?

No.

Scenario 23

The organisation reformats a drive containing sensitive data.

Can it automatically assume sanitisation?

No.

Scenario 24

Residual information remains recoverable after ordinary deletion.

Which concept?

Data remanence.

Scenario 25

Media is logically sanitised so it can be appropriately reused.

Which general sanitisation category may apply?

Clear.

Scenario 26

A stronger sanitisation technique is selected because the media will leave organisational control.

Which general category may apply?

Purge.

Scenario 27

Media is physically rendered unusable.

Which category?

Destroy.

Scenario 28

The organisation sanitises cryptographic key material so encrypted data can no longer be decrypted.

Which technique?

Cryptographic erase.

Scenario 29

Cryptographic erase is planned but unencrypted historical copies of the same information exist.

Primary concern?

Not all target data is protected by the erased key.

Scenario 30

Sanitisation software reports success.

What should the organisation also consider?

Validation of the sanitisation outcome.

Scenario 31

A company returns a leased printer without considering its internal drive.

Which mistake?

Failure to identify embedded storage media.

Scenario 32

Confidential documents are left beside a communal printer.

Which issue?

Improper handling of non-digital media.

Scenario 33

Sensitive paper documents are placed in ordinary recycling bins.

Which control is missing?

Appropriate media destruction.

Scenario 34

A virtual machine is deleted but its snapshots remain.

Has every copy of the data been removed?

No.

Scenario 35

In a public cloud, who may physically sanitise failed storage hardware?

Likely answer?

The cloud provider under the shared-responsibility model.

Scenario 36

The customer cannot physically access the cloud disk.

Does resource-protection responsibility disappear?

No.

Scenario 37

A disposal vendor destroys drives for the organisation.

Has accountability been fully transferred?

No. Third-party governance remains important.

Scenario 38

A destruction supplier provides documentation showing which drives were processed.

What does this primarily support?

Accountability and disposition records.

Scenario 39

A user can physically steal an unencrypted hard drive but cannot log into the server normally.

Which control could protect the data against offline reading?

Encryption at rest.

Scenario 40

An employee can legitimately read a file but should not copy it to an unmanaged USB drive.

Which controls may help?

DLP and removable-media control.

Scenario 41

A drive contains public marketing information.

Another contains unreleased acquisition documents.

Should protection necessarily be identical?

No. Protection should reflect classification and risk.

Scenario 42

A company transports sensitive media but has no confirmation that the recipient received it.

Which weakness?

Insufficient media-transport accountability.

Scenario 43

A sensitive USB drive is encrypted but the decryption password is written on a label attached to it.

Primary weakness?

Credential / key protection defeats the encryption benefit.

Scenario 44

An SSD is sanitised using a method designed for a different storage technology without validation.

Primary concern?

The sanitisation method may not be appropriate for the media.

Scenario 45

A laptop is internally reassigned from one department to another.

Should previous sensitive data be considered?

Yes. Reuse can require sanitisation too.

Scenario 46

A storage device is physically destroyed before resale.

Can it still be reused?

No - destruction renders the media unusable.

Scenario 47

An organisation encrypts its laptops but never tests whether recovery keys are securely protected.

Which area needs attention?

Cryptographic key management.

Scenario 48

Sensitive cloud storage is deleted from the active service but retained for 30 days in provider backups.

What must be understood?

The complete data-retention and deletion lifecycle.

Scenario 49

Management asks what should primarily determine the degree of media protection.

Best answer?

Information sensitivity, risk, media characteristics and applicable requirements.

Scenario 50

Management asks for the core principle of 7.5.

Best answer?

Protect information wherever it is stored or moved and ensure it cannot remain accessible when its media is reused or disposed of.

CISSP Exam Perspective

Recognise the Clue Words

USB · Tape · SSD

Stored information.

Media

Portable Storage

Easy to move.

Removable Media

Who Has the Tape?

Tracking.

Media Accountability

Handling Label

Communicate protection.

Media Marking

Locked Storage Facility

Prevent access.

Media Storage

Media Moves Off-Site

Protect movement.

Media Transport

Unknown USB

Malware + data risk.

Media Use Control

Block USB Copies

Prevent data leaving.

DLP / Device Control

Stored on Disk

Static data.

Data at Rest

Across Network

Moving data.

Data in Transit

Being Processed

Active data.

Data in Use

Lost Laptop

Offline confidentiality.

Disk Encryption

Web / API Traffic

Protected channel.

TLS

VPN Traffic

Secure tunnel.

Transit Protection

Strong Encryption · Exposed Key

Weakness.

Key Management

Deleted File Recoverable

Residual information.

Data Remanence

Reuse Media

Remove old data.

Sanitisation

Logical Sanitisation

Reuse.

Clear

Stronger Sanitisation

Higher assurance.

Purge

Media Unusable

Physical disposition.

Destroy

Destroy Encryption Key

Encrypted data inaccessible.

Cryptographic Erase

Did Sanitisation Work?

Assurance.

Validation

Delete Cloud VM

Other copies?

Snapshots / Backups

Printer Returned

Hidden storage.

Embedded Media

Disposal Company

External dependency.

Third-Party Media Handling
⚠️ Common CISSP Mistakes Protect the information, not just the device
Media ≠ USB Only

Media includes disks, tapes, paper, mobile devices, embedded storage and other information-bearing resources.

Digital Media ≠ All Media

Printed and other non-digital information still requires protection.

Physical Possession ≠ Authorised Access

Sensitive digital media may still require access controls and encryption.

Media Tracking ≠ Forensic Chain of Custody

Both support accountability but serve different purposes.

Removable Media ≠ Automatically Prohibited

Use should reflect business need, risk and policy.

Approved USB ≠ Automatically Safe Data Transfer

Data classification and authorisation still matter.

Encryption ≠ Access Control

Encryption protects confidentiality under certain conditions. Authorisation still determines who should access information.

Encryption ≠ Complete Media Security

Physical security, access control, monitoring and key management remain important.

Encrypted Disk ≠ Secure Compromised Endpoint

Information may already be decrypted when the system is operating.

Strong Cipher ≠ Strong Protection With Exposed Key

Key management is part of cryptographic security.

At Rest ≠ In Transit

Protecting stored data does not automatically protect network transmission.

Private Network ≠ Encrypted Network

Internal location does not establish cryptographic protection.

TLS Somewhere ≠ Encryption Everywhere

Determine exactly where encryption starts and terminates.

Production Encrypted ≠ Backup Encrypted

Evaluate each copy separately.

Backup ≠ Less Sensitive Copy

Backup media can contain the complete sensitive dataset.

Delete ≠ Sanitise

Underlying data may remain recoverable.

Format ≠ Automatically Sanitise

The sanitisation technique must provide required assurance for the media involved.

Clear ≠ Destroy

Clear permits media reuse. Destruction renders the media unusable.

Purge ≠ Simply Delete More Files

Purge represents a stronger sanitisation objective.

Destroy ≠ Randomly Damage

Use approved destruction methods suitable for the media.

One Sanitisation Method ≠ Every Media Type

Storage technologies behave differently.

Sanitisation Tool Says Success ≠ End of Assurance

Appropriate validation strengthens confidence in the result.

Crypto Erase ≠ Delete Any Key

Relevant target data must actually depend on the sanitised cryptographic key material.

Deleted VM ≠ All Data Deleted

Snapshots, backups and other copies may remain.

Cloud ≠ No Media

Physical media still exists even when it is controlled by the provider.

Cloud Provider ≠ Customer Has No Responsibility

Shared responsibility and contractual requirements still apply.

Printer ≠ No Storage

Multifunction devices may contain persistent internal storage.

Third-Party Disposal ≠ Risk Transferred Completely

Supplier governance and appropriate evidence remain important.

Certificate of Destruction ≠ Vendor Due Diligence

Documentation supports the process but does not eliminate supplier oversight.

Reuse ≠ No Sanitisation Needed

Data may need to be removed even when the device remains inside the organisation.

Old Device ≠ Low-Value Data

An obsolete device may still contain highly valuable information.

Quick Reference

If you see...Think...
USB, disk, tape, paperMedia
Portable storageRemovable Media
What media exists?Media Inventory
Who currently possesses it?Media Accountability
Handling designationMedia Marking
Locked cabinet / secure roomMedia Storage
Physical movementMedia Transport
Unknown USBMedia Use Risk
Control removable storageDevice Control
Stop sensitive copyingDLP
Stored informationData at Rest
Moving across networkData in Transit
Being processedData in Use
Protect lost laptop diskEncryption at Rest
Protect web connectionTLS
Strong encryption, poor keysKey Management Problem
Old data recoverableData Remanence
Delete before disposalNot Sufficient by Itself
Remove data for reuseSanitisation
Logical sanitisationClear
Stronger sanitisationPurge
Media rendered unusableDestroy
Encrypted data + key sanitisedCryptographic Erase
Was sanitisation effective?Validation
Deleted cloud workloadCheck Snapshots + Backups
Leased copier returnedEmbedded Storage
External destruction companyThird-Party Media Handling

Media Management Memory Aid

IDENTIFY Know the media
CLASSIFY Know the data
MARK Communicate handling
STORE Protect it
TRACK Maintain accountability
SANITISE Remove safely

Data State Memory Aid

REST Stored
TRANSIT Moving
USE Processing

Stored · Moving · Processing

Sanitisation Memory Aid

CLEAR Logical sanitisation
PURGE Higher sanitisation assurance
DESTROY Media unusable
CRYPTO ERASE Sanitise required key material
VALIDATE Confirm effectiveness

7.5 Master Memory Aid

KNOW What media and data?
PROTECT At rest
PROTECT In transit
CONTROL Use + movement
SANITISE Before reuse or release
VALIDATE Confirm protection worked

Identify → Protect → Track → Sanitise → Validate

The Resource Protection Questions

WHAT? Which information is stored?
WHERE? Which media holds it?
SENSITIVITY? Which protection is required?
ACCESS? Who can reach it?
ENCRYPTED? At rest and in transit?
KEYS? Who controls decryption?
COPIES? Backups, snapshots, exports?
MOVE? How is transport protected?
REUSE? Must old information be removed?
DISPOSAL? Which sanitisation method?
VALIDATED? Did sanitisation work?
PROVIDER? Who controls physical media?

Key Takeaways

CISSP 7.5 focuses on applying resource protection.

The current CISSP outline explicitly includes media management, media protection techniques and protection of data at rest and in transit.

Media includes physical devices and surfaces on which information is stored or recorded.

It can include hard drives, SSDs, tapes, removable drives, optical media, mobile devices and printed material.

Information-bearing storage may also exist inside devices such as printers, scanners, copiers and network equipment.

Do not protect only obvious storage devices.

Media protection should reflect the sensitivity and value of the information it contains.

A useful operational lifecycle is:

Identify → Classify → Protect → Use → Transport → Sanitise.

Sensitive media should be appropriately inventoried and associated with ownership or custody where required.

Media marking can communicate classification and handling requirements.

Access to sensitive media may require physical, logical and cryptographic controls.

Possession of media should not automatically provide access to its information.

Sensitive media should be appropriately protected during storage.

Physical security, environmental controls, access restrictions and encryption can all contribute to media protection.

Physical media transport creates additional risk because the media leaves its normal controlled location.

Transport controls can include authorisation, encryption, suitable packaging, tracking and confirmation of receipt.

Operational tracking of organisational media and forensic chain of custody are related accountability concepts but should not automatically be treated as identical processes.

Removable media creates particular risks because it is portable and can connect to multiple systems.

Risks include malware introduction, data exfiltration, loss, theft, uncontrolled copying and bypass of normal network controls.

Organisations can restrict removable-media use through device controls, approved-media policies, encryption, DLP, malware scanning and logging.

Removable media should be allowed according to need and risk - not simply because a USB port exists.

Media protection techniques can include encryption, access control, physical protection, device control, DLP, integrity protection, write protection, malware scanning, backup and sanitisation.

Protection should follow the information's classification.

Data at rest refers to stored information.

Examples include databases, files, backups, disks and cloud object storage.

Data in transit refers to information being transmitted between systems or services.

Examples include web traffic, API calls, database connections and remote communications.

Data in use describes information actively being processed.

Rest = stored. Transit = moving. Use = processing.

Data at rest can be protected through encryption, access control, physical security, monitoring and appropriate key management.

Full-disk encryption is particularly valuable against offline access to a lost or stolen storage device.

Full-disk encryption does not replace access controls or endpoint security once an authorised system has unlocked the storage.

Cryptographic protection depends on appropriate key management.

A strong encryption algorithm provides little confidentiality if an attacker can easily obtain the required key.

Encrypt the data. Protect the key.

Data in transit can be protected using secure communication mechanisms such as TLS, IPsec, VPN technologies and SSH depending on the use case.

Transport protection can provide confidentiality, integrity and endpoint authentication.

Encryption at rest and encryption in transit protect different data states.

Encrypted disk ≠ encrypted network connection.

Similarly, use of a private or internal network does not automatically mean communications are encrypted.

When evaluating encrypted communications, determine where encryption begins and where it terminates.

TLS may terminate at a reverse proxy or load balancer while subsequent traffic takes a different protected or unprotected path.

Backups require the same security thinking as other copies of sensitive information.

Production encryption does not automatically guarantee that backup exports, snapshots or archives are encrypted.

Another copy of the data = another asset to protect.

Printed information remains media and should be protected according to its sensitivity.

Sensitive documents should not be left unattended at shared printers or disposed of through inappropriate ordinary waste processes.

Devices such as multifunction printers may themselves contain persistent storage.

Embedded storage should therefore be included in equipment retirement and sanitisation processes.

Media sanitisation becomes important before media is reused, reassigned, returned, recycled, sold, donated or otherwise released.

Ordinary file deletion should not automatically be considered secure sanitisation.

Reformatting a device also does not automatically provide appropriate sanitisation assurance.

Looks empty ≠ data unrecoverable.

Data remanence describes residual data remaining after ordinary deletion or attempted removal.

Sanitisation methods should be selected according to information sensitivity, storage technology and the media's intended disposition.

Clear, Purge and Destroy are important sanitisation concepts.

Clear uses suitable logical sanitisation techniques.

Purge provides stronger sanitisation assurance.

Destroy renders the media unusable.

Clear = logical sanitisation. Purge = stronger sanitisation. Destroy = media unusable.

Sanitisation techniques are media-specific.

A technique appropriate for magnetic media may not be appropriate for flash storage, optical media or cloud storage.

Cryptographic erase can render encrypted data inaccessible by appropriately sanitising the cryptographic key material required to recover it.

Its effectiveness depends on suitable encryption and complete management of relevant key material and data copies.

Crypto erase works because the ciphertext becomes inaccessible without the required key.

Modern sanitisation programmes should include appropriate validation of sanitisation effectiveness.

Running a sanitisation process successfully does not by itself provide the strongest possible assurance that the desired outcome was achieved.

Sanitise → Validate → Record.

Media can be sanitised for internal reuse as well as before it leaves the organisation.

A device being passed to another employee may still contain information the new user should not receive.

Cloud computing changes how media protection is implemented because the customer frequently does not control the underlying physical storage.

Cloud data may exist in active resources, snapshots, backups and other provider-managed copies.

Deleting a virtual machine or cloud object does not necessarily mean that every copy immediately disappears.

Provider deletion mechanisms, retention behaviour, encryption, cryptographic keys and contractual requirements therefore become important.

Cloud changes who controls the physical media. It does not eliminate media-protection responsibility.

Third parties may also transport, store, sanitise or destroy media.

Supplier contracts, due diligence, handling requirements and disposition evidence can support appropriate control.

Outsourcing media destruction does not eliminate the organisation's need to govern the risk.

Certificates or records of destruction can provide useful evidence of disposition but should not replace appropriate supplier assurance.

The central CISSP principle is:

identify where sensitive information exists, protect it according to its classification while stored and transmitted, control the media that carries it and ensure residual information cannot remain accessible when that media is reused or leaves organisational control.

📚 Sources & Further Reading Current and foundational media-protection references