← CISSP: security, risk, and operations
02 / 10 · 30 MIN

Assets, data, and decommissioning

Maintain protection and accountability when data changes format or location.

Concept and mechanism

Inventory should track data, copies, and owners, not only servers. An export, backup, or AI training set can retain sensitivity despite a temporary name. Classify resulting contents and the impact of use or disclosure. Combining public data with restricted identifiers does not make the set public. For a defined analytical purpose, deliver necessary fields and assess aggregation instead of distributing complete production data for convenience. Pseudonymization can reduce exposure but should not automatically be confused with irreversible anonymization. Concrete retention and access requirements should follow each copy.

Guided application

At decommissioning, separate two questions: has still-needed information been preserved and made recoverable, and has outgoing media been suitably sanitized? Functional migration does not answer both. If a formal preservation instruction exists, scope covered records and suspend incompatible deletion. For sanitization, assess media type, sensitivity, method, verification, and evidence. Cryptographic erase has prerequisites, including protection of target data by the affected keys; earlier plaintext may need different treatment. Record media identifiers, owners, and results, and validate retained copies before releasing equipment. Decommissioning savings depend on safely completing these conditions.

IN PRACTICE

An encrypted database exports plaintext into a shared folder: control must follow the copy to that destination.

Common pitfalls

Machine-only inventory; temporary data without retention; erasing keys without prerequisites; Running treated as preservation proof.

Related topics: Architecture, cryptography, and common failures · Networks, channels, and access boundaries

Take this idea with you

Protection follows the data lifecycle through verified recovery and disposal.

Create account

Reference: Guidelines for Media Sanitization · CISSP outline effective April 15, 2024; current AI guidance consulted 2026-09-29