3. Domain 2 — Asset Security (10%)
Assets are what security protects. Before you can secure anything, you must know what you have, how sensitive it is, who owns it, and what happens to it over its lifetime — from creation to destruction. Domain 2 makes these abstractions operational: classification schemes define sensitivity, ownership roles define accountability, lifecycle management defines obligations, and data security controls protect assets in their various states.
At 10% weight, Domain 2 is relatively compact — but its concepts thread through every other domain. You cannot apply the right control without knowing the classification. You cannot assign the right protection without knowing the data state. You cannot destroy data properly without knowing what "proper" means for that media type.
⚠️ Domain Trap: Domain 2 questions frequently test the difference between similar-sounding roles (owner vs. custodian vs. controller vs. processor) and similar-sounding concepts (EOL vs. EOS, DLP vs. CASB vs. DRM). Precision in role assignments and tool selection is what separates correct from plausible answers.