
When organisations talk about security, the conversation usually starts with tools:
Encryption.
Access control.
Monitoring.
But CISSP starts somewhere else.
It starts with a simple, foundational question:
What are you protecting?
Security Without Classification Is Blind
Most organisations rush into implementing controls without understanding the data they are trying to protect.
This leads to two common problems:
- Overprotection → unnecessary cost, complexity, and friction
- Underprotection → increased exposure and risk
Both are failures.
Because security without classification is guesswork.
A Simple Way to Understand This
Imagine a warehouse storing:
- Gold
- Electronics
- Documents
- Scrap
Now imagine applying the same lock to everything.
That is exactly what happens when organisations skip data classification.
Not all data is equal.
And treating it equally is inefficient and risky.
What Is Data Classification?
Data classification is the process of categorising data based on:
- Sensitivity
- Value
- Criticality
- Legal or regulatory requirements
Typical classification levels include:
- Public
- Internal
- Confidential
- Restricted / Highly Sensitive
Each classification level determines:
- Who can access the data
- How it should be stored
- How it should be transmitted
- What controls must be applied
Who Owns Data Classification?
This is a critical CISSP concept.
Data classification is not owned by IT.
It is owned by the Data Owner — the business.
Why?
Because only the business understands:
- The value of the data
- The impact of exposure
- Legal and regulatory implications
IT and security teams implement controls.
But classification is a business decision.
Why Classification Must Come First
Every security control depends on classification.
Without it:
- Encryption decisions become arbitrary
- Access control lacks direction
- Retention policies fail
- Compliance becomes inconsistent
With classification:
- Controls become targeted
- Risk becomes measurable
- Governance becomes enforceable
CISSP principle:
You cannot secure what you have not defined.
The Correct Security Flow
CISSP expects a clear sequence:
- Identify the data
- Classify the data
- Apply security controls
Most candidates reverse this order.
That’s why they get scenario-based questions wrong.
How This Appears in the CISSP Exam
CISSP rarely asks direct definitions.
Instead, it will test your thinking:
- What should be done first before applying controls?
- Who determines sensitivity?
- What drives protection requirements?
Correct answer:
Data classification comes first
If you jump straight to encryption or access control, you are thinking operationally — not strategically.
Key Takeaway
If you remember one concept from this topic, remember this:
Data classification defines protection — not the other way around.
Listen to the Podcast
This article is part of the CISSP Blog and Podcast Series – PK’s Chronicles.
In the podcast episode, this concept is explained using practical analogies and CISSP exam scenarios in a structured 5-minute format.
Search on Spotify:
PK’s Chronicles
Final Thought
Data classification is not just a process.
It is the starting point of all security decisions.
If you get this right, everything else in Domain 2 becomes logical.
Until then—
Think classification.
Think risk.
Think like a CISSP.



Pingback: CISSP Domain 2 – Mastering Asset Security – TheCyberThrone