Handling requirements

The rules, set by an asset's classification, for how information and assets are marked, stored, transmitted, accessed, retained and destroyed across their lifecycle.

Handling requirements turn a classification level into instructions that people and systems can follow. Once the data owner has assigned a data classification, the organisation states what each level demands: how the material is marked, where it may be stored, whether it must be encrypted in transit, who may take it off site, how long it is kept, and how it is sanitised or destroyed at the end. The ISC2 exam outline gives this its own objective, 2.2, Establish information and asset handling requirements. NIST SP 800-53 Rev. 5 groups many related controls in its Media Protection family, which covers media access, marking, storage, transport and sanitisation.

Handling requirements sit between the governance decision and daily practice. The owner decides the level; data custodians and data users apply the rules that follow from it. Marking and labelling is usually the first requirement, because a person cannot handle material correctly without knowing its level. A clean desk policy and removable media controls are typical ways the rules are enforced.

Exam relevance: a scenario may describe staff mishandling sensitive material and ask what was missing. Candidates are expected to trace handling back to classification: the label comes first, the handling rules follow from it, and the rules go with the asset wherever it travels, including to third parties and to disposal.