CISSP · Domain 2 · 10%

Bảo mật tài sản

Asset Security — Domain 2

Domain tập trung vào vòng đời dữ liệu từ khi tạo đến khi hủy, phân loại tài sản, vai trò sở hữu dữ liệu, và các yêu cầu bảo vệ quyền riêng tư theo GDPR. Nguyên lý cốt lõi: bạn không thể bảo vệ thứ bạn không biết mình đang có.

Mục tiêu chương / Learning objectives

1. Lý thuyết cốt lõi / Core theory

1.1. Phân loại tài sản (Asset classification)

Phân loại tài sản là nền tảng của mọi chương trình bảo mật — không thể áp dụng kiểm soát phù hợp nếu không biết tài sản nào quan trọng. Hai chiều đánh giá:

Phân loại chính phủ Mỹ (từ cao đến thấp): Top Secret → Secret → Confidential → Unclassified. Dữ liệu chỉ được declassify bởi người có thẩm quyền.

Phân loại doanh nghiệp (phổ biến): Confidential/Restricted → Internal Use Only → Public. Một số tổ chức thêm "Sensitive" giữa Confidential và Internal.

CISSP Insight: Câu hỏi thi thường hỏi: "Ai chịu trách nhiệm phân loại dữ liệu?" → Data Owner (người tạo/sở hữu dữ liệu, thường là business manager). IT/CISO chỉ là Custodian — quản lý kỹ thuật, không phải chủ sở hữu.

1.2. Vai trò sở hữu dữ liệu (Data ownership roles)

CISSP định nghĩa 4 vai trò rõ ràng với trách nhiệm không chồng lấn:

1.3. Vòng đời dữ liệu (Data lifecycle)

Dữ liệu trải qua 6 giai đoạn, mỗi giai đoạn có yêu cầu bảo mật riêng:

1. Create

Phân loại ngay khi tạo. Áp dụng label/watermark.

2. Store

Encryption at-rest, access control, backup.

3. Use

Least privilege, audit logging, DLP endpoint.

4. Share

Encryption in-transit (TLS), DLP network, DRM.

5. Archive

Retention policy, long-term encryption, immutability.

6. Destroy

NIST 800-88: Clear/Purge/Destroy. Certificate of destruction.

1.4. Yêu cầu bảo vệ quyền riêng tư (Privacy protection — GDPR principles)

GDPR (hiệu lực 2018) đặt ra 7 nguyên tắc xử lý dữ liệu cá nhân, trong đó CISSP tập trung vào:

Data Sovereignty & Residency: Dữ liệu phải tuân theo luật của quốc gia nơi nó được lưu trữ, không chỉ quốc gia của tổ chức. GDPR yêu cầu dữ liệu công dân EU không được chuyển ra ngoài EEA nếu không có safeguards (Standard Contractual Clauses, Adequacy Decisions). Azure/AWS cung cấp "data residency guarantees" để giúp doanh nghiệp tuân thủ.

1.5. Hủy dữ liệu & DLP (Data destruction & DLP technologies)

NIST SP 800-88 Rev.1 định nghĩa 3 mức hủy dữ liệu theo độ nhạy cảm:

NIST SP 800-88 Rev.1 — Hủy dữ liệu chi tiết (Media Sanitization)

Phương pháp Kỹ thuật Áp dụng cho Độ nhạy cảm
Clear Logical overwrite (zeros/ones/patterns). DoD 5220.22-M: 3-pass wipe. HDD tái sử dụng nội bộ. KHÔNG hiệu quả trên SSD/flash — wear leveling giữ data ở sectors cũ. Thấp → Trung bình
Purge Cryptographic erase (CE), degaussing (từ tính HDD), ATA Secure Erase. Tái phân phối ra ngoài. Degaussing KHÔNG hoạt động trên SSD/flash/optical — chỉ tác dụng với vật liệu từ tính. Trung bình → Cao
Destroy Shredding, disintegrating, incinerating, melting, pulverizing. Dữ liệu Top Secret hoặc thiết bị hư hỏng không thể CE/degauss. Yêu cầu certificate of destruction. Cao → Tối mật
CISSP Trick Question: "Nhân viên IT dùng degaussing để hủy SSD chứa dữ liệu mật. Điều này có đủ không?" → Không. Degaussing chỉ hoạt động với vật liệu từ tính (HDD truyền thống). SSD lưu data bằng flash memory (điện tích trong floating gate transistors) — không bị ảnh hưởng bởi từ trường. Với SSD: dùng Cryptographic Erase (nếu self-encrypting drive) hoặc Destroy (shred).

DLP (Data Loss Prevention) — 3 loại triển khai:

2. Bài thực hành / Hands-on labs

🖥️ Platform: Windows 11 · Ubuntu 22.04
🛠️ Tools: PowerShell 7 · Bash · grep · aureport

Lab 1 — DLP-style Audit: Kiểm soát tài sản nhạy cảm trên Windows (PowerShell)

OS: Windows 11 · Tool: PowerShell 7

  1. Liệt kê file nhạy cảm, kiểm tra ACL, và phát hiện USB device được kết nối:
# === DLP AUDIT: Sensitive File Discovery ===
$SensitivePath = "C:\SensitiveData"

# 1. Tìm file nhạy cảm theo extension
Write-Host "=== Sensitive Files Inventory ===" -ForegroundColor Cyan
Get-ChildItem -Path $SensitivePath -Recurse -ErrorAction SilentlyContinue |
    Where-Object { $_.Extension -in '.pdf','.docx','.xlsx','.csv','.pem','.key' } |
    Select-Object Name, LastWriteTime,
        @{N='Size_KB';E={[math]::Round($_.Length/1KB,1)}},
        DirectoryName |
    Sort-Object LastWriteTime -Descending |
    Format-Table -AutoSize

# 2. Kiểm tra quyền truy cập thư mục nhạy cảm
Write-Host "`n=== Access Control List ===" -ForegroundColor Cyan
Get-Acl -Path $SensitivePath | Format-List Path, Owner, Group
(Get-Acl $SensitivePath).Access |
    Select-Object IdentityReference, FileSystemRights, AccessControlType |
    Format-Table -AutoSize

# 3. Phát hiện USB device được kết nối (Event ID 6416 = new device)
Write-Host "`n=== USB Device Connection Events (last 7 days) ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{
    LogName   = 'Security'
    Id        = 6416
    StartTime = (Get-Date).AddDays(-7)
} -ErrorAction SilentlyContinue | Select-Object -First 10 |
    Select-Object TimeCreated,
        @{N='Device';E={$_.Properties[1].Value}} |
    Format-Table -AutoSize

# 4. Kiểm tra file đã copy ra USB gần đây (Removable Media via WMI)
Write-Host "`n=== Removable Drives Currently Connected ===" -ForegroundColor Cyan
Get-WmiObject Win32_LogicalDisk | Where-Object { $_.DriveType -eq 2 } |
    Select-Object DeviceID, VolumeName, Size, FreeSpace | Format-Table -AutoSize

✅ Kết quả mong đợi: Danh sách file nhạy cảm với ngày sửa đổi mới nhất. ACL hiển thị chỉ DOMAIN\SensitiveDataAccess group có quyền, không phải "Everyone". USB events (nếu có) liệt kê device ID và thời gian. Phát hiện USB kết nối ngoài giờ làm việc là tín hiệu insider threat.

Lab 2 — File Classification & Sensitive Data Discovery (Bash)

OS: Ubuntu 22.04 · Tool: Bash + grep + aureport

#!/bin/bash
# === SENSITIVE DATA DISCOVERY & FILE CLASSIFICATION ===

echo "=== 1. Search for sensitive keywords in text files ==="
grep -rn --include="*.txt" --include="*.csv" --include="*.conf" \
  -E "password|credit.card|ssn|social.security|api.key|secret" \
  /home /var/www 2>/dev/null | head -20

echo -e "\n=== 2. Find cryptographic key files (should not be world-readable) ==="
find / \( -name "*.pem" -o -name "*.key" -o -name "id_rsa" \
         -o -name "*.p12" -o -name "*.pfx" \) \
  -not -path "*/proc/*" 2>/dev/null | while read f; do
    perms=$(stat -c "%a %U %n" "$f")
    echo "  $perms"
done

echo -e "\n=== 3. Files modified in last 24 hours in sensitive dirs ==="
find /etc /root /home -newer /etc/passwd -type f 2>/dev/null | head -15

echo -e "\n=== 4. Audit log: access to /etc/shadow ==="
sudo aureport --file -- /etc/shadow 2>/dev/null | head -20

echo -e "\n=== 5. World-readable files containing 'password' ==="
find /etc /home -perm /o+r -type f 2>/dev/null | \
  xargs grep -l "password" 2>/dev/null | head -10

echo -e "\n=== 6. Data retention check: files older than 7 years ==="
find /var/data/archive -type f -mtime +2555 2>/dev/null | \
  wc -l | xargs -I{} echo "{} files older than 7 years — review retention policy"

✅ Kết quả mong đợi: grep tìm thấy file CSV chứa "credit_card" trong /home → cần DLP và reclassification. Key files chỉ nên có quyền 600 (owner read/write only). Audit log cho thấy ai đã đọc /etc/shadow — truy cập ngoài maintenance window là sự kiện đáng ngờ. Files quá hạn retention cần review để xóa hoặc archive.

3. Tình huống doanh nghiệp / Enterprise scenario

Bối cảnh:

Công ty bảo hiểm MedCare Vietnam lưu trữ hồ sơ bệnh án khách hàng trong SharePoint. Kiểm toán viên phát hiện: nhân viên sales có thể tải xuống toàn bộ database khách hàng dưới dạng Excel; không có watermark; không có policy xóa dữ liệu; hồ sơ từ 2010 vẫn còn trong hệ thống dù luật Việt Nam yêu cầu lưu tối đa 10 năm với hồ sơ bảo hiểm.

Giải pháp:

  1. Asset Inventory: Lập danh mục đầy đủ tất cả data stores (SharePoint, SQL, file shares). Phân loại theo sensitivity: PHI (Protected Health Information) = Confidential/Restricted.
  2. Assign Ownership: Head of Operations = Data Owner; IT team = Custodian. Owner phê duyệt access matrix.
  3. DLP Implementation: Microsoft Purview DLP policy: block download of >100 records; watermark tất cả document printed/exported; alert khi email attachment chứa số CMND/SĐT.
  4. Retention Policy: Tạo retention label trong M365: "Insurance Record" = retain 10 years, then auto-delete. Chứng chỉ hủy dữ liệu cho audit trail.
  5. Data Residency: Đảm bảo dữ liệu khách hàng VN lưu trong Azure Southeast Asia (Singapore/Vietnam) — không replication ra ngoài khu vực.

Bài học: Asset security không chỉ là kỹ thuật — phải có chính sách, quy trình và accountability rõ ràng. Data Owner là nhân tố quyết định, không phải IT.

4. Tự kiểm tra / CISSP-style knowledge check

  1. Giám đốc kinh doanh yêu cầu IT xóa toàn bộ dữ liệu khách hàng cũ trên server sắp thanh lý. Ai là người có thẩm quyền quyết định phương pháp hủy và mức độ xóa cần thiết?
  2. Công ty cloud của bạn xử lý dữ liệu y tế cho bệnh viện. Theo GDPR, bạn là Controller hay Processor? Điều này ảnh hưởng gì đến nghĩa vụ pháp lý của bạn?
  3. Nhân viên HR xuất danh sách lương nhân viên ra Excel và gửi cho đối tác ngoài. DLP network nên chặn hay alert-only? Giải thích lý do chọn mức độ kiểm soát phù hợp.
  4. Ổ cứng chứa dữ liệu bí mật thương mại bị hỏng vật lý. Theo NIST 800-88, phương pháp nào phù hợp và tại sao không thể dùng Clear hay Purge?
  5. GDPR "right to erasure" (right to be forgotten) xung đột với nghĩa vụ lưu trữ hồ sơ tài chính 7 năm theo SOX. Cách giải quyết xung đột này trong thực tế?
C01: Quản lý bảo mật & Rủi ro C03: Kiến trúc & Kỹ thuật bảo mật
Thực hành trên công cụPowerShell 7 · Bash · grep · aureport
Nền tảngWindows 11 · Ubuntu 22.04
Thời điểm phát hànhQ2/2026
Ngày biên soạn24/05/2026
Người biên soạnTrần Văn Hòa (MCT)
Phiên bảnv1.0
Zalo