ExamGecko
Question list
Search
Search

Related questions











Question 298 - CISA discussion

Report
Export

Which of the following is the MOST important activity in the data classification process?

A.
Labeling the data appropriately
Answers
A.
Labeling the data appropriately
B.
Identifying risk associated with the data
Answers
B.
Identifying risk associated with the data
C.
Determining accountability of data owners
Answers
C.
Determining accountability of data owners
D.
Determining the adequacy of privacy controls
Answers
D.
Determining the adequacy of privacy controls
Suggested answer: C

Explanation:

Determining accountability of data owners is the most important activity in the data classification process. Data classification is a process that assigns categories or labels to data based on their value, sensitivity, criticality and risk to the organization. Data classification helps to determine the appropriate level of protection, access and retention for data. Determining accountability of data owners is an activity that identifies and assigns roles and responsibilities for data classification, protection and management to individuals or functions within the organization. Data owners are individuals or functions who have authority and responsibility for defining, classifying, protecting and managing data throughout their lifecycle. Determining accountability of data owners is essential for ensuring that data are classified correctly and consistently, and that data classification policies and procedures are followed and enforced. The other options are not as important as option C, as they are dependent on or derived from the accountability of data owners. Labeling the data appropriately is an activity that applies the categories or labels assigned by data owners to data based on their classification criteria. Identifying risk associated with the data is an activity that assesses the potential impact and likelihood of loss, disclosure, modification or destruction of data based on their classification level. Determining the adequacy of privacy controls is an activity that evaluates whether the controls implemented to protect personal or sensitive data are sufficient and effective based on their classification level.Reference:CISA Review Manual (Digital Version) , Chapter 5: Protection of Information Assets, Section 5.3: Data Classification.

asked 18/09/2024
Md Ali Uz Zaman
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first