ExamGecko
Question list
Search
Search

Related questions











Question 510 - CISA discussion

Report
Export

Which of the following is the BEST source of information for examining the classification of new data?

A.
Input by data custodians
Answers
A.
Input by data custodians
B.
Security policy requirements
Answers
B.
Security policy requirements
C.
Risk assessment results
Answers
C.
Risk assessment results
D.
Current level of protection
Answers
D.
Current level of protection
Suggested answer: C

Explanation:

The best source of information for examining the classification of new data is the risk assessment results, because they provide an objective and consistent basis for determining the value, sensitivity, and criticality of the data, as well as the potential impact of unauthorized disclosure, modification, or loss of the data12.The risk assessment results can help to define the appropriate classification levels and criteria for the data, such as public, internal, confidential, or restricted12.Input by data custodians, security policy requirements, and current level of protection are not the best sources of information for examining the classification of new data, because they may not reflect the actual risk exposure or business needs of the data.Reference:1: CISA Review Manual (Digital Version), Chapter 5, Section 5.4.22: CISA Online Review Course, Module 5, Lesson 4

asked 18/09/2024
Kishi Peart
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first