ExamGecko
Question list
Search
Search

Question 244 - CISM discussion

Report
Export

While classifying information assets an information security manager notices that several production databases do not have owners assigned to them What is the BEST way to address this situation?

A.
Assign responsibility to the database administrator (DBA).
Answers
A.
Assign responsibility to the database administrator (DBA).
B.
Review the databases for sensitive content.
Answers
B.
Review the databases for sensitive content.
C.
Prepare a report of the databases for senior management.
Answers
C.
Prepare a report of the databases for senior management.
D.
Assign the highest classification level to those databases.
Answers
D.
Assign the highest classification level to those databases.
Suggested answer: A

Explanation:

Information asset classification is the process of identifying, labeling, and categorizing information assets based on their value, sensitivity, and criticality to the organization. Information asset classification helps to establish appropriate security controls, policies, and procedures for protecting the information assets from unauthorized access, use, disclosure, modification, or destruction. One of the key elements of information asset classification is assigning owners to each information asset. Owners are responsible for managing the information asset throughout its lifecycle, including defining its security requirements, implementing security controls, monitoring its usage and performance, reporting any incidents or breaches, and ensuring compliance with legal and regulatory obligations.Therefore, assigning responsibility to the database administrator (DBA) is the best way to address the situation where several production databases do not have owners assigned to them.Reference= CISM Review Manual 15th Edition1, page 256; Information Asset and Security Classification Procedure2.

asked 01/10/2024
ce temp2
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first