ExamGecko
Question list
Search
Search

Question 555 - CISM discussion

Report
Export

Which of the following is necessary to ensure consistent protection for an organization's information assets?

A.
Data ownership
Answers
A.
Data ownership
B.
Classification model
Answers
B.
Classification model
C.
Regulatory requirements
Answers
C.
Regulatory requirements
D.
Control assessment
Answers
D.
Control assessment
Suggested answer: B

Explanation:

A classification model is necessary to ensure consistent protection for an organization's information assets, because it defines the criteria for assigning different levels of sensitivity and criticality to the information assets, and determines the appropriate security controls and handling procedures for each level. Data ownership, regulatory requirements, and control assessment are also important aspects of information security management, but they are not sufficient to ensure consistent protection without a classification model.

Reference= CISM Review Manual, 16th Edition, page 67

asked 01/10/2024
Yrae Franca de Pinho Gomes
50 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first