ExamGecko
Question list
Search
Search

Question 793 - CISM discussion

Report
Export

Which of the following is the PRIMARY objective of information asset classification?

A.
Vulnerability reduction
Answers
A.
Vulnerability reduction
B.
Compliance management
Answers
B.
Compliance management
C.
Risk management
Answers
C.
Risk management
D.
Threat minimization
Answers
D.
Threat minimization
Suggested answer: C

Explanation:

The primary objective of information asset classification is C. Risk management. This is because information asset classification is a process of assigning labels or categories to information assets based on their value, sensitivity, and criticality to the organization. Information asset classification helps the organization to identify, assess, and treat the risks associated with the information assets, and to apply the appropriate level of protection and controls to them. Information asset classification also helps the organization to comply with the legal, regulatory, and contractual obligations regarding the information assets, and to optimize the use of resources and costs for information security.

Information asset classification is a process of assigning labels or categories to information assets based on their value, sensitivity, and criticality to the organization. Information asset classification helps the organization to identify, assess, and treat the risks associated with the information assets, and to apply the appropriate level of protection and controls to them. (From CISM Manual or related resources)

Reference = CISM Review Manual 15th Edition, Chapter 2, Section 2.2.1, page 751; CISM Review Questions, Answers & Explanations Manual 9th Edition, Question 7, page 3; Certified Information Security Manager Exam Prep Guide - Packt Subscription2

asked 01/10/2024
MOHD SAIFUL SYAHMI SAIFUDDIN
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first