CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 549


When performing a data classification project, an information security manager should:

Show Answer
Correct Answer: AC

In a data classification project, it is crucial to identify information owners. Information owners are responsible for understanding the nature and value of the data, as well as making informed decisions regarding its classification. While assigning information criticality and sensitivity is an important aspect of data classification, it is generally the responsibility of the data owners rather than the information security manager to do so. Identifying information owners ensures that the proper stakeholders are involved in classifying the data appropriately according to its importance and sensitivity to the organization.

Discussion

12 comments
Sign in to comment
D2D2Option: A
Nov 19, 2022

I would have picked C, data/Info owners would classify, however, the question states "performing" which is now past the identification. I feel A is still correct.

AlexJacobson
Jan 25, 2024

But infosec manager doesn't assign sensitivity and criticality, it's the data owners who do that. So C is more likely, IMO.

03allen
Jun 14, 2024

But data owner is not identified by ITSM, it will be provided.

ZiggyboobooOption: C
Oct 23, 2022

Information owner would define criticality of data in my view

MyKasalaOption: C
Jan 21, 2023

C is correct

CarlPTY07Option: C
Mar 11, 2023

When performing the data classification, we need to know who the owner is!

welloOption: C
Jun 12, 2023

In a data classification project, it is important to identify information owners who are responsible for the data and have the authority to make decisions regarding its classification. The information security manager should work closely with the information owners to understand the nature of the data, its value to the organization, and the appropriate classification levels. By involving information owners in the classification process, the organization can ensure that the classification accurately reflects the criticality and sensitivity of the information.

cosmo4ngOption: A
Apr 7, 2023

Agreed. A is correct.

mad68Option: A
May 14, 2023

A. Assign information criticality and sensitivity. Assigning information criticality and sensitivity is a crucial step in a data classification project. It involves assessing the importance and sensitivity of different types of information within the organization. By assigning criticality and sensitivity levels to the data, the organization can prioritize its protection and apply appropriate security controls based on the value and potential impact of the information.

secdocOption: A
Sep 29, 2023

Only the Data owners can assign criticality and sensitivity.

richck102Option: A
Jun 29, 2023

A. assign information criticality and sensitivity.

[Removed]
Jul 16, 2023

that's the job of the owners

GoseuOption: C
Jul 16, 2023

C looks OK

SHERLOCKAWSOption: C
Dec 13, 2023

C. identify information owners.

jcisco123Option: C
Feb 11, 2024

Owners provide the necessary context and understanding of the data's use and importance, which are essential for effective classification.