CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 89


Which of the following should be the FIRST step when developing a data loss prevention (DLP) solution for a large organization?

Show Answer
Correct Answer: AC

The first step when developing a data loss prevention (DLP) solution for a large organization is to conduct a data inventory and classification exercise. This step involves identifying the types, locations, formats, and repositories of data that need to be protected, as well as categorizing the data based on its sensitivity and regulatory requirements. This foundational step is crucial because it allows the organization to understand what data exists, where it resides, and its level of sensitivity, which in turn informs the development of effective DLP policies and controls.

Discussion

12 comments
Sign in to comment
Adams159753Option: C
Dec 28, 2022

I think answer is C

Lapin_perduOption: C
Dec 22, 2022

answer is C

MichaelHoangOption: C
Jan 13, 2023

how can you create DLP policy without knowing which data needs to be applying with which protection? And how do you know which protection needs to be applied without knowing the classification of data? Hence, Data classification must be the first step. The answer is C

TTH1019Option: C
Jun 6, 2023

Before implementing a DLP solution, it is crucial to understand the organization's data landscape. Conducting a data inventory and classification exercise helps identify the types of data that need to be protected and their sensitivity levels. This step involves identifying the locations, formats, and repositories where data resides, as well as categorizing the data based on its sensitivity and regulatory requirements. This exercise forms the foundation for developing effective DLP policies and controls.

5b56aaeOption: C
Apr 22, 2024

1st step about inventory

ooramiOption: C
Mar 5, 2023

Answer is C

swmasindeOption: C
Mar 9, 2023

First, understand the needs of the business by identifying and prioritizing risks such as the data risk appetite. Then identify the data the business needs to protect, including intellectual property (IP), and verify the data and application owners.

meelaanOption: A
Sep 19, 2023

1st step would be policy. which will guide the implementation

blues_leeOption: C
Jan 17, 2024

C. Conduct a data inventory and classification exercise.

echo_certOption: C
Feb 24, 2024

C - You can't do anything without an inventory and classification of assets

RS66Option: C
Jun 27, 2024

classification

SwallowsOption: C
Jul 14, 2024

Identifying sensitive data and important information is the basis for developing DLP policies and conducting threat analysis. Clarifying what data needs to be protected will help you design subsequent policies and procedures.