CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 100


While auditing a small organization's data classification processes and procedures, an IS auditor noticed that data is often classified at the incorrect level. What is the MOST effective way for the organization to improve this situation?

Show Answer
Correct Answer: C

The most effective way for an organization to improve the accuracy of its data classification is to have IT security staff conduct targeted training for data owners. Data owners are the individuals who create and handle the data, making them directly responsible for its classification. Targeted training can provide detailed guidance on the criteria for classification, examples of correct classification, and consequences of incorrect classification, thus addressing the issue directly and effectively.

Discussion

14 comments
Sign in to comment
DeeplaxmiOption: A
Sep 26, 2022

targetted seminars suite well in small company.

Eric0223Option: B
Jan 9, 2023

i would say B is more practical

MichaelHoang
Jan 13, 2023

why is it not B?

lsiau76Option: A
Aug 19, 2023

A. Conduct awareness presentations and seminars for information classification policies. The most effective way for the organization to improve the situation of incorrect data classification is to conduct awareness presentations and seminars for information classification policies (Option A). By providing targeted training and education to employees, data owners, and relevant staff, the organization can ensure that everyone understands the importance of proper data classification and the guidelines for doing so correctly. Raising awareness through presentations and seminars can help employees make informed decisions when classifying data, reducing the likelihood of incorrect classification.

OD1NOption: B
Dec 3, 2023

B is Correct

siva1963Option: C
Aug 28, 2023

C is correct as data owner is only deciding it

001YogeshOption: C
Dec 15, 2023

C as data owner classify the data so better go for targeted one

a84nOption: C
Apr 25, 2024

Answer: C

oldmagicOption: A
Jun 25, 2023

I would go with A here. People are incorrectly classifying data. They need to be trained on the classification policies.

Manuella75kOption: B
Aug 11, 2023

Une formation ciblée à destination des propriétaires de données semble la bonne solution

SwallowsOption: C
Apr 6, 2024

IT security staff should provide tailored training to data owners based on their roles, functions, and the types of data they handle.

Swallows
Jun 1, 2024

While awareness presentations and seminars (Option A) can be beneficial in educating staff about information classification policies, targeted training specifically for data owners conducted by IT security staff (Option C) is likely to be more effective in addressing the issue directly. This targeted training can provide detailed guidance on the criteria for classification, examples of correct classification, and consequences of incorrect classification. It allows for personalized interaction and addresses specific concerns and questions that data owners may have.

5b56aaeOption: A
Apr 22, 2024

Awareness program

46080f2Option: C
Jun 12, 2024

Data owners are the individuals who create and handle the data, making them directly responsible for its classification. Targeted training equips them with the knowledge and skills to accurately classify data based on its sensitivity level. A small organization can tailor the training to address the specific types of data they handle and the challenges they face with classification.

RS66Option: C
Jun 27, 2024

classification = data owners