CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 234


When classifying information, it is MOST important to align the classification to:

Show Answer
Correct Answer: AD

When classifying information, it is most important to align the classification to the security policy. The security policy provides a framework for how information should be protected based on its sensitivity and importance to the organization. It outlines the rules for the classification of data, ensuring that the appropriate security measures are applied consistently across the organization. While business risk, data retention requirements, and industry standards are important considerations, the overarching guidance for classification should come from the security policy to ensure comprehensive protection and compliance.

Discussion

9 comments
Sign in to comment
3008Option: D
Jun 11, 2023

D IS ANSWER

3008
Jun 17, 2023

Business risk is also an important consideration when classifying information, but it is typically addressed in the security policy. The security policy should identify the risks that the organization faces and the measures that should be implemented to mitigate those risks. The classification system should reflect the risks identified in the security policy, ensuring that sensitive data is protected appropriately.

shiowbahOption: A
Sep 10, 2023

A. business risk.

[Removed]Option: A
Oct 23, 2023

A. business risk.

Aboodi000Option: A
Nov 13, 2023

I will go withe Bessines risk A

mibg83Option: D
Jun 7, 2023

security police

cidigiOption: C
Aug 21, 2023

C to me.

dan08Option: A
Feb 24, 2024

Isn't the usual classification is High, Mid, and Low? These are all relating to risks right. When classifying information, the most important consideration is to align the classification to business risk. Information classification involves categorizing data based on its level of sensitivity and importance.

SwallowsOption: D
Apr 9, 2024

The classification of information assets functions like a label in determining the degree of control and management of information by value and importance.

HengaOption: A
Jun 13, 2024

A, based oncriticality