CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 118


Which of the following criteria ensures information is protected relative to its importance to the organization?

Show Answer
Correct Answer: A

The criteria that ensure information is protected relative to its importance to the organization include legal requirements, the value of the information, its criticality to business operations, and its sensitivity to unauthorized disclosure or modification. Legal requirements ensure compliance with laws and regulations, while considering value and criticality helps prioritize resources to protect the most important information. Sensitivity to unauthorized disclosure or modification addresses the need to safeguard against breaches that could harm the organization. Therefore, the answer encompasses all necessary aspects for information protection.

Discussion

11 comments
Sign in to comment
JAckThePipOption: A
Oct 3, 2022

Answer is A "Information must be classified in terms of legal requirements, value, criticality and sensitivity to any unauthorised disclosure or modification, ideally classified to reflect business activity rather than inhibit or complicate" https://www.isms.online/iso-27001/annex-a-8-asset-management/

jackdryan
May 12, 2023

A is correct

CuteRabbit168Option: A
Sep 9, 2022

A data classification identifies the value of the data to the organization and is critical to protect data confidentiality and integrity.

Cww1Option: A
Sep 20, 2022

agree with A

gooftroopOption: C
Sep 8, 2022

C. Organizational stakeholders, with classification approved by the management board

Rollizo
Sep 30, 2022

really it is A, because you need first to classify for the stakeholders take the decision

Ramye
May 20, 2024

This is exactly what my thinking. Information needs to be protected according to organization’s needs and not just because we want to.

[Removed]Option: A
Oct 26, 2022

A all day baby!

somkiatrOption: A
Dec 30, 2022

Just eliminated B,C, and D then chose A.

xxxBadManxxxOption: C
Jun 6, 2023

c is the correct ans

HughJassoleOption: A
Jun 24, 2023

A. It's all encompassing.

Bach1968Option: A
Jul 6, 2023

A. Legal requirements, value, criticality, and sensitivity to unauthorized disclosure or modification. Ensuring that information is protected relative to its importance to the organization involves considering several criteria. Legal requirements, such as data protection laws and industry regulations, provide a baseline for protecting sensitive information.

georgegeorge125487Option: C
Aug 17, 2023

Information is protected as a result of management decision, not because you identify criteria to classify information.

RamyeOption: B
Jun 26, 2024

Organization’s senior management decides the value of the data and we have to protect those accordingly. We do not secure and put controls without senior managements’ input.

Ramye
Jun 26, 2024

On a second thought, I think C is more important than B. Stakeholders (business owners) are the data owners and their input is most important.