CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 155


Which factors MUST be considered when classifying information and supporting assets for risk management, legal discovery, and compliance?

Show Answer
Correct Answer: C

When classifying information and supporting assets for risk management, legal discovery, and compliance, the essential factors include data stewardship roles, data handling and storage standards, and data lifecycle requirements. Data stewardship ensures that data management practices meet business needs and regulatory requirements, focusing on data quality, accessibility, security, and lifecycle. These elements are critical for appropriately classifying data and assets, ensuring their protection and compliance with legal and regulatory standards.

Discussion

14 comments
Sign in to comment
sandeepghadgeOption: C
Oct 13, 2022

"classifying information " isnt its Data owner(steward) job ?

jackdryan
May 13, 2023

C is correct

franbarproOption: C
Oct 21, 2022

From Google: Data stewardship is the collection of practices that ensure an organization's data is accessible, usable, safe, and trusted.

DracoLOption: C
Oct 31, 2022

It is data lifecycle not secure development lifecycle. This is really a give away why it is NOT A.

Hava_2013
Nov 14, 2022

secure development is for the Due Diligence part

Delab202Option: C
Jan 2, 2023

Data steward A person responsible for data management from a business and stakeholder perspective; may or may not also be a custodian or owner. Data stewards ensure that data quality meets business needs, that data is supported by sufficient metadata to make it easy to use, and that it meets all regulatory requirements. They also work with stakeholders to create and monitor data acquisition and dissemination procedures.

obanOption: A
Jan 11, 2023

A. System owner roles and responsibilities, data handling standards, storage and secure development lifecycle requirements are important factors that must be considered when classifying information and supporting assets for risk management, legal discovery, and compliance. In order to effectively manage the risks associated with sensitive information, it is important to understand who is responsible for that information, how it is supposed to be handled, and where and how it is stored. This includes understanding the roles and responsibilities of system owners, who are responsible for the security and operation of the systems that hold the data, as well as the standards for data handling and storage and the requirements for secure development lifecycle (SDLC) . This can help organizations to ensure that they are following best practices for protecting sensitive information and meeting regulatory requirements. B,C and D options also include some important factors that need to be considered but A option covers most of the important points for classifying information and assets for risk management, legal discovery and compliance. - openai

kuberkOption: A
Nov 1, 2022

It is not specifically for data, hence A makes more sense

JamatiOption: C
Nov 9, 2022

Definitely C

somkiatrOption: C
Jan 2, 2023

C is better than A. Reference : https://www.techtarget.com/searchdatamanagement/definition/data-stewardship

MG1707Option: C
Oct 15, 2022

data stewards are first to be asked...

SoleandheelOption: C
Dec 9, 2023

Guys the correct answer is C. Data Stewart..... A. could have been the best answer if it said Data owner as opposed to system owner.

boyinOption: A
Dec 18, 2022

The question is asking for "classifying information and supporting assets"

Moose01Option: A
Oct 30, 2023

Life Cycle! Categorize the Data, Classify (active data, or data at rest, retention period) all these is covered in the question itself. Data Owner is responsible to identifying and categorizing, legal team is will decide how to retain the data, data at rest must be secured (encrypted). the answer is "A" - See below Oban has good explanation

splash2357Option: C
Jan 23, 2024

Since the question doesn't specify the assets are: - related to software development (e.g. source code repositories) - storage only - on the cloud I'm going with C

TheManiacOption: C
May 18, 2024

classifying information = classifying data. Other options do not talk about data, but A and C. A starts with system owner roles. System owner or Data steward. Which one is more important on this issue? Data steward. So, it is C