CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 68


Why is data classification control important to an organization?

Show Answer
Correct Answer: C

Data classification control is crucial to an organization to ensure its integrity, confidentiality, and availability. By categorizing data based on its sensitivity and value, appropriate security measures and protocols can be implemented to protect it from unauthorized access, modification, and disruptions, thus maintaining the organization’s data security principles of confidentiality, integrity, and availability.

Discussion

17 comments
Sign in to comment
FiredragonOption: B
Nov 13, 2022

B. official study guide, P182. data classification only protects data confidentiality and integrity, it has nothing to do with availability. A data classification identifies the value of the data to the organization and is critical to protect data confidentiality and integrity.

jackdryan
May 11, 2023

B is correct

jackdryan
May 18, 2023

Changing to C

Meowson
Jul 17, 2023

Your reply can't be more meaningless for the discussion.

LoveguitarOption: B
Oct 12, 2022

C would be right if it aligns with the risk tolerance of the organization, why ensure the CIA if it does not align with your goals? the best choice is B

a88aas
Jan 31, 2023

Best Answer would be C. You don’t perform Data classification to ensure that “security controls” are aligned with the organisational risk appetite. It doesn’t make sense. You implement data classification to ensure that only individuals at specific clearance levels have access to read/write to specific sets of classified data (Confidentiality). Classifying the data would then In-turn, prove to be integral, & the availability piece would then be applicable

InclusiveSTEAMOption: B
Oct 9, 2023

The correct answer is B Data classification is important to enable security controls that align with an organization's risk appetite, so option B is correct. Properly classifying data allows applying security controls at levels commensurate with the data's sensitivity and criticality to the business. This ensures controls match the organization's priorities and risk profile. Option A is a benefit of classification but not the core purpose. Option C states generic goals rather than strategic alignment. Option D is also a secondary advantage, not the primary driver.

glenndexterOption: B
Nov 8, 2023

B Think like a manager, or perhaps a CISO.

Delab202Option: C
Dec 31, 2022

CIA is why we classify data-Simple.

Yokota
Jun 10, 2023

CIA is not why we classify data, it's confidentiality and need to know

Dee83Option: B
Jan 24, 2023

B. To ensure security controls align with organizational risk appetite is one of the reasons why data classification control is important to an organization. By classifying data based on its sensitivity and criticality, an organization can ensure that appropriate security controls are implemented to protect that data. This helps the organization to align its security efforts with its overall risk appetite and risk management strategy. Additionally, C. To ensure its integrity, confidentiality and availability is also a reason why data classification control is important. By classifying data, the organization can ensure that the appropriate level of protection is applied to the data to maintain its confidentiality, integrity, and availability. D. To control data retention in alignment with organizational policies and regulation is also a reason why data classification control is important. By classifying data, the organization can ensure that data is retained and disposed of in accordance with legal, regulatory, and organizational requirements.

da2_mxOption: D
Feb 10, 2023

I think is D for C the data classification can't address the availability and integrity For appetite not make sense, beacause the security strategy must driven by the business address (remember think first in human life, second in the business) for D the data retention involve a business process (example match with PCI regulation) so the business need to classify the data in orden to know with which data and if this data address with a regulation importan to the business

GoseuOption: D
May 6, 2023

The only thing that makes sense is D , C although its the most popular makes no sense .how can data classification achieve CIA ? E.g in Biba or Bell lapadula do you have all 3s from CIA ? Makes no sense .

YokotaOption: B
Jun 10, 2023

Data classification, public data, internal data, confidential data, and restricted data Data classification helps organizations understand the sensitivity and criticality of their data. By classifying data based on its importance, organizations can align their security controls and measures with their risk appetite. This ensures that appropriate security controls are applied to protect data according to its classification level.

Bach1968Option: B
Jul 5, 2023

Option B, "To ensure security controls align with organizational risk appetite," is indeed a valid reason for why data classification control is important to an organization. Data classification helps organizations align their security controls with their risk appetite by enabling them to identify and prioritize the protection of sensitive or critical data. It allows organizations to allocate resources and apply appropriate security measures based on the classification of data and the associated risks. By classifying data, organizations can determine the level of security controls and safeguards needed for each classification category. This ensures that security measures are proportionate to the level of risk associated with the data. It helps organizations focus their efforts and resources on protecting the most sensitive or high-risk data, while also ensuring that less critical data receives appropriate levels of protection. So, both option B ("To ensure security controls align with organizational risk appetite") and option C ("To ensure its integrity, confidentiality, and availability") are valid reasons for the importance of data classification control.

Dann108Option: B
Aug 31, 2023

though C sounds good, data classification contribute to confidentiality and integrity and less for availability, therefore I think "To ensure security controls align with organizational risk appetite" is the better answer

aape1Option: B
Oct 4, 2023

B. because it's all about Risk when comes to protecting the Data = values. Risk appetite in NIST definition is "The types and amount of risk, on a broad level, [an organization] is willing to accept in its pursuit of value."

SoleandheelOption: C
Dec 6, 2023

C. To ensure its integrity, confidentiality and availability

YesPleaseOption: B
Dec 10, 2023

Answer B) Data classification helps you provide the right level of protection based on the data's value, sensitivity, and the risk posed to the organization if that data is lost, stolen, or exposed

HongjunOption: C
Mar 3, 2024

Cissp 9th official guide chapter 5.1.2 page 157. The description of classification. It mentioned classification recognize the value of the data. It is important to protect the data integrity and confidentiality.

Ramye
May 28, 2024

So it’s not saying anything about availability, and that makes B as the answer.

73f8ac3Option: B
Apr 3, 2024

Correct answer is B you do not need data classification to protect the CIA. But you need it to adapt the appropriate controls to the level of sensitivity you classified the asset

CCNPWILLOption: B
Jun 3, 2024

Getting us back on the right course. B. To ensure security controls align with organizational risk appetite This is correct. ive seen different flavors of this same question. Data classification is primarily used to determine the appropriate security controls on it that align with the business risk appetite. this is the correct answer every time. Simply classifying it doesnt ensure jack anything. you need the controls. B