Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1495 discussion

Actual exam question from Isaca's CISA
Question #: 1495
Topic #: 1
[All CISA Questions]

What is the FIRST step when creating a data classification program?

  • A. Develop a policy.
  • B. Develop data process maps.
  • C. Categorize and prioritize data.
  • D. Categorize information by owner.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
PurpleParrot
1 month, 1 week ago
Selected Answer: A
As per CRM, it is data policy followed by data classification.
upvoted 3 times
...
RS66
3 months ago
Selected Answer: C
C. Categorize and prioritize data.
upvoted 1 times
...
Swallows
5 months, 3 weeks ago
Selected Answer: A
The first step when creating a data classification program is to develop a policy. This policy outlines the objectives, scope, and guidelines for classifying data within an organization. It provides the framework for identifying, categorizing, and protecting sensitive information based on its importance and sensitivity. Once the policy is established, the organization can proceed with categorizing and prioritizing data (option C) according to the guidelines outlined in the policy.
upvoted 2 times
RS66
3 months ago
The policy will be build based on the classification. So you need classification first.
upvoted 1 times
...
...
Swallows
7 months, 2 weeks ago
Selected Answer: C
Inventorying data assets is the first step.
upvoted 1 times
...
Yejide03
8 months ago
C. Categorize and prioritize data. Before developing policies or processes, it's essential to categorize and prioritize the organization's data based on its sensitivity, criticality, and regulatory requirements. This step helps identify the different types of data handled by the organization and allows for the implementation of appropriate security controls and measures. Once data has been categorized and prioritized, policies and procedures can be developed to govern its handling, storage, transmission, and disposal in accordance with its classification level. Therefore, categorizing and prioritizing data sets the foundation for effective data classification and management within the organization.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...