Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1538 discussion

Actual exam question from Isaca's CISA
Question #: 1538
Topic #: 1
[All CISA Questions]

Which of the following is the MOST appropriate procedure for an organization to use when classifying data?

  • A. Have the information security manager assign data classification levels.
  • B. Review data classification questionnaires completed by data owners.
  • C. Use results from business impact analyses to classify data.
  • D. Publish data classification templates on the corporate intranet.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
PurpleParrot
2 months ago
Selected Answer: B
option B Option B: Reviewing data classification questionnaires completed by data owners is a crucial step, as data owners are typically the best source of information about the data they handle. This method allows for input from those who are familiar with the data’s sensitivity and usage. Option C: While BIA is primarily used for understanding business processes, its insights can inform data classification decisions by highlighting which data supports critical processes and has significant business impact. However, it's not the direct method for classifying data itself.
upvoted 1 times
...
RS66
3 months ago
Selected Answer: C
C. Use results from business impact analyses to classify data.
upvoted 1 times
...
Binagr8
4 months ago
B. "Review data classification questionnaires completed by data owners" is the most appropriate procedure. Data owners, who are responsible for the data and understand its value and sensitivity, should be the ones to complete detailed questionnaires about the data. The information security team can then review these questionnaires and work with the data owners to determine the appropriate data classification levels. C. "Use results from business impact analyses to classify data" is not the most appropriate procedure for data classification. While business impact analyses can provide valuable insights, they may not capture the full context and nuances required for accurate data classification. Data classification should be a separate and more focused process that involves the data owners directly.
upvoted 2 times
...
joehong
4 months ago
Selected Answer: C
C. Use results from business impact analyses to classify data.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...