Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 693 discussion

Actual exam question from Isaca's CISM
Question #: 693
Topic #: 1
[All CISM Questions]

Which of the following is MOST important to ensuring information stored by an organization is protected appropriately?

  • A. Defining security asset categorization
  • B. Assigning information asset ownership
  • C. Developing a records retention schedule
  • D. Defining information stewardship roles
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
aokisan
Highly Voted 1 year, 11 months ago
Selected Answer: B
data owner is important for assurance.
upvoted 10 times
...
Boomers
Highly Voted 1 year, 9 months ago
Selected Answer: A
A. Defining security asset categorization is the MOST important to ensuring information stored by an organization is protected appropriately. This involves classifying and prioritizing information assets based on their level of sensitivity and the impact to the organization in the event of a security breach. This helps to determine the appropriate level of protection needed for each asset and guides the development of security controls.
upvoted 7 times
ats20
8 months, 2 weeks ago
Agree with A - Assigning ownership is important aspects but it is typically built upon a foundation of well-defined security asset categorization.
upvoted 1 times
...
...
pgonza
Most Recent 2 months, 3 weeks ago
Selected Answer: A
Its A. Before you decide what controls area appropriate, you got yo categorize (classify) your information assets. The owners can be assigned based on sensitivity.
upvoted 1 times
...
03allen
4 months, 3 weeks ago
Selected Answer: B
A is for effectiveness, B is the most important
upvoted 2 times
...
yottabyte
8 months ago
Selected Answer: A
A seems to be correct, Asset categorization is required.
upvoted 1 times
...
xcjxcj
8 months, 1 week ago
Selected Answer: B
A = label your computer as class A B = assign computer ownership to you B is better assurence
upvoted 2 times
...
Salilgen
8 months, 2 weeks ago
Selected Answer: A
Identify asset ownership (option B) is necessary to classify security asset but to ensuring information is protected appropriately occur that assets are categorized. Then B should be the FIRST and A is the MOST important thing
upvoted 1 times
...
REHAMAZZAM
9 months, 2 weeks ago
Selected Answer: B
B. Assigning information asset ownership Assigning information asset ownership is the most important aspect of ensuring that information stored by an organization is protected appropriately. When information assets have clearly defined owners, individuals or teams are accountable for their protection, including implementing security measures, monitoring for threats, and ensuring compliance with policies and regulations. This accountability fosters a sense of responsibility and promotes proactive management of information security risks. While options A, C, and D are also important components of an effective information security program, assigning ownership directly addresses the fundamental responsibility for protecting information assets.
upvoted 2 times
...
AlexJacobson
9 months, 3 weeks ago
Selected Answer: B
I'm gonna go with B here, because B does A.
upvoted 1 times
...
blehbleh
10 months, 2 weeks ago
Selected Answer: A
I think the answer is A. You have to know how to protect something and classify it to meet the requirements of appropriate protection. Assigning an owner doesn't inherently set a standard for classification protection. Therefore you need to have criteria for classification to standardize protection.
upvoted 1 times
...
Marcovic00
12 months ago
Selected Answer: A
If the asset has an owner but there is no criteria to calssify the data how would it help?
upvoted 1 times
...
Kunzle
1 year, 2 months ago
Selected Answer: B
Assigning information asset ownership ensures that there is a designated individual or group responsible for the protection, use, and lifecycle management of specific information assets. The asset owner makes decisions about security controls based on the value and sensitivity of the information and is accountable for its protection. Having a clear ownership helps in effectively managing and protecting the asset according to organizational policies and requirements.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: B
B. Assigning information asset ownership All of the options listed (A, B, C, and D) are important for ensuring that information stored by an organization is protected appropriately. However, if we had to prioritize them in terms of importance, it would typically be as follows: B > A > D > C
upvoted 2 times
...
Goseu
1 year, 4 months ago
Selected Answer: A
A seems right .
upvoted 1 times
...
richck102
1 year, 4 months ago
B. Assigning information asset ownership
upvoted 1 times
...
jennarink13
1 year, 4 months ago
A. While ownership entails accountability, it doesn't mean that it is appropriately protected. For instance, misclassifying a sensitive information, although you have an owner, the level of protection is not appropriate since it is not properly classified.
upvoted 1 times
...
zero46
1 year, 4 months ago
Selected Answer: B
Asset owner will define asset category
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...