most appropriate control for asset data labeling procedures because it helps to ensure that data is appropriately labeled and protected based on its sensitivity and value. Different types of media may require different levels of security, and categorizing them allows organizations to implement appropriate controls.
Option B sounds more logical to me. Assets can easily get lost without inventory, and you can't protect what you don't have.
I think there's a grey area here because labeling requires both classification and categorization of data.
By classifying data based on sensitivity, value, and criticality, organizations can apply appropriate security controls and protection measures. This approach ensures that sensitive information is handled with the necessary care, REGARDLESS OF THE MEDIA ON WHICH IT IS STORED.
Categorizing media types is still important for physical security and access controls, but it's a secondary consideration compared to data classification.
Review is important during audits, not necessarily during data labeling.
Answer A)
Classification versus Categorization:
Classification by itself is simply a system of classes set up by an organization to differentiate asset values and, therefore, protection levels. The act of assigning a classification level to an asset is called categorization. Ideally, all assets should be categorized into a classification system to allow them to be protected based on value.
https://destcert.com/resources/domain-2-asset-security/
The MOST appropriate control for asset data labeling procedures is option A: Categorizing the types of media being used.
Asset data labeling procedures involve labeling and categorizing different types of media (such as physical storage devices, electronic media, or documents) to effectively manage and track data assets. Categorizing the types of media being used helps in identifying and distinguishing between different storage devices and media types, allowing for better organization and control.
By categorizing the types of media, organizations can implement appropriate security controls and procedures tailored to each category. This includes assigning different levels of sensitivity or classification to data stored on specific media, implementing access controls based on media types, and applying specific handling and disposal procedures.
The question is asking "control for asset data labeling". So how to label data that is an asset, for example an application or a database with customer info. A CMDB does that, that's where you store all this info, and everything is a Configuration Item and has all relevant info. So the answer is B.
I go with B.
While categorizing the types of media being used and reviewing audit trails of logging records are important controls, it may not be as directly relevant to asset data labeling procedures as logging data media to provide a physical inventory control.
The most appropriate control for asset data labeling procedures is B. Logging data media to provide physical inventory control. By logging the data media, organizations can keep track of all of the different types of media being used, such as CDs, USBs, hard drives, etc. Organizations can also use the logs to track the movement of data media within the organization, including any off-site storage access controls. Additionally, by logging data media, organizations can review audit trails of logging records to ensure that all data media is properly labeled and accounted for. Resources include National Institute of Standards and Technology (NIST) Special Publication 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, and The National Archives, Guidance on the Management of Data Media Labeling.
We are talking about the data itself not the medium
upvoted 4 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
stickerbush1970
Highly Voted 2 years, 2 months agojackdryan
1 year, 6 months agorobervalchocolat
Most Recent 2 months, 3 weeks agodeeden
3 months, 3 weeks agoCCNPWILL
7 months, 1 week agoYesPlease
11 months, 2 weeks agoVince_F_Fang
1 year, 2 months ago50e940e
4 months, 3 weeks agoBach1968
1 year, 4 months agoHughJassole
1 year, 5 months agoRollingalx
1 year, 8 months agos_n_
1 year, 9 months agoBilly235
1 year, 11 months agoFiredragon
2 years agoJimmyliu0822
2 years agoBhuraw
2 years agoDButtare
2 years, 2 months ago