CAS-002 · Question #835
An IT auditor is reviewing the data classification for a sensitive system. The company has classified the data stored in the sensitive system according to the following matrix: DATA…
The correct answer is C. HIGH, HIGH, HIGH. When aggregating data classifications across multiple data types, the highest classification value in each category must be used - the high water mark principle - not an average.
Question
An IT auditor is reviewing the data classification for a sensitive system. The company has classified the data stored in the sensitive system according to the following matrix:
DATA TYPECONFIDENTIALITYINTEGRITYAVAILABILITY ----------------------------------------------------------------------- FinancialHIGHHIGHLOW Client nameMEDIUMMEDIUMHIGH Client addressLOWMEDIUMLOW ----------------------------------------------------------------------- AGGREGATEMEDIUMMEDIUMMEDIUM The auditor is advising the company to review the aggregate score and submit it to senior management. Which of the following should be the revised aggregate score?
Options
- AHIGH, MEDIUM, LOW
- BMEDIUM, MEDIUM, LOW
- CHIGH, HIGH, HIGH
- DMEDIUM, MEDIUM, MEDIUM
How the community answered
(61 responses)- A15% (9)
- B8% (5)
- C49% (30)
- D28% (17)
Why each option
When aggregating data classifications across multiple data types, the highest classification value in each category must be used - the high water mark principle - not an average.
HIGH, MEDIUM, LOW correctly identifies confidentiality as HIGH but incorrectly selects a middle value for integrity and the lowest value for availability instead of taking the highest across all data types.
MEDIUM, MEDIUM, LOW ignores that Financial data carries HIGH confidentiality and HIGH integrity ratings, and that Client name carries a HIGH availability rating.
The high water mark principle requires that the aggregate classification reflect the most restrictive (highest) value present in each CIA category across all data types. Financial data contributes HIGH to both confidentiality and integrity, while Client name contributes HIGH to availability. Therefore the correct aggregate is HIGH, HIGH, HIGH, not an average or median of the values.
MEDIUM, MEDIUM, MEDIUM is the existing incorrect aggregate that fails to apply the high water mark principle and underrepresents the true sensitivity of the combined dataset.
Concept tested: Data classification high water mark aggregation
Source: https://csrc.nist.gov/publications/detail/sp/800-60/vol-1/final
Topics
Community Discussion
No community discussion yet for this question.