nerdexam
Isaca

CGEIT · Question #228

An IT audit reveals inconsistent maintenance of data privacy in enterprise systems primarily due to a lack of data sensitivity categorizations. Once the categorizations are defined, what is the BEST l

The correct answer is A. Standardize data classification processes throughout the enterprise.. The best long-term strategic response is to standardize data classification processes throughout the enterprise, ensuring consistent application of privacy categorizations to all data.

Submitted by andreas_gr· Apr 18, 2026Governance of Enterprise IT

Question

An IT audit reveals inconsistent maintenance of data privacy in enterprise systems primarily due to a lack of data sensitivity categorizations. Once the categorizations are defined, what is the BEST long-term strategic response by IT governance to address this problem?

Options

  • AStandardize data classification processes throughout the enterprise.
  • BIncorporate enterprise privacy categorizations into contracts.
  • CRequire business impact analyses (BIAs) for enterprise systems.
  • DReassess the data governance policy.

How the community answered

(53 responses)
  • A
    64% (34)
  • B
    11% (6)
  • C
    6% (3)
  • D
    19% (10)

Why each option

The best long-term strategic response is to standardize data classification processes throughout the enterprise, ensuring consistent application of privacy categorizations to all data.

AStandardize data classification processes throughout the enterprise.Correct

Inconsistent data privacy stemming from a lack of data sensitivity categorizations is best addressed long-term by standardizing data classification processes across the entire enterprise. This ensures that once categories are defined, they are consistently applied, managed, and enforced across all systems and data, leading to uniform privacy maintenance.

BIncorporate enterprise privacy categorizations into contracts.

Incorporating privacy categorizations into contracts is a good step for third-party agreements but does not address the internal operational problem of inconsistent data privacy maintenance within enterprise systems.

CRequire business impact analyses (BIAs) for enterprise systems.

Requiring business impact analyses (BIAs) for enterprise systems focuses on the impact of disruption, which is different from ensuring consistent data privacy based on classification.

DReassess the data governance policy.

Reassessing the data governance policy might be a step, but the specific, actionable strategic response to implement the newly defined categorizations is process standardization.

Concept tested: Data governance, data classification standardization

Source: https://learn.microsoft.com/en-us/azure/purview/concept-data-classification

Topics

#Data Privacy#Data Classification#IT Governance Strategy#Process Standardization

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice