nerdexam
Isaca

CGEIT · Question #294

Which of the following is the BEST indication that information security requirements are taken into consideration when developing IT processes?

The correct answer is B. The information architecture incorporates data classification. Integrating data classification into the information architecture demonstrates a fundamental consideration of information security requirements early in the design process.

Submitted by amina.ke· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following is the BEST indication that information security requirements are taken into consideration when developing IT processes?

Options

  • AThe database is deployed in a distributed processing platform
  • BThe information architecture incorporates data classification
  • CCustomer profiles are stored with a domestic service provider
  • DThe integrity of sensitive information is periodically reviewed

How the community answered

(32 responses)
  • A
    9% (3)
  • B
    69% (22)
  • C
    19% (6)
  • D
    3% (1)

Why each option

Integrating data classification into the information architecture demonstrates a fundamental consideration of information security requirements early in the design process.

AThe database is deployed in a distributed processing platform

Deploying a database in a distributed processing platform is an architectural choice for performance or scalability, not directly indicative of specific information security requirements being considered.

BThe information architecture incorporates data classificationCorrect

When the information architecture incorporates data classification, it signifies that information security requirements have been fundamentally considered at the design stage of IT processes. Data classification is the foundation for applying appropriate security controls based on the sensitivity and criticality of information, directly indicating that security has been embedded into how data is structured and managed.

CCustomer profiles are stored with a domestic service provider

Storing customer profiles with a domestic service provider might address data residency or compliance concerns, but it doesn't indicate a comprehensive approach to integrating security requirements into IT processes.

DThe integrity of sensitive information is periodically reviewed

Periodically reviewing the integrity of sensitive information is an operational security control or audit activity, which occurs after processes are developed, rather than indicating that security was considered during their development.

Concept tested: Security by design, information architecture

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security/security-governance#data-classification-standard

Topics

#Information Security Requirements#IT Process Development#Data Classification#Information Architecture

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice