CGEIT · Question #294
Which of the following is the BEST indication that information security requirements are taken into consideration when developing IT processes?
The correct answer is B. The information architecture incorporates data classification. Integrating data classification into the information architecture demonstrates a fundamental consideration of information security requirements early in the design process.
Question
Which of the following is the BEST indication that information security requirements are taken into consideration when developing IT processes?
Options
- AThe database is deployed in a distributed processing platform
- BThe information architecture incorporates data classification
- CCustomer profiles are stored with a domestic service provider
- DThe integrity of sensitive information is periodically reviewed
How the community answered
(32 responses)- A9% (3)
- B69% (22)
- C19% (6)
- D3% (1)
Why each option
Integrating data classification into the information architecture demonstrates a fundamental consideration of information security requirements early in the design process.
Deploying a database in a distributed processing platform is an architectural choice for performance or scalability, not directly indicative of specific information security requirements being considered.
When the information architecture incorporates data classification, it signifies that information security requirements have been fundamentally considered at the design stage of IT processes. Data classification is the foundation for applying appropriate security controls based on the sensitivity and criticality of information, directly indicating that security has been embedded into how data is structured and managed.
Storing customer profiles with a domestic service provider might address data residency or compliance concerns, but it doesn't indicate a comprehensive approach to integrating security requirements into IT processes.
Periodically reviewing the integrity of sensitive information is an operational security control or audit activity, which occurs after processes are developed, rather than indicating that security was considered during their development.
Concept tested: Security by design, information architecture
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security/security-governance#data-classification-standard
Topics
Community Discussion
No community discussion yet for this question.