nerdexam
Isaca

CGEIT · Question #315

Which of the following would be MOST helpful to an enterprise that wants to standardize how sensitive corporate data is handled?

The correct answer is A. Information classification framework. An information classification framework is most helpful for standardizing how sensitive corporate data is handled by categorizing data based on its sensitivity and defining specific handling requirements.

Submitted by cyberguy42· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following would be MOST helpful to an enterprise that wants to standardize how sensitive corporate data is handled?

Options

  • AInformation classification framework
  • BEnterprise risk policy
  • CEnterprise risk management (ERM) framework
  • DInformation security policy

How the community answered

(62 responses)
  • A
    84% (52)
  • B
    5% (3)
  • C
    2% (1)
  • D
    10% (6)

Why each option

An information classification framework is most helpful for standardizing how sensitive corporate data is handled by categorizing data based on its sensitivity and defining specific handling requirements.

AInformation classification frameworkCorrect

An information classification framework establishes categories (e.g., public, internal, confidential) and defines specific handling requirements for each, ensuring consistent protection levels across the enterprise. By clearly defining data types and associated controls, it allows for the standardization of security measures, access controls, and retention policies, which is essential for managing sensitive data consistently.

BEnterprise risk policy

An enterprise risk policy outlines the organization's overall stance and approach to risk, but it does not specifically detail how data is categorized or handled based on sensitivity.

CEnterprise risk management (ERM) framework

An Enterprise Risk Management (ERM) framework provides a structure for identifying, assessing, and responding to risks, but it does not directly prescribe how sensitive data should be classified or handled.

DInformation security policy

An information security policy sets broad rules and guidelines for protecting information assets, but an information classification framework provides the granular detail needed to standardize *how* sensitive data is specifically categorized and handled according to its sensitivity.

Concept tested: Information classification framework for data handling

Topics

#Information Classification#Data Governance#Information Security#Standardization

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice