nerdexam
Isaca

CGEIT · Question #422

Which of the following should be established FIRST so that data owners can consistently assess the level of data protection needed across the enterprise?

The correct answer is D. Data classification policy. To consistently determine appropriate data protection levels, an enterprise must first establish a clear data classification policy that categorizes data based on its sensitivity and business impact.

Submitted by noor.lb· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following should be established FIRST so that data owners can consistently assess the level of data protection needed across the enterprise?

Options

  • AData encryption program
  • BData risk management program
  • CData retention policy
  • DData classification policy

How the community answered

(52 responses)
  • A
    4% (2)
  • B
    8% (4)
  • C
    2% (1)
  • D
    87% (45)

Why each option

To consistently determine appropriate data protection levels, an enterprise must first establish a clear data classification policy that categorizes data based on its sensitivity and business impact.

AData encryption program

A data encryption program is a specific technical control for data protection; its implementation depends on a prior understanding of which data needs what level of protection, derived from classification.

BData risk management program

A data risk management program identifies and mitigates data-related risks, but it relies on a foundation of knowing what data exists and its classification to effectively assess potential risks.

CData retention policy

A data retention policy defines how long data should be kept, which is a crucial aspect of data lifecycle management, but it doesn't primarily guide the level of protection (e.g., encryption, access) needed during its active life.

DData classification policyCorrect

A data classification policy defines categories of data (e.g., public, confidential, secret) and assigns protection requirements to each category based on its sensitivity and value. Establishing this policy first provides data owners with a consistent framework to understand and apply the correct level of protection, such as encryption or access controls, to their respective data assets across the enterprise.

Concept tested: Data protection foundation

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/data-classification-overview?view=o365-worldwide

Topics

#Data classification#Information governance#Security policy#Data protection strategy

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice