nerdexam
Isaca

CGEIT · Question #70

An IT risk assessment for a large healthcare group revealed an increased risk of unauthorized disclosure of information. Which of the following should be established FIRST to address the risk?

The correct answer is C. Data classification policy. To address the increased risk of unauthorized data disclosure, the foundational first step is to establish a data classification policy.

Submitted by daniela_cl· Apr 18, 2026Governance of Enterprise IT

Question

An IT risk assessment for a large healthcare group revealed an increased risk of unauthorized disclosure of information. Which of the following should be established FIRST to address the risk?

Options

  • AData encryption tools
  • BData loss prevention tools
  • CData classification policy
  • DData retention policy

How the community answered

(31 responses)
  • A
    10% (3)
  • B
    3% (1)
  • C
    84% (26)
  • D
    3% (1)

Why each option

To address the increased risk of unauthorized data disclosure, the foundational first step is to establish a data classification policy.

AData encryption tools

Data encryption tools are technical controls that implement protection, but without classification, it's unclear which data needs encryption and to what level.

BData loss prevention tools

Data loss prevention (DLP) tools are technical controls designed to prevent data exfiltration, but their effectiveness relies on knowing what data is sensitive, which is determined by classification.

CData classification policyCorrect

A data classification policy defines what data is sensitive, who can access it, and how it should be protected based on its criticality. This policy acts as the prerequisite for implementing technical controls like encryption or DLP, as it provides the necessary framework to understand what needs protection and how much.

DData retention policy

A data retention policy defines how long data should be kept, which is related to data lifecycle but does not directly address the unauthorized disclosure risk in terms of defining sensitivity and access.

Concept tested: Foundational data governance for risk management

Source: https://learn.microsoft.com/en-us/purview/data-classification-overview

Topics

#Data Classification#Information Security Policy#Risk Mitigation#IT Governance

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice