CGEIT · Question #70
An IT risk assessment for a large healthcare group revealed an increased risk of unauthorized disclosure of information. Which of the following should be established FIRST to address the risk?
The correct answer is C. Data classification policy. To address the increased risk of unauthorized data disclosure, the foundational first step is to establish a data classification policy.
Question
An IT risk assessment for a large healthcare group revealed an increased risk of unauthorized disclosure of information. Which of the following should be established FIRST to address the risk?
Options
- AData encryption tools
- BData loss prevention tools
- CData classification policy
- DData retention policy
How the community answered
(31 responses)- A10% (3)
- B3% (1)
- C84% (26)
- D3% (1)
Why each option
To address the increased risk of unauthorized data disclosure, the foundational first step is to establish a data classification policy.
Data encryption tools are technical controls that implement protection, but without classification, it's unclear which data needs encryption and to what level.
Data loss prevention (DLP) tools are technical controls designed to prevent data exfiltration, but their effectiveness relies on knowing what data is sensitive, which is determined by classification.
A data classification policy defines what data is sensitive, who can access it, and how it should be protected based on its criticality. This policy acts as the prerequisite for implementing technical controls like encryption or DLP, as it provides the necessary framework to understand what needs protection and how much.
A data retention policy defines how long data should be kept, which is related to data lifecycle but does not directly address the unauthorized disclosure risk in terms of defining sensitivity and access.
Concept tested: Foundational data governance for risk management
Source: https://learn.microsoft.com/en-us/purview/data-classification-overview
Topics
Community Discussion
No community discussion yet for this question.