CGEIT · Question #97
Which of the following MUST be established before implementing an information architecture that restricts access to data based on sensitivity?
The correct answer is C. Classification and ownership. Before implementing an information architecture that restricts data access based on sensitivity, it is essential to establish data classification and ownership.
Question
Which of the following MUST be established before implementing an information architecture that restricts access to data based on sensitivity?
Options
- ARisk and control frameworks
- BProbability and impact analysis
- CClassification and ownership
- DSecurity and privacy policies
How the community answered
(56 responses)- A14% (8)
- B4% (2)
- C73% (41)
- D9% (5)
Why each option
Before implementing an information architecture that restricts data access based on sensitivity, it is essential to establish data classification and ownership.
Risk and control frameworks provide the overall context for security but do not, in themselves, define the specific sensitivity or ownership of individual data elements.
Probability and impact analysis is part of risk assessment and quantifies potential harm but does not establish the fundamental classification or ownership of data.
Before restricting access based on sensitivity, an organization MUST classify its data to determine what is sensitive and establish data ownership to assign accountability, as these foundations define the criteria for applying access controls in the information architecture.
Security and privacy policies define the rules for protecting data but rely on prior classification and ownership to be effectively implemented and enforced regarding sensitivity-based access.
Concept tested: Data governance, information security foundations
Topics
Community Discussion
No community discussion yet for this question.