nerdexam
(ISC)2

CGRC · Question #241

___________________ information is defined as any information that the loss, misuse or unauthorized access would adversely affect the national interest or the conduct of federal programs or the privac

The correct answer is A. Sensitive. Sensitive information is defined by the potential adverse impact on national interest, federal programs, or individual privacy if mishandled. This classification requires robust protection due to the significant consequences of its compromise.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

___________________ information is defined as any information that the loss, misuse or unauthorized access would adversely affect the national interest or the conduct of federal programs or the privacy to which individuals are entitled. Response:

Options

  • ASensitive
  • BAvailability
  • CResponsibility
  • DCriticality

How the community answered

(27 responses)
  • A
    89% (24)
  • C
    7% (2)
  • D
    4% (1)

Why each option

Sensitive information is defined by the potential adverse impact on national interest, federal programs, or individual privacy if mishandled. This classification requires robust protection due to the significant consequences of its compromise.

ASensitiveCorrect

Sensitive information is explicitly defined in various government and organizational security frameworks as data whose compromise (loss, misuse, or unauthorized access) would have a detrimental effect on national interests, government operations, or individuals' privacy rights. This definition underscores the need for enhanced protection measures for such data.

BAvailability

Availability refers to the characteristic of data or systems being accessible and usable when needed, not the type of information itself.

CResponsibility

Responsibility refers to accountability for actions or duties, not a classification of information based on its impact.

DCriticality

Criticality refers to the importance of a system or function to an organization's mission, not a direct classification of information based on potential adverse effects.

Concept tested: Definition of sensitive information

Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-60v1r1.pdf

Topics

#Information Classification#Sensitive Information#Data Protection#Privacy

Community Discussion

No community discussion yet for this question.

Full CGRC Practice