CISA · Question #10
Management is concerned about sensitive information being intentionally or unintentionally emailed as attachments outside the organization by employees. What is the MOST important task before implemen
The correct answer is B. Develop an information classification scheme.. Before implementing email controls to prevent sensitive information exfiltration, the most crucial task is to develop an information classification scheme to define what data is considered sensitive and requires protection.
Question
Management is concerned about sensitive information being intentionally or unintentionally emailed as attachments outside the organization by employees. What is the MOST important task before implementing any associated email controls?
Options
- AProvide notification to employees about possible email monitoring.
- BDevelop an information classification scheme.
- CDevelop an acceptable use policy for end-user computing (EUC).
- DRequire all employees to sign nondisclosure agreements (NDAs).
How the community answered
(35 responses)- A3% (1)
- B77% (27)
- C14% (5)
- D6% (2)
Why each option
Before implementing email controls to prevent sensitive information exfiltration, the most crucial task is to develop an information classification scheme to define what data is considered sensitive and requires protection.
Notifying employees about monitoring is a legal and ethical consideration, but it doesn't define *what* sensitive data needs monitoring or protection.
An information classification scheme provides the essential framework for identifying, labeling, and handling sensitive data. Without clearly defined classifications, it's impossible to consistently and effectively configure email controls to detect and prevent the unauthorized transmission of specific types of sensitive information, leading to either over-blocking or under-protection.
An acceptable use policy is important for employee conduct but does not inherently define the technical characteristics of sensitive data that email controls need to enforce.
Requiring NDAs addresses legal protection and employee accountability but does not provide the technical basis for implementing automated controls to *prevent* data loss via email.
Concept tested: Data Loss Prevention (DLP) prerequisites, information classification
Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.