CISA · Question #198
A startup organization wants to develop a data loss prevention (DLP) program. The FIRST step should be to implement:
The correct answer is C. data classification. Data classification must come first because you cannot protect data you haven't identified and categorized - without knowing what data is sensitive, critical, or public, any subsequent controls are applied blindly and inconsistently. Why the distractors are wrong: A (Security awa
Question
A startup organization wants to develop a data loss prevention (DLP) program. The FIRST step should be to implement:
Options
- Asecurity awareness training
- Baccess controls
- Cdata classification
- Ddata encryption
How the community answered
(61 responses)- A3% (2)
- B3% (2)
- C92% (56)
- D2% (1)
Explanation
Data classification must come first because you cannot protect data you haven't identified and categorized - without knowing what data is sensitive, critical, or public, any subsequent controls are applied blindly and inconsistently.
Why the distractors are wrong:
- A (Security awareness training): Training employees on handling data is valuable, but meaningless without first defining what data requires protection and why.
- B (Access controls): You can't determine who should access data until you know what the data is and how sensitive it is - classification drives access decisions.
- D (Data encryption): Encrypting everything is costly and impractical; classification tells you which data warrants encryption.
Memory tip: Think of DLP as building a house - classification is the blueprint. You wouldn't hire electricians (access controls), buy locks (encryption), or train workers (awareness) before you have a plan showing what rooms exist and what's in them.
Topics
Community Discussion
No community discussion yet for this question.