CISM · Question #207
What should be used to determine whether an information asset should be protected with multi- layered security?
The correct answer is B. Classification level of the asset. The classification level of an information asset determines the sensitivity and criticality of the data, which in turn drives the appropriate depth of security controls. Multi-layered (defense-in-depth) security is warranted for highly classified or sensitive assets. RPO (A)…
Question
What should be used to determine whether an information asset should be protected with multi- layered security?
Options
- ARecovery point objective (RPO)
- BClassification level of the asset
- CReplacement cost of the asset
- DRecovery time objective (RTO)
How the community answered
(48 responses)- A2% (1)
- B92% (44)
- C2% (1)
- D4% (2)
Explanation
The classification level of an information asset determines the sensitivity and criticality of the data, which in turn drives the appropriate depth of security controls. Multi-layered (defense-in-depth) security is warranted for highly classified or sensitive assets. RPO (A) and RTO (D) are recovery metrics related to availability, not to the sensitivity of data requiring layered protection. Replacement cost (C) is a financial metric, not a direct indicator of the need for multi-layered controls. Classification is the primary driver for protection requirements.
Topics
Community Discussion
No community discussion yet for this question.