nerdexam
Isaca

CISM · Question #254

The PRIMARY reason to properly classify information assets is to determine:

The correct answer is C. the appropriate protection based on sensitivity. The primary reason to properly classify information assets is to determine the appropriate protection based on sensitivity. Information classification helps organizations apply the necessary security controls and measures commensurate with the sensitivity and criticality of the…

Submitted by alyssa_d· Apr 18, 2026Information Security Risk Management

Question

The PRIMARY reason to properly classify information assets is to determine:

Options

  • Aappropriate encryption strength using a risk-based approach.
  • Bthe business impact if assets are compromised.
  • Cthe appropriate protection based on sensitivity.
  • Duser access levels based on the need to know.

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    87% (26)
  • D
    7% (2)

Explanation

The primary reason to properly classify information assets is to determine the appropriate protection based on sensitivity. Information classification helps organizations apply the necessary security controls and measures commensurate with the sensitivity and criticality of the While understanding business impact, determining encryption strength, and establishing user access levels are important considerations, the main focus of classification is ensuring that information receives the right level of protection according to its sensitivity.

Topics

#Information Asset Classification#Data Sensitivity#Security Controls#Risk Treatment

Community Discussion

No community discussion yet for this question.

Full CISM Practice