nerdexam
Isaca

CISM · Question #322

A company has purchased a rival organization and is looking to align security strategies. Which of the following issues is MOST important to address?

The correct answer is A. Differing approaches to data classification. Data classification is the foundational layer that everything else in security depends on - if two organizations define "sensitive," "confidential," or "public" data differently, they cannot effectively protect assets, meet compliance obligations, or make consistent access…

Submitted by satoshi_tk· Apr 18, 2026Information Risk Management

Question

A company has purchased a rival organization and is looking to align security strategies. Which of the following issues is MOST important to address?

Options

  • ADiffering approaches to data classification
  • BDiffering operational security technologies
  • CDiffering organizational risk appetites
  • DDiffering security skills within the organizations

How the community answered

(20 responses)
  • A
    65% (13)
  • B
    5% (1)
  • C
    20% (4)
  • D
    10% (2)

Explanation

Data classification is the foundational layer that everything else in security depends on - if two organizations define "sensitive," "confidential," or "public" data differently, they cannot effectively protect assets, meet compliance obligations, or make consistent access control decisions across the merged entity. Without a unified classification scheme, every downstream security control (encryption, retention, sharing policies) will produce inconsistent and potentially dangerous results.

Why the distractors fall short:

  • B (Operational security technologies): Tool differences are a real challenge but are tactical - they can be integrated, replaced, or bridged without fundamentally breaking security posture.
  • C (Risk appetite): Leadership-level risk tolerance differences matter strategically, but they are typically reconciled at the executive level during M&A governance and don't create immediate data exposure the way classification gaps do.
  • D (Security skills): Skill gaps can be addressed through training and hiring; they don't create the same systemic data-protection failure that misaligned classification does.

Memory tip: Think of data classification as the "common language" of security - if both sides are speaking different dialects about what data matters and how much, no other security alignment conversation can be productive. In M&A security questions, always prioritize what breaks everything else if left unresolved.

Topics

#Data Classification#M&A Security#Information Asset Protection#Risk Prioritization

Community Discussion

No community discussion yet for this question.

Full CISM Practice