nerdexam
Isaca

CISM · Question #57

What should be the PRIMARY objective of an information classification scheme?

The correct answer is D. To implement controls proportionate to risk. The primary objective of an information classification scheme is to implement security controls that are proportionate to the risk associated with the data's sensitivity and value.

Submitted by the_admin· Apr 18, 2026Information Security Risk Management

Question

What should be the PRIMARY objective of an information classification scheme?

Options

  • ATo define data retention requirements
  • BTo develop an asset inventory
  • CTo meet legislative and regulatory requirements
  • DTo implement controls proportionate to risk

How the community answered

(35 responses)
  • A
    3% (1)
  • C
    3% (1)
  • D
    94% (33)

Why each option

The primary objective of an information classification scheme is to implement security controls that are proportionate to the risk associated with the data's sensitivity and value.

ATo define data retention requirements

While classification can inform data retention, defining retention requirements is a secondary outcome and not the primary objective of classification itself.

BTo develop an asset inventory

An asset inventory lists assets, but classification specifically focuses on the *information* within those assets to determine its protection needs, not just inventorying.

CTo meet legislative and regulatory requirements

Meeting legislative and regulatory requirements is a goal that classification helps achieve, but the direct *mechanism* is enabling proportionate control implementation.

DTo implement controls proportionate to riskCorrect

The primary objective of an information classification scheme is to implement controls proportionate to risk by categorizing information based on its sensitivity, value, and criticality. This classification allows organizations to apply appropriate security measures, such as access controls, encryption, and handling procedures, ensuring that the most valuable and sensitive data receives the highest level of protection without over-securing less critical information.

Concept tested: Information classification objectives

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/data-classification-overview

Topics

#Information Classification#Risk Management#Security Controls#Proportionality

Community Discussion

No community discussion yet for this question.

Full CISM Practice