nerdexam
Isaca

CISM · Question #626

Which of the following security initiatives should be the FIRST step in helping an organization maintain compliance with privacy regulations?

The correct answer is A. Implementing a data classification framework. Privacy regulations (GDPR, CCPA, HIPAA, etc.) are fundamentally about knowing what personal and sensitive data exists, where it resides, and how it is used. A data classification framework (A) establishes exactly this foundation - it enables the organization to identify, label, a

Submitted by salim_om· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following security initiatives should be the FIRST step in helping an organization maintain compliance with privacy regulations?

Options

  • AImplementing a data classification framework
  • BImplementing security information and event management (SIEM)
  • CDeveloping security awareness training
  • DInstalling a data loss prevention (DLP) solution

How the community answered

(55 responses)
  • A
    80% (44)
  • B
    4% (2)
  • C
    5% (3)
  • D
    11% (6)

Explanation

Privacy regulations (GDPR, CCPA, HIPAA, etc.) are fundamentally about knowing what personal and sensitive data exists, where it resides, and how it is used. A data classification framework (A) establishes exactly this foundation - it enables the organization to identify, label, and manage data based on sensitivity. Without knowing what data you have, you cannot meaningfully implement a DLP solution (D), tune a SIEM for data-related events (B), or create targeted security awareness training (C). Classification is the prerequisite that makes all other privacy compliance controls actionable.

Topics

#Data Classification#Privacy Compliance#Security Program Development#Foundational Controls

Community Discussion

No community discussion yet for this question.

Full CISM Practice