CISM · Question #626
Which of the following security initiatives should be the FIRST step in helping an organization maintain compliance with privacy regulations?
The correct answer is A. Implementing a data classification framework. Privacy regulations (GDPR, CCPA, HIPAA, etc.) are fundamentally about knowing what personal and sensitive data exists, where it resides, and how it is used. A data classification framework (A) establishes exactly this foundation - it enables the organization to identify, label, a
Question
Which of the following security initiatives should be the FIRST step in helping an organization maintain compliance with privacy regulations?
Options
- AImplementing a data classification framework
- BImplementing security information and event management (SIEM)
- CDeveloping security awareness training
- DInstalling a data loss prevention (DLP) solution
How the community answered
(55 responses)- A80% (44)
- B4% (2)
- C5% (3)
- D11% (6)
Explanation
Privacy regulations (GDPR, CCPA, HIPAA, etc.) are fundamentally about knowing what personal and sensitive data exists, where it resides, and how it is used. A data classification framework (A) establishes exactly this foundation - it enables the organization to identify, label, and manage data based on sensitivity. Without knowing what data you have, you cannot meaningfully implement a DLP solution (D), tune a SIEM for data-related events (B), or create targeted security awareness training (C). Classification is the prerequisite that makes all other privacy compliance controls actionable.
Topics
Community Discussion
No community discussion yet for this question.