CRISC · Question #21
Before assigning sensitivity levels to information it is MOST important to:
The correct answer is B. define the information classification policy. Before assigning sensitivity levels, it is crucial to first establish a formal information classification policy that dictates how information assets should be categorized. This policy provides the framework and criteria for all subsequent classification activities.
Question
Before assigning sensitivity levels to information it is MOST important to:
Options
- Adefine recovery time objectives (RTOs).
- Bdefine the information classification policy
- Cconduct a sensitivity analyse
- DIdentify information custodians
How the community answered
(36 responses)- A3% (1)
- B89% (32)
- C6% (2)
- D3% (1)
Why each option
Before assigning sensitivity levels, it is crucial to first establish a formal information classification policy that dictates how information assets should be categorized. This policy provides the framework and criteria for all subsequent classification activities.
Recovery Time Objectives (RTOs) are related to business continuity and disaster recovery, not directly to the initial process of defining information sensitivity levels.
Defining the information classification policy establishes the fundamental rules, criteria, and procedures for how an organization will categorize its data based on sensitivity and business impact. This policy is a prerequisite, as it sets the guidelines that inform how sensitivity levels will be assigned, ensuring consistency and alignment with organizational objectives.
Conducting a sensitivity analysis is an action performed *after* the classification policy is defined, as it uses the policy's criteria to assess and assign actual sensitivity levels.
Identifying information custodians is important for data governance and accountability, but the overarching policy framework for classification must be in place before specific custodians can effectively manage data sensitivity.
Concept tested: Information classification policy foundation
Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/information-protection-overview?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.