nerdexam
Isaca

CRISC · Question #21

Before assigning sensitivity levels to information it is MOST important to:

The correct answer is B. define the information classification policy. Before assigning sensitivity levels, it is crucial to first establish a formal information classification policy that dictates how information assets should be categorized. This policy provides the framework and criteria for all subsequent classification activities.

Submitted by manish99· Apr 18, 2026Governance

Question

Before assigning sensitivity levels to information it is MOST important to:

Options

  • Adefine recovery time objectives (RTOs).
  • Bdefine the information classification policy
  • Cconduct a sensitivity analyse
  • DIdentify information custodians

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    89% (32)
  • C
    6% (2)
  • D
    3% (1)

Why each option

Before assigning sensitivity levels, it is crucial to first establish a formal information classification policy that dictates how information assets should be categorized. This policy provides the framework and criteria for all subsequent classification activities.

Adefine recovery time objectives (RTOs).

Recovery Time Objectives (RTOs) are related to business continuity and disaster recovery, not directly to the initial process of defining information sensitivity levels.

Bdefine the information classification policyCorrect

Defining the information classification policy establishes the fundamental rules, criteria, and procedures for how an organization will categorize its data based on sensitivity and business impact. This policy is a prerequisite, as it sets the guidelines that inform how sensitivity levels will be assigned, ensuring consistency and alignment with organizational objectives.

Cconduct a sensitivity analyse

Conducting a sensitivity analysis is an action performed *after* the classification policy is defined, as it uses the policy's criteria to assess and assign actual sensitivity levels.

DIdentify information custodians

Identifying information custodians is important for data governance and accountability, but the overarching policy framework for classification must be in place before specific custodians can effectively manage data sensitivity.

Concept tested: Information classification policy foundation

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/information-protection-overview?view=o365-worldwide

Topics

#Information Classification#Security Policy#Risk Governance#Information Sensitivity

Community Discussion

No community discussion yet for this question.

Full CRISC Practice