Yeah, D for sure. You need a data classification policy first or else there's no standard way for data owners to know how sensitive anything is. Everything else like risk management or encryption relies on that baseline. Pretty confident, but if someone thinks B makes more sense let me know.
Maybe D makes more sense here. Data classification policy usually comes before risk management because you need to know what type of data you have before you can figure out the risks or decide retention/encryption. B is tempting but it's a bit of a trap in this context I think. Anyone see a reason to pick B over D?
I see why most go with D, but I'm thinking B here. Wouldn't you need a data risk management program so owners know what type of threats and exposures to assess before applying any standards? Policy alone might not be enough in weird edge cases where regulatory risk isn't defined yet. I think B fits first if they're worried about risk exposure upfront. Open to other viewpoints if I missed something.