Q: 8
When classifying information, it is MOST important to align the classification to:
Options
Discussion
Option A, business risk. Info classification really needs to map directly to what could impact the business most.
A . Classification always comes back to business risk, since that's what determines the level of control or protection you need. Policy is important but it's built from risk assessments anyway.
A, Practice exams and the ISACA official review manual both say business risk is the top factor here. Someone disagree?
A
I don’t think it’s A. B makes more sense since aligning with the security policy ensures everyone classifies data the same way across the org. Business risk is important too but policies are what everyone actually follows day to day. Could be wrong here but that’s my take, especially thinking about real-life processes. Anyone disagree?
I don’t think B makes sense here. A (business risk) is what I saw on similar exam reports.
C/D? I can see why retention (C) and industry standards (D) might factor in, but real world classification always circles back to the impact on the business. Still, curious if there are any orgs out there that treat industry requirements as primary drivers. Most I've seen use risk at the core.
Why not C? Retention matters but classification really drives controls based on business risk, not just legal timelines.
Be respectful. No spam.
Question 8 of 35