CISSP Practice Question (Domain 2: Asset Security)
Your organization classifies data into four tiers, but a recent audit reveals that 60% of assets remain unclassified because data owners dispute classification responsibility with IT custodians. What should you do FIRST?
A. Default all unclassified assets to the highest classification tier
B. Assign IT custodians temporary classification authority to eliminate the backlog
C. Clarify data ownership roles and accountability in the classification policy
D. Implement automated classification tools to remove the human bottleneck
Please share your thinking, I'd really like to know how everyone looks at this very real world scenario.
Come back for the answer tomorrow, or study more now!
3
25 comments
Vincent Primiani
7
CISSP Practice Question (Domain 2: Asset Security)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by