Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesHard
A highly regulated financial institution is subject to strict compliance requirements for data protection. They implement a system that automatically categorizes data based on its sensitivity (e.g., Public, Internal, Confidential, Restricted) and applies corresponding security controls, such as encryption and access restrictions. This practice is best described as an element of which security program component?
- AData Classification Policy
- BIncident Response Plan
- CSecurity Awareness Training
- DVulnerability Management
Show answer & explanationAnswer & explanation
Correct answer: A. Data Classification Policy
Data classification is the process of categorizing data based on its sensitivity and impact if compromised, which then dictates the security controls applied to it. The scenario explicitly describes categorizing data by sensitivity and applying controls, which is the core function of a data classification policy.
Why the other options are wrong
- B. An Incident Response Plan deals with reacting to security breaches, not proactive data categorization.
- C. Security Awareness Training educates employees, but doesn't define how data itself is categorized and protected.
- D. Vulnerability Management focuses on identifying and remediating system weaknesses, not data categorization.
Data Classification
The process of organizing data into categories based on its sensitivity, value, and regulatory requirements, to ensure appropriate security controls are applied.
- Establishes levels like Public, Internal, Confidential, Restricted.
- Guides the implementation of access controls, encryption, and retention policies.
- Crucial for compliance with data protection regulations.
Memory trick: Security Program: Policy, Risk, Incident, Awareness, Data, Access