Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium
A company is developing a new data classification policy. They decide to label data into categories such as 'Public,' 'Internal Use Only,' 'Confidential,' and 'Restricted.' What is the primary purpose of classifying data in this manner?
- ATo determine appropriate security controls and handling requirements.
- BTo ensure data availability during a disaster.
- CTo establish non-repudiation for data transactions.
- DTo simplify data backup and recovery processes.
Show answer & explanationAnswer & explanation
Correct answer: A. To determine appropriate security controls and handling requirements.
Data classification assigns sensitivity levels to data, which then dictates the specific security controls (e.g., encryption, access restrictions) and handling procedures (e.g., storage, sharing) required to protect it effectively. Higher classifications demand stronger controls.
Why the other options are wrong
- B. While indirectly related to disaster recovery, classification's primary goal isn't just availability.
- C. Non-repudiation is about proving actions, not about data sensitivity and controls.
- D. Simplifying backup is a potential side benefit, but not the main objective of classification.
Data Classification
The process of organizing data into categories based on its sensitivity, value, and regulatory compliance requirements. This helps organizations determine the appropriate security controls needed to protect the data.
- Common classifications include Public, Internal, Confidential, Restricted.
- Determines access permissions, encryption standards, storage locations.
- Essential for compliance with regulations like GDPR, HIPAA.
Memory trick: Classify data to know how to protect it, like labeling boxes.