ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityMedium

An organization is developing a new data classification scheme. They need to ensure that the classification levels accurately reflect the potential impact of unauthorized disclosure, alteration, or destruction of the data. Which of the following is the MOST important objective of this data classification effort?

  1. ATo reduce the overall cost of data processing.
  2. BTo simplify data storage and backup procedures.
  3. CTo assign appropriate security controls based on data value.
  4. DTo meet legal and regulatory compliance requirements.
Show answer & explanation

Correct answer: C. To assign appropriate security controls based on data value.

The primary objective of data classification is to understand the value and sensitivity of data so that appropriate security controls can be assigned and implemented. This ensures that resources are allocated effectively to protect the most critical assets, directly addressing the 'potential impact' mentioned in the question. While compliance is a driver and cost is a factor, assigning appropriate controls is the direct outcome and purpose.

Why the other options are wrong

  • A. Reducing cost might be an indirect benefit, but security is the direct driver for classification.
  • B. Simplifying storage/backup is a secondary benefit, not the primary objective.
  • D. Meeting compliance is a goal, but classification is the mechanism to achieve it by defining controls.

Data Classification Objectives

The goals of categorizing data based on its sensitivity and value, primarily to ensure appropriate security controls are applied.

  • Aligns security controls with data risk.
  • Informs access control decisions.
  • Supports regulatory compliance.

Memory trick: Classify to Control, Value to Guard All.

More Asset Security questions