ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityMedium

A financial institution is implementing a new data classification scheme for its customer information. The scheme defines 'Confidential' data as information whose unauthorized disclosure would cause severe financial damage or legal penalties. Which of the following is the MOST appropriate next step after defining this classification level?

  1. AImplementing mandatory quarterly security awareness training for all employees.
  2. BPurchasing a new, more powerful firewall to protect the network perimeter.
  3. CConducting a comprehensive risk assessment of all IT systems.
  4. DAssigning data owners for all 'Confidential' data assets.
Show answer & explanation

Correct answer: D. Assigning data owners for all 'Confidential' data assets.

After defining data classification levels, assigning ownership is crucial. Data owners are responsible for making decisions about data protection and handling, ensuring that the classification scheme is practically applied and enforced. Without clear ownership, the classification remains theoretical.

Why the other options are wrong

  • A. While important, security awareness training is a general control and not the immediate, specific follow-up to defining classification levels.
  • B. A new firewall is a technical control that might be part of the solution, but it's not the direct next step after classification definition.
  • C. A risk assessment is a broader activity that informs security strategy, but assigning ownership is a more direct and immediate action after defining classification levels within a scheme.

Data Owner Responsibility

The individual or entity accountable for specific data assets, making decisions regarding their classification, protection, and usage throughout their lifecycle.

  • Responsible for data classification and access rights.
  • Ultimately accountable for the data's integrity, confidentiality, and availability.
  • Often a business unit head or senior manager.

Memory trick: Classify, then Owner, then Protect.

More Asset Security questions