ISC2 Certified in Cybersecurity (CC)Security OperationsEasy
A company is implementing a new policy for handling sensitive customer data. The policy states that data classified as 'Confidential' must be encrypted both in transit and at rest, and access must be restricted to authorized personnel only. This policy is primarily addressing which aspect of data handling?
- AData disposal
- BData labeling
- CData classification
- DData retention
Show answer & explanationAnswer & explanation
Correct answer: C. Data classification
The scenario describes assigning a sensitivity level ('Confidential') to data and then defining security controls based on that level, which is the core concept of data classification.
Why the other options are wrong
- A. Data disposal concerns the secure removal of data at the end of its lifecycle.
- B. Data labeling is a *part* of classification, but classification is the overarching process of assigning sensitivity and controls.
- D. Data retention defines how long data is kept, not its sensitivity or protection.
Data Classification
The process of categorizing data based on its sensitivity, value, and regulatory requirements to determine appropriate security controls and handling procedures.
- Assigns sensitivity levels (e.g., Public, Internal, Confidential, Secret)
- Guides security controls like encryption and access control
- Crucial for compliance and risk management
Memory trick: Classify, Protect, Retain, Dispose - the data's journey.