CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingEasy

An organization has implemented a new data classification policy. All employees are required to classify data according to its sensitivity level (Public, Internal, Confidential, Restricted) before storing it in any system. This control is designed to ensure that appropriate security measures are applied based on the data's value. Which of the following control objectives is this policy primarily supporting?

  1. AAvailability
  2. BConfidentiality
  3. CIntegrity
  4. DNon-repudiation
Show answer & explanation

Correct answer: B. Confidentiality

Data classification directly supports confidentiality by ensuring that data is handled and protected according to its sensitivity, thus preventing unauthorized disclosure. While it can indirectly support other objectives, its primary focus here is preventing unauthorized access or disclosure.

Why the other options are wrong

  • A. Availability ensures that systems and data are accessible when needed.
  • C. Integrity ensures that data is accurate, complete, and uncorrupted.
  • D. Non-repudiation proves that a sender sent a message and a receiver received it.

Confidentiality

The control objective that ensures information is not disclosed to unauthorized individuals or systems.

  • A fundamental principle of information security (CIA triad).
  • Achieved through access controls, encryption, and data classification.
  • Aims to prevent unauthorized viewing or access of sensitive data.

Memory trick: Confidentiality: Keep secrets safe.

More Risk Response and Reporting questions