CISM - Information Security Program - Section 3.2

Identify and classify information assets to determine appropriate protection requirements.

Build and maintain an asset inventory, then apply a data classification scheme to categorise information assets by sensitivity and business value. Use classification outcomes to determine the level of protection required and the appropriate controls for each asset category.

Asset inventoryData classificationInformation assetData sensitivity

Practice question for this objective

Free sampleInformation Security Programeasy

During a data classification review, a dispute arises over what protection level a customer database should carry. Who is the most appropriate party to decide the classification level of that information asset?

  • AThe database administrator, because they configure the technical access controls and backups for the system
  • BThe information security manager, because they author the security policy and the classification scheme
  • CThe business data owner, because they understand the value of the information and accountability rests with them Correct
  • DThe internal audit team, because they independently assess whether controls match the assigned classification
The accountable business data owner, not the custodian or security function, decides an information asset's classification level. Classification reflects business value, which the data owner is accountable for and best understands, whereas custodians, the security function, and audit support, enforce, or review the decision rather than make it.

Why A is wrong: Tempting because the administrator handles the asset day to day, but that is a custodian role responsible for safeguarding data, not for judging its business value.

Why B is wrong: Tempting because the security manager defines the scheme, but they facilitate classification rather than decide the sensitivity of data they do not own.

Why C is correct: Correct because the data owner is accountable for the asset, understands its business worth, and is therefore best placed to assign and approve its classification.

Why D is wrong: Tempting because audit checks the outcome, but its independence would be compromised if it set the classification it later reviews.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Program objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.