CISM - Information Security Program (33% of the exam) - Section 3.2

Identify and classify information assets to determine appropriate protection requirements.

Build and maintain an asset inventory, then apply a data classification scheme to categorise information assets by sensitivity and business value. Use classification outcomes to determine the level of protection required and the appropriate controls for each asset category.

Asset inventoryData classificationInformation assetData sensitivity

Practice question for this objective

Free sampleInformation Security Programeasy

During a data classification review, a dispute arises over what protection level a customer database should carry. Who is the most appropriate party to decide the classification level of that information asset?

  • AThe database administrator, because they configure the technical access controls and backups for the system
  • BThe information security manager, because they author the security policy and the classification scheme
  • CThe business data owner, because they understand the value of the information and accountability rests with them Correct
  • DThe internal audit team, because they independently assess whether controls match the assigned classification
The accountable business data owner, not the custodian or security function, decides an information asset's classification level. Classification reflects business value, which the data owner is accountable for and best understands, whereas custodians, the security function, and audit support, enforce, or review the decision rather than make it.

Why A is wrong: Tempting because the administrator handles the asset day to day, but that is a custodian role responsible for safeguarding data, not for judging its business value.

Why B is wrong: Tempting because the security manager defines the scheme, but they facilitate classification rather than decide the sensitivity of data they do not own.

Why C is correct: Correct because the data owner is accountable for the asset, understands its business worth, and is therefore best placed to assign and approve its classification.

Why D is wrong: Tempting because audit checks the outcome, but its independence would be compromised if it set the classification it later reviews.

See more CISM practice questions, answers explained.

Exam traps in Information Security Program

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • It guarantees that the organisation will pass any future regulatory audit without further remediation work

    Why it is wrong: Tempting because classification supports compliance, but no single control guarantees an audit pass, and the absolute claim overstates what classification alone achieves.

  • It guarantees that the organisation will pass any future regulatory audit covering the handling of personal and financial data

    Why it is wrong: Classification supports compliance but cannot guarantee an audit outcome; the absolute promise overstates the benefit and is not the core management rationale.

  • Purchasing a data loss prevention tool so that classified data can be blocked automatically at the network boundary

    Why it is wrong: Tempting because tooling supports enforcement, but buying technology before assets are inventoried and classified means the controls have nothing accurate to enforce against.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.