An organisation is writing its data classification policy for data stored across several cloud services. Which element is most essential for the policy to be enforceable in practice?
- AA published list of approved cloud providers that have completed a SOC 2 Type II examination
- BA fixed schedule of encryption key rotation intervals for every storage bucket in use
- CA record of each provider's data centre locations to satisfy residency obligations
- DClearly defined sensitivity levels with criteria for assigning them and the handling rules each level requires Correct
Why A is wrong: Provider assurance supports vendor risk management, but it does not tell staff how to classify or handle data; a candidate may reach for a familiar audit report instead of the policy's own content.
Why B is wrong: Key rotation is an operational control that may follow from a classification, but it is not what makes the classification policy enforceable; it addresses cryptography, not the criteria for assigning sensitivity.
Why C is wrong: Residency mapping matters for compliance, yet it does not define sensitivity levels or handling rules; it is a downstream concern that a policy relies on rather than the defining element of classification.
Why D is correct: Without defined levels, assignment criteria, and per-level handling requirements, staff cannot classify consistently or know how to protect data, so these elements are the enforceable core of the policy.