CCSP - Cloud Data Security - Section 2.5

Plan and implement data classification.

Data classification policies, mapping classification to sensitivity and to protective controls, and labelling that survives movement between services.

data classification policysensitivity levelsdata labellingdata owner and data custodian

Practice question for this objective

Free sampleCloud Data Securitymedium

An organisation is writing its data classification policy for data stored across several cloud services. Which element is most essential for the policy to be enforceable in practice?

  • AA published list of approved cloud providers that have completed a SOC 2 Type II examination
  • BA fixed schedule of encryption key rotation intervals for every storage bucket in use
  • CA record of each provider's data centre locations to satisfy residency obligations
  • DClearly defined sensitivity levels with criteria for assigning them and the handling rules each level requires Correct
Identify defined sensitivity levels, assignment criteria, and handling rules as the enforceable core of a data classification policy. A classification policy becomes enforceable only when it states the sensitivity levels, gives objective criteria for assigning each level, and specifies the handling controls each level demands; these let people and tools act consistently, whereas provider assurance or key schedules are supporting controls, not the policy's defining content.

Why A is wrong: Provider assurance supports vendor risk management, but it does not tell staff how to classify or handle data; a candidate may reach for a familiar audit report instead of the policy's own content.

Why B is wrong: Key rotation is an operational control that may follow from a classification, but it is not what makes the classification policy enforceable; it addresses cryptography, not the criteria for assigning sensitivity.

Why C is wrong: Residency mapping matters for compliance, yet it does not define sensitivity levels or handling rules; it is a downstream concern that a policy relies on rather than the defining element of classification.

Why D is correct: Without defined levels, assignment criteria, and per-level handling requirements, staff cannot classify consistently or know how to protect data, so these elements are the enforceable core of the policy.

See more CCSP practice questions, answers explained.

More in this domain

Back to all Cloud Data Security objectives, or the CCSP cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.