A regional bank is rolling out a new four-tier data classification scheme. The CISO has approved the policy, but business unit managers are pushing back on the operational burden of marking every document. As the security manager leading the rollout, what should you do FIRST to ensure marking and labelling requirements take hold across the bank?
- AEngage data owners to confirm classification criteria and define handling and labelling procedures tied to each tier Correct
- BDeploy an automated classification and labelling tool across all endpoints to enforce marking technically
- CIssue a memo from the CISO requiring all staff to label documents within thirty days or face disciplinary action
- DSchedule mandatory awareness training so every employee understands the new classification tiers
Why A is correct: Asset handling and labelling derive from classification, which is the data owner's accountability. Confirming criteria and procedures with the owners produces an enforceable, business-aligned standard before any tool, audit, or training is layered on top.
Why B is wrong: Automated tooling is valuable later, but deploying it before data owners have agreed on classification criteria and labelling conventions produces inconsistent or wrong labels at scale. Technical enforcement of an unresolved policy disagreement is a classic over-technical CISSP trap.
Why C is wrong: An enforcement memo without agreed criteria or procedures produces inconsistent labels and resentment, and it bypasses the data owner's accountability for classification. Sanctions belong at the end of the rollout, not the start.
Why D is wrong: Training is necessary but premature: staff cannot be trained on procedures that have not yet been defined with data owners. Training delivered against draft criteria has to be repeated, which damages credibility of the programme.