What is the First Step in a Data Classification Program?
What is the FIRST step when creating a data classification program?
Community Votes
71% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding of governance sequencing—policies set the rules and criteria before data can be properly categorized or mapped.
Establishing a formal data classification policy is the essential first step before identifying or labeling assets. Community consensus and ISACA guidelines confirm that governance frameworks must precede technical implementation.
Candidates often choose "Categorize and prioritize data" because it seems more actionable, but without a governing policy, categorization lacks standardized criteria and organizational authority.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
ISACA methodology mandates that governance foundations precede operational execution. Developing a formal policy establishes the program's objectives, scope, classification tiers, and accountability structure. Without these predefined rules, any subsequent categorization efforts lack consistency and executive mandate. The CISA Review Manual explicitly confirms that policy creation is the mandatory initial phase.Why the Other Options Are Wrong
Option B involves documenting workflows, which logically follows once classification criteria and ownership are defined in the policy. Option C and D assume that data owners and sensitivity levels are already known, but ISACA requires a governing framework to dictate how data should be categorized and who owns it. Attempting to map or label assets before establishing policy leads to inconsistent controls and audit failures.Community Comment Notes
Commenters [1] and [2] correctly cite the CISA Review Manual to reinforce that policy must precede classification activities. While comment [5] argues that inventorying data first seems practical, it overlooks the governance requirement that policies define the inventory standards. Consensus strongly favors Option A as the foundational step aligned with ISACA auditing standards.Official Reference
Exam Strategy
Always look for the governance or framework-establishing option first in CISA questions. If an option defines rules, roles, or scopes, it typically precedes execution steps like mapping, labeling, or categorizing.
Frequently Asked Questions
Why not categorize data before writing a policy?
Without a policy, categorization lacks standardized criteria, ownership definitions, and executive backing required by ISACA.
When do data process maps fit into the program?
Process maps are created after the policy and categorization phases to document how classified data flows through systems.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →