Which procedure is most appropriate for classifying organizational data?

Information Asset Classification
Answer Correct answer: C — Use results from business impact analyses (BIA) to classify data based on actual impact to the organization.

Which of the following is the MOST appropriate procedure for an organization to use when classifying data?

  1. Have the information security manager assign data classification levels.
  2. Review data classification questionnaires completed by data owners.
  3. Use results from business impact analyses to classify data. Correct Answer
  4. Publish data classification templates on the corporate intranet.

Community Votes

C
67%
B
33%

67% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests whether you know that data classification levels should reflect business impact, not subjective opinions or administrative templates.

CISA treats data classification as an impact-driven activity, so using business impact analysis results is the most defensible approach. This page explains why Option C is correct and why owner questionnaires are only supporting mechanisms.

Choosing Option B (reviewing questionnaires completed by data owners) because data owners know their data, when in fact BIA provides the objective basis needed for classification.

Community Discussion (4 comments)

PurpleParrot 👍 1 Selected: B
option B Option B: Reviewing data classification questionnaires completed by data owners is a crucial step, as data owners are typically the best source of information about the data they handle. This method allows for input from those who are familiar with the data’s sensitivity and usage. Option C: While BIA is primarily used for understanding business processes, its insights can inform data classification decisions by highlighting which data supports critical processes and has significant business impact. However, it's not the direct method for classifying data itself.
RS66 👍 1 Selected: C
C. Use results from business impact analyses to classify data.
Binagr8 👍 2
B. "Review data classification questionnaires completed by data owners" is the most appropriate procedure. Data owners, who are responsible for the data and understand its value and sensitivity, should be the ones to complete detailed questionnaires about the data. The information security team can then review these questionnaires and work with the data owners to determine the appropriate data classification levels. C. "Use results from business impact analyses to classify data" is not the most appropriate procedure for data classification. While business impact analyses can provide valuable insights, they may not capture the full context and nuances required for accurate data classification. Data classification should be a separate and more focused process that involves the data owners directly.
joehong 👍 1 Selected: C
C. Use results from business impact analyses to classify data.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option C is correct because a robust data classification program must define data sensitivity and criticality based on the harm the business would suffer if the data were disclosed, modified, or lost. Business impact analysis (BIA) quantifies those impacts for confidentiality, integrity, and availability, providing defensible and repeatable criteria for assigning classification levels. CISA doctrine holds that classifying data is not a purely administrative task; it is a risk-based determination best supported by BIA results.

Why the Other Options Are Wrong

Option A is wrong because the information security manager should not unilaterally assign classification levels to data owned by other business units; the data owner is ultimately responsible. Option B may be a useful input-collection tool, but reviewing questionnaires alone is subjective and does not map responses to impact thresholds the way a BIA does. Option D simply publishes templates; templates support communication and consistency but do not actually classify data based on impact.

Community Comment Notes

Some learners favored Option B, noting that "data owners are typically the best source of information about the data they handle." Others such as RS66 picked Option C, and joehong also sided with BIA. PurpleParrot conceded that "BIA is primarily used for understanding business processes" and that its insights can inform classification, which supports the exam's expected answer. The majority vote (67 for C) aligns with the official-key rationale.

Official Reference

Exam Strategy

For data classification questions, look for the option that ties classification levels to measured business impact. Rule out options that merely describe communication or input gathering, and remember the data owner sets the level, not the security manager.

Frequently Asked Questions

Why is Option B not the best choice when data owners know their data?

Owner questionnaires capture local knowledge, but they don't standardize the impact criteria needed for classification; BIA gives an objective, business-wide basis.

Does CISA require a BIA for every data-classification exercise?

No, but BIA is the preferred source of impact evidence because it quantifies confidentiality, integrity, and availability requirements for data.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide