Which procedure is most appropriate for classifying organizational data?
Which of the following is the MOST appropriate procedure for an organization to use when classifying data?
Community Votes
67% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests whether you know that data classification levels should reflect business impact, not subjective opinions or administrative templates.
CISA treats data classification as an impact-driven activity, so using business impact analysis results is the most defensible approach. This page explains why Option C is correct and why owner questionnaires are only supporting mechanisms.
Choosing Option B (reviewing questionnaires completed by data owners) because data owners know their data, when in fact BIA provides the objective basis needed for classification.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option C is correct because a robust data classification program must define data sensitivity and criticality based on the harm the business would suffer if the data were disclosed, modified, or lost. Business impact analysis (BIA) quantifies those impacts for confidentiality, integrity, and availability, providing defensible and repeatable criteria for assigning classification levels. CISA doctrine holds that classifying data is not a purely administrative task; it is a risk-based determination best supported by BIA results.Why the Other Options Are Wrong
Option A is wrong because the information security manager should not unilaterally assign classification levels to data owned by other business units; the data owner is ultimately responsible. Option B may be a useful input-collection tool, but reviewing questionnaires alone is subjective and does not map responses to impact thresholds the way a BIA does. Option D simply publishes templates; templates support communication and consistency but do not actually classify data based on impact.Community Comment Notes
Some learners favored Option B, noting that "data owners are typically the best source of information about the data they handle." Others such as RS66 picked Option C, and joehong also sided with BIA. PurpleParrot conceded that "BIA is primarily used for understanding business processes" and that its insights can inform classification, which supports the exam's expected answer. The majority vote (67 for C) aligns with the official-key rationale.Official Reference
Exam Strategy
For data classification questions, look for the option that ties classification levels to measured business impact. Rule out options that merely describe communication or input gathering, and remember the data owner sets the level, not the security manager.
Frequently Asked Questions
Why is Option B not the best choice when data owners know their data?
Owner questionnaires capture local knowledge, but they don't standardize the impact criteria needed for classification; BIA gives an objective, business-wide basis.
Does CISA require a BIA for every data-classification exercise?
No, but BIA is the preferred source of impact evidence because it quantifies confidentiality, integrity, and availability requirements for data.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →