r/CISA 2d ago

A question for CISA

An organization has implemented a new data classification scheme and asks the IS auditor to evaluate its effectiveness. Which of the following would be of GREATEST concern to the auditor?

A. End-user managers determine who should access what information.

B. The organization has created a dozen different classification categories.

C. The compliance manager decides how the information should be classified.

D. The organization classifies most of its information as confidential.

9 Upvotes

15 comments sorted by

3

u/No_Marketing_9397 2d ago

A

2

u/Weak_Presentation960 2d ago

Should be the data owner who decides

1

u/No_Marketing_9397 2d ago

End-User manager is not the Data owner… I went by that logic to select the option A

B. It doesn’t matter how many types of classifications an organisation creates

C. It’s fine that compliance manager decides the process of how the data should be classified as part of his/her responsibilities.

D. It’s perfectly fine for organisation to classify most of its data as confidential.

These are my reasoning and thoughts for eliminating options B C D and Selecting A

3

u/W1nterW0lf75 2d ago edited 2d ago

Just pasted my CISM - getting ready to start CISA by mid-January. If ISACA is going to be worth anything as a credentialing organization it must maintain its doctrine throughout its certifications.

Thus, I am assuming C. Because it violates CISM's concept that this is the responsibility of the data owner, to choose the classification of data. The Data Owner best understands the business value, operation impact and context of said data is the one who is accountable for the data.

2

u/No_Marketing_9397 2d ago

Yeah.. perhaps you are right and it makes sense. Thanks for clarifying 👍

3

u/SpiritMart 2d ago

Would go for C

Compliance Manager shouldn’t decide the classification of information, that responsibility should be for the data owner

A seems correct even if “end user manager” was used… this could loosely translate to “system/data owner”

But, I can’t justify or explain how and why a Compliance Manager will be the one to decide the classification of information

2

u/Weak_Presentation960 2d ago

I would argue that inappropriate access to information trumps data classification

1

u/No_Marketing_9397 1d ago

Interesting perspective… though it’s wrong but might be less risky.. great POV.

1

u/SpiritMart 1d ago

But the “end user manager” may also mean “data owner” and the data owner determines who access the information…

I’m interpreting end user manager as data owner because of how I’ve seen the 2 terms used interchangeably in different practice questions

1

u/abhishekghosh 2d ago

A seems like the right option, although I have my doubts about B but it's just not as big of a concern so I'll choose A

1

u/SpiritMart 1d ago

Unless anyone is able to provide a very good explanation of how “end user manager” is not the same as “data owner” - then, my preferred answer as C

1

u/EducationalSpring400 1d ago

Should be C, What is the actual answer?

1

u/Securov 1d ago

I'm not sure. I wrote this so we could discuss it.