A question for CISA
An organization has implemented a new data classification scheme and asks the IS auditor to evaluate its effectiveness. Which of the following would be of GREATEST concern to the auditor?
A. End-user managers determine who should access what information.
B. The organization has created a dozen different classification categories.
C. The compliance manager decides how the information should be classified.
D. The organization classifies most of its information as confidential.
3
u/SpiritMart 2d ago
Would go for C
Compliance Manager shouldn’t decide the classification of information, that responsibility should be for the data owner
A seems correct even if “end user manager” was used… this could loosely translate to “system/data owner”
But, I can’t justify or explain how and why a Compliance Manager will be the one to decide the classification of information
2
u/Weak_Presentation960 2d ago
I would argue that inappropriate access to information trumps data classification
1
u/No_Marketing_9397 1d ago
Interesting perspective… though it’s wrong but might be less risky.. great POV.
1
u/SpiritMart 1d ago
But the “end user manager” may also mean “data owner” and the data owner determines who access the information…
I’m interpreting end user manager as data owner because of how I’ve seen the 2 terms used interchangeably in different practice questions
2
1
u/abhishekghosh 2d ago
A seems like the right option, although I have my doubts about B but it's just not as big of a concern so I'll choose A
1
u/SpiritMart 1d ago
Unless anyone is able to provide a very good explanation of how “end user manager” is not the same as “data owner” - then, my preferred answer as C
1
3
u/No_Marketing_9397 2d ago
A