Certified Information Systems Auditor (CISA) — Question 1252
What is the FIRST step when creating a data classification program?
Answer options
- A. Develop a policy.
- B. Develop data process maps.
- C. Categorize and prioritize data.
- D. Categorize information by owner.
Correct answer: A
Explanation
The first step in creating a data classification program is to develop a policy, as it sets the framework and guidelines for the entire program. Without a policy, subsequent steps like developing process maps or categorizing data would lack direction and purpose. The other options are important actions but come after the establishment of a clear policy.