Certified Information Systems Auditor (CISA) — Question 718
Which of the following would BEST help to support an auditor's conclusion about the effectiveness of an implemented data classification program?
Answer options
- A. Access rights provisioned according to scheme
- B. Detailed data classification scheme
- C. Purchase of information management tools
- D. Business use cases and scenarios
Correct answer: A
Explanation
Access rights provisioned according to the scheme provide clear evidence of how well the data classification program is being enforced, as it shows that access is aligned with the established classifications. The other options, while helpful, do not directly demonstrate the effectiveness of implementation in the same clear manner as access rights do.