Certified Information Security Manager (CISM) — Question 394

Which of the following departments should be responsible for classifying customer relationship management (CRM) system data on a database server maintained by IT?

Answer options

Correct answer: A

Explanation

The Sales department is the most familiar with customer interactions and data, making them the best suited to classify CRM data accurately. While Information Security has a role in protecting data, they typically do not classify it, and Human Resources and IT are not directly involved with CRM-specific data classification.