A security team is developing a data classification policy. Which TWO of the following elements should be included in the policy to ensure effective data governance?
Specifies how data should be protected based on classification.
Why this answer
A data classification policy must define handling requirements for each classification level, specifying how data should be stored, transmitted, and accessed. This ensures consistent protection controls are applied based on sensitivity, which is a core governance principle. Without these requirements, data may be mishandled, leading to compliance violations or data breaches.
Exam trap
CompTIA often tests the distinction between policy elements (what the policy should contain) and derived controls (e.g., DLP rules, encryption algorithms), leading candidates to confuse operational implementation details with foundational policy components.