Courseiva
hardMultiple Choice

Data Classification Criteria: Legal, Regulatory & Business Impact

A security architect is designing a data classification schema for a multinational corporation. Which combination of factors is MOST critical for determining the classification level of a data asset?

Quick Answer

The answer is legal, regulatory, and business impact if disclosed, as these three factors form the core of any defensible data classification criteria. This is correct because classification levels are fundamentally about the potential harm to the organization—specifically the confidentiality, integrity, and availability risks—if the data is compromised. Without assessing legal mandates like GDPR or HIPAA, regulatory frameworks such as PCI DSS, and the direct business impact of a breach, any classification scheme lacks a risk-based foundation and becomes arbitrary. On the CISA exam, this concept tests your understanding that classification must align with organizational risk tolerance and compliance obligations, not just technical attributes like data type or volume. A common trap is focusing on data sensitivity alone, but the exam emphasizes that impact drives the level. Remember the mnemonic "LRB" for Legal, Regulatory, and Business impact—the three pillars that determine how strictly a data asset must be protected.

⚠ Common exam trap

ISACA often tests the misconception that technical attributes (like encryption or storage location) determine classification, when in reality classification is a business-driven risk decision based on the impact of disclosure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Legal, regulatory, and business impact if disclosed.

The classification level of a data asset is primarily determined by the potential harm that could result from its unauthorized disclosure, modification, or loss. Legal, regulatory, and business impact factors—such as compliance with GDPR, HIPAA, or PCI DSS—directly dictate the required confidentiality, integrity, and availability controls. Without assessing these impacts, any classification scheme would be arbitrary and fail to align with organizational risk tolerance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data volume and storage location.

    Why it's wrong here

    Volume and storage location describe scale and hosting, not the sensitivity, regulatory obligations or business impact that actually determine classification. These factors suit capacity planning or data-residency decisions, whereas classification hinges on content sensitivity, legal requirements and the harm arising from disclosure.

  • ✗

    Data format and encryption status.

    Why it's wrong here

    Format and encryption status describe how data is stored or protected, not the impact of its disclosure, so they cannot assign a classification level. They are tempting because encryption often accompanies handling requirements, and would be relevant when selecting protective controls after classification, not when determining it.

  • ✗

    Data creation date and last access time.

    Why it's wrong here

    Creation and access timestamps describe data lifecycle, not sensitivity, so they cannot set a classification level. They are tempting because retention and access-review processes rely on such metadata, which would suit lifecycle or audit scheduling decisions rather than determining how confidential an asset is.

  • ✓

    Legal, regulatory, and business impact if disclosed.

    Why this is correct

    Classification hinges on the harm arising from unauthorised disclosure, so legal, regulatory and business impact together set the level. These factors determine required handling controls, whereas storage format or owner preference does not drive the classification decision.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO are primary criteria for classifying information assets within an organization? (Choose two.)

easy
  • A.The format of the data (structured vs. unstructured)
  • B.The age of the data
  • ✓ C.Business impact if the data is lost or disclosed
  • D.Physical storage location of the data
  • ✓ E.Legal and regulatory requirements

Why C: Option C is correct because the primary purpose of information asset classification is to determine the harm that loss, disclosure, alteration, or unavailability would cause to the organization, so business impact drives the assigned classification level (e.g., Public, Internal, Confidential, Restricted). Option E is correct because legal and regulatory requirements—such as GDPR, HIPAA, PCI DSS, or SOX—mandate specific handling and protection levels, making compliance obligations a fundamental classification criterion. By contrast, option A (data format) affects storage and tooling choices but not the sensitivity-based classification itself, option B (data age) is not a standard classification driver since old data can still be highly sensitive, and option D (physical storage location) is a deployment or residency consideration rather than a primary classification criterion.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.