Courseiva
hardMultiple ChoiceObjective-mapped

Data Classification Criteria: Legal, Regulatory & Business Impact

A security architect is designing a data classification schema for a multinational corporation. Which combination of factors is MOST critical for determining the classification level of a data asset?

Quick Answer

The answer is legal, regulatory, and business impact if disclosed, as these three factors form the core of any defensible data classification criteria. This is correct because classification levels are fundamentally about the potential harm to the organization—specifically the confidentiality, integrity, and availability risks—if the data is compromised. Without assessing legal mandates like GDPR or HIPAA, regulatory frameworks such as PCI DSS, and the direct business impact of a breach, any classification scheme lacks a risk-based foundation and becomes arbitrary. On the CISA exam, this concept tests your understanding that classification must align with organizational risk tolerance and compliance obligations, not just technical attributes like data type or volume. A common trap is focusing on data sensitivity alone, but the exam emphasizes that impact drives the level. Remember the mnemonic "LRB" for Legal, Regulatory, and Business impact—the three pillars that determine how strictly a data asset must be protected.

⚠ Common exam trap

ISACA often tests the misconception that technical attributes (like encryption or storage location) determine classification, when in reality classification is a business-driven risk decision based on the impact of disclosure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Legal, regulatory, and business impact if disclosed.

The classification level of a data asset is primarily determined by the potential harm that could result from its unauthorized disclosure, modification, or loss. Legal, regulatory, and business impact factors—such as compliance with GDPR, HIPAA, or PCI DSS—directly dictate the required confidentiality, integrity, and availability controls. Without assessing these impacts, any classification scheme would be arbitrary and fail to align with organizational risk tolerance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data volume and storage location.

    Why it's wrong here

    Volume and location do not determine sensitivity.

  • Data format and encryption status.

    Why it's wrong here

    Format and encryption affect protection, not classification level.

  • Data creation date and last access time.

    Why it's wrong here

    Time factors are not classification criteria.

  • Legal, regulatory, and business impact if disclosed.

    Why this is correct

    These are the core factors in determining classification.

About these practice questions

Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO are primary criteria for classifying information assets within an organization? (Choose two.)

easy
  • A.The format of the data (structured vs. unstructured)
  • B.The age of the data
  • C.Business impact if the data is lost or disclosed
  • D.Physical storage location of the data
  • E.Legal and regulatory requirements

Why C: Business impact if the data is lost or disclosed (Option C) is a primary criterion because classification directly depends on the potential harm to the organization—confidentiality, integrity, and availability breaches drive the classification level (e.g., public, internal, confidential, restricted). Legal and regulatory requirements (Option E) are also primary because they mandate specific classification labels and handling controls (e.g., GDPR for PII, HIPAA for PHI, PCI DSS for cardholder data) that override internal business impact assessments. These two factors form the core of any information classification policy, as they dictate the protective measures required.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.