hardMultiple ChoiceObjective-mapped
Data Classification Criteria: Legal, Regulatory & Business Impact
A security architect is designing a data classification schema for a multinational corporation. Which combination of factors is MOST critical for determining the classification level of a data asset?
Quick Answer
The answer is legal, regulatory, and business impact if disclosed, as these three factors form the core of any defensible data classification criteria. This is correct because classification levels are fundamentally about the potential harm to the organization—specifically the confidentiality, integrity, and availability risks—if the data is compromised. Without assessing legal mandates like GDPR or HIPAA, regulatory frameworks such as PCI DSS, and the direct business impact of a breach, any classification scheme lacks a risk-based foundation and becomes arbitrary. On the CISA exam, this concept tests your understanding that classification must align with organizational risk tolerance and compliance obligations, not just technical attributes like data type or volume. A common trap is focusing on data sensitivity alone, but the exam emphasizes that impact drives the level. Remember the mnemonic "LRB" for Legal, Regulatory, and Business impact—the three pillars that determine how strictly a data asset must be protected.
⚠ Common exam trap
ISACA often tests the misconception that technical attributes (like encryption or storage location) determine classification, when in reality classification is a business-driven risk decision based on the impact of disclosure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Legal, regulatory, and business impact if disclosed.
The classification level of a data asset is primarily determined by the potential harm that could result from its unauthorized disclosure, modification, or loss. Legal, regulatory, and business impact factors—such as compliance with GDPR, HIPAA, or PCI DSS—directly dictate the required confidentiality, integrity, and availability controls. Without assessing these impacts, any classification scheme would be arbitrary and fail to align with organizational risk tolerance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data volume and storage location.
Why it's wrong here
Volume and location do not determine sensitivity.
- ✗
Data format and encryption status.
Why it's wrong here
Format and encryption affect protection, not classification level.
- ✗
Data creation date and last access time.
Why it's wrong here
Time factors are not classification criteria.
- ✓
Legal, regulatory, and business impact if disclosed.
Why this is correct
These are the core factors in determining classification.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO are primary criteria for classifying information assets within an organization? (Choose two.)
easy- A.The format of the data (structured vs. unstructured)
- B.The age of the data
- ✓ C.Business impact if the data is lost or disclosed
- D.Physical storage location of the data
- ✓ E.Legal and regulatory requirements
Why C: Business impact if the data is lost or disclosed (Option C) is a primary criterion because classification directly depends on the potential harm to the organization—confidentiality, integrity, and availability breaches drive the classification level (e.g., public, internal, confidential, restricted). Legal and regulatory requirements (Option E) are also primary because they mandate specific classification labels and handling controls (e.g., GDPR for PII, HIPAA for PHI, PCI DSS for cardholder data) that override internal business impact assessments. These two factors form the core of any information classification policy, as they dictate the protective measures required.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.