Which of the following are key considerations when implementing a data classification policy? (Choose THREE.)
Defining classification categories establishes the taxonomy itself—the labels such as public, internal, confidential and restricted—that every subsequent rule references. Without agreed categories, no consistent assignment, labelling or handling can occur, making this a foundational consideration for the policy.
Why this answer
Option B is correct because a data classification policy must first define the classification categories (e.g., Public, Internal, Confidential, Restricted) so that data can be consistently evaluated and tagged against a common taxonomy. Option D is correct because handling and labeling procedures specify how each class of data must be marked, stored, transmitted, and destroyed, translating the classification scheme into enforceable day-to-day controls. Option E is correct because assigning data owners establishes accountability for classifying data correctly, approving access, and reviewing classifications over time, which is essential for the policy to function.
Option A does not belong because encryption key management is a cryptographic control that supports protection of classified data but is not itself a defining consideration of the classification policy. Option C does not belong because backup frequency is a availability/recovery decision typically governed by backup and retention policies, not by the data classification scheme itself.
Exam trap
ISACA often tests the distinction between policy-level definitions (classification categories, data owners, handling procedures) and operational controls (encryption, backup frequency), leading candidates to mistakenly select technical safeguards as key policy considerations.