CISA Protection of Information Assets Practice Question
An IS auditor is examining how an organization classifies and handles its data. The auditor finds that the data classification policy defines four tiers but does not specify retention periods, handling procedures, or labeling requirements for each tier. Management states that employees use their judgment when handling sensitive information. Which of the following is the MOST appropriate recommendation?
⚠ Common exam trap
The trap here is recommending a technical enforcement tool such as DLP before the underlying policy defines what must be enforced.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require management to define retention periods, handling procedures, and labeling requirements for each classification tier.
A data classification policy is only effective when each tier carries explicit retention, handling, and labeling requirements. The organization's policy defines tiers but leaves their treatment to employee judgment, which produces inconsistent protection and no auditable standard. The auditor should recommend that management complete the policy by specifying these requirements per tier, creating the foundation for consistent handling and subsequent enforcement through technical controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement automated data loss prevention (DLP) tools to enforce handling rules across all endpoints.
Why it's wrong here
DLP tools enforce rules, but they require well-defined classification criteria to be configured effectively. Recommending technology before the policy defines retention, handling, and labeling requirements would automate an undefined process and likely produce excessive false positives. The root deficiency is the incomplete policy, so the auditor should first recommend that management define the required controls for each classification tier.
- ✗
Reduce the number of classification tiers to two to simplify employee decision-making.
Why it's wrong here
Reducing tiers may simplify usability, but it does not address the missing retention, handling, and labeling requirements. Fewer tiers with the same lack of defined controls would leave sensitive data equally unprotected. The audit finding concerns the absence of prescriptive requirements, not the granularity of the taxonomy, so collapsing the tiers misdiagnoses the problem and could weaken differentiation of sensitive data.
- ✓
Require management to define retention periods, handling procedures, and labeling requirements for each classification tier.
Why this is correct
The policy establishes tiers but omits the operational requirements that make classification meaningful. Without defined retention, handling, and labeling rules, employees cannot apply consistent protection, and reliance on individual judgment creates unacceptable variability. The auditor should recommend that management complete the policy by specifying these requirements for each tier, which provides a basis for later technical enforcement and monitoring.
- ✗
Conduct mandatory security awareness training so employees can better judge how to handle sensitive data.
Why it's wrong here
Training is valuable, but it cannot compensate for a policy that never defines what correct handling looks like. Asking employees to exercise judgment about retention and labeling of sensitive data invites inconsistency and potential regulatory violations. The primary deficiency is the incomplete policy framework, so training alone would leave the underlying control gap unresolved and would not provide auditable criteria.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.