CISSP Asset Security Practice Question
A multinational corporation is implementing a data classification program. The information security manager must ensure that data is handled appropriately based on its classification level. The company operates in multiple jurisdictions, including the European Union and the United States. Which two of the following are key considerations when developing the data classification policy? (Choose two.)
⚠ Common exam trap
The trap here is assuming that a one-size-fits-all classification scheme works globally, or that IT alone should classify data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defining clear criteria for each classification level based on data sensitivity and business impact
Aligning classification with legal requirements and defining clear criteria are essential for a multinational data classification policy. Legal alignment ensures compliance across jurisdictions, while clear criteria promote consistent application. Other options are flawed: overclassification is inefficient, delegating solely to IT ignores business ownership, and a rigid global scheme fails to address local legal nuances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delegating classification decisions solely to the IT department
Why it's wrong here
Data classification is a business responsibility, not solely IT. Data owners, who are typically business managers, are accountable for classifying data based on its value and sensitivity. IT provides tools and support, but delegating solely to IT can result in misclassification because IT may lack the business context. A collaborative approach involving data owners and IT is necessary.
- ✓
Defining clear criteria for each classification level based on data sensitivity and business impact
Why this is correct
Clear criteria ensure consistent application of classification levels across the organization. Without defined criteria, employees may classify data inconsistently, leading to either overprotection or underprotection. Criteria should consider factors such as confidentiality, integrity, availability, legal requirements, and business impact. This is essential for a successful data classification program.
- ✓
Aligning classification levels with legal and regulatory requirements in each jurisdiction
Why this is correct
Data classification must comply with laws such as GDPR in the EU and sector-specific regulations like HIPAA in the US. Different jurisdictions have varying requirements for data protection, breach notification, and cross-border transfers. Aligning classification levels with these legal frameworks ensures that data handling procedures meet legal obligations and avoids penalties. This is a fundamental consideration for a multinational corporation.
- ✗
Ensuring that all data is classified as 'Confidential' by default to maximize protection
Why it's wrong here
Classifying all data as 'Confidential' by default is impractical and can lead to overclassification, which increases costs and hampers business operations. It also dilutes the meaning of the classification, making it harder to identify truly sensitive data. A risk-based approach that assigns appropriate levels based on sensitivity and criticality is more effective and aligns with best practices.
- ✗
Implementing a single global classification scheme without considering local variations
Why it's wrong here
A single global scheme may not account for differing legal and cultural requirements across jurisdictions. For example, GDPR has specific definitions of personal data that may not align with other regions. While a global framework can provide consistency, it must be flexible enough to accommodate local variations. Ignoring local differences can lead to non-compliance and legal risks.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.