Data Classification and Asset Ownership
You protect data according to its value, so first you have to know its value. The exam tests that classification comes first and that the business owner, not IT, assigns it.
What this makes you able to do
Evaluate whether information assets are classified by sensitivity and owned, so that protection is proportionate to value.
By the end you can
- Explain why data classification precedes applying controls.
- Identify who assigns an asset's classification.
- Recognise the risk of uniform controls regardless of sensitivity.
Transcript
Data classification and asset ownership. This lesson is foundational: you cannot protect information appropriately until you know what it is worth.
The scene. Every file in the organisation is treated the same way. The public marketing brochure and the board’s confidential merger papers sit under identical controls, because we encrypt everything, so we’re covered. Nobody has said which data actually matters, and when you ask who decided the merger papers were confidential, the answer is that I-T set the permissions when the folder was created. Two things are wrong here.
Start with the principle: protect by value. Classification sorts information by sensitivity and value, typically into levels such as public, internal, confidential and restricted, so that the level of protection matches the level of risk. Highly sensitive data warrants strong protection; public data does not, and spending the same effort on it is waste.
Which is why classification comes first, before controls are chosen. It is the same identify-before-you-control principle that ran through compliance in Domain two and end-user computing in Domain four: you decide what matters, then protect accordingly.
And when a question asks the purpose of classification, the answer is to make protection proportionate: directing the strongest controls, and the tightest access, to the data whose loss would hurt most, while not burning the same effort on data that does not need it.
Now the second failure: I-T classified the merger papers. Classification is a judgement about business value and sensitivity, so it belongs to the data owner, the business role accountable for the asset. I-T can enforce controls, but it is not positioned to judge that the papers are confidential, or how confidential. That call is the owner’s.
So the two roles. The data owner is a business role: it assigns the classification and judges the asset’s value and sensitivity. The data custodian, usually I-T, protects the data to the level the owner has set, and holds and secures it. Owner decides; custodian protects.
Now, why does treating all data the same fail. First, cost, performance and user friction are wasted on public and low-value data.
And second, more damagingly, uniform treatment means the organisation is not making risk-based decisions about what genuinely needs protecting: the merger papers and the brochure are indistinguishable to the control set, so nothing is prioritised.
Which points at the trap. More protection is not always better. Applying maximum controls to everything wastes resources and abandons the risk-based prioritisation classification exists to provide. Good protection is proportionate.
And this whole lesson is an echo of the owner-versus-custodian split from Domain four, applied to protection: the business owns and decides the classification; I-T holds and secures the data to the level the owner sets.
So carry this away. Whether it is a spreadsheet, a brochure, or merger papers, protection follows value. Know the value first, set the classification from the business owner, not the custodian, and let the controls follow it.
1.What is the PRIMARY purpose of classifying data?
2.Who is responsible for assigning a classification to an information asset?
3.An organisation applies the same strong controls to every piece of data regardless of sensitivity. What is the MAIN problem?
Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.
Stay ahead of cyber threats
Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.
No spam. Unsubscribe at any time.
