🔥 3-day streak
ISACA CISA — Certified Information Systems Auditor39 / 148
Question 39 of 148

An organization is launching an enterprise data protection program. Management wants to ensure that encryption, access restrictions, and retention rules are applied proportionately across all information assets. Before selecting specific technical controls, which activity should the IS auditor recommend be completed FIRST?

Reviewed for accuracy · Report an issueNext question