🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control32 / 150
Question 32 of 150
A financial services firm is rolling out a new data protection program. The security team wants to apply encryption, access restrictions, and retention rules across all repositories. However, they find that data across shared drives, databases, and cloud storage is treated uniformly, making it unclear which datasets warrant the strongest safeguards. What should the risk practitioner recommend the organization establish FIRST to guide the assignment of protection controls?
Reviewed for accuracy · Report an issueNext question