Asset classification is the responsibility of the asset owner, as they have the best understanding of the asset’s value and sensitivity.
The auditor’s role is to identify gaps and guide the process, not to directly reclassify assets.
Why Not Other Options:
A: Immediate board notification is premature without thorough documentation and recommendations.
B: The auditor does not have the authority or detailed knowledge to classify assets.
C: Documenting the issue is part of the process but does not resolve the problem.
References:
EC-Council CISO Material: Asset Management and Classification Best Practices.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit