Isaca Certified Information Systems Auditor CISA Question # 359 Topic 36 Discussion
CISA Exam Topic 36 Question 359 Discussion:
Question #: 359
Topic #: 36
Which of the following is the BEST way to ensure an organization ' s data classification policies are preserved during the process of data transformation?
A.
Map data classification controls to data sets.
B.
Control access to extract, transform, and load (ETL) tools.
C.
Conduct a data discovery exercise across all business applications.
D.
Implement classification labels in metadata during data creation.
Data classification is the process of tagging data according to its type, sensitivity, and value to the organization. Data transformation is the process of changing the structure and format of data to make it usable for analysis and visualization. Both processes are important for data security and compliance, but they also pose some challenges.
One of the challenges is to ensure that the organization’s data classification policies are preserved during the process of data transformation. This means that the data should retain its original classification level and labels after it is transformed, and that the appropriate controls and protections are applied to the transformed data.
The best way to ensure this is to implement classification labels in metadata during data creation (D). Metadata is data that describes other data, such as its source, format, content, and context. By adding classification labels to metadata, the data can be easily identified and tracked throughout its lifecycle, including during data transformation. The labels can also help enforce the proper access rights and encryption standards for the data, regardless of its state or location.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit