Which of the following is the PRIMARY security consideration for how an organization should handle Information Technology (IT) assets?
Correct Answer: D
The classification of the data on the asset is the primary security consideration for how an organization should handle Information Technology (IT) assets. An IT asset is any hardware, software, or data that is owned or used by the organization. The classification of the data on the asset indicates the level of sensitivity, confidentiality, and criticality of the data, and determines the appropriate security measures and controls to protect the asset. The classification of the data on the asset also guides the handling, storage, transmission, and disposal of the asset, as well as the access rights and responsibilities of the users. References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 2: Asset Security, page 50; [Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 2: Asset Security, page 112]