Which of the following MUST be considered when developing business rules for a data loss prevention (DLP) solution?
Correct Answer: B
A data loss prevention (DLP) solution is a system that monitors, detects, and prevents the unauthorized access, use, or transfer of sensitive data. A DLP solution relies on business rules to define what constitutes sensitive data and what actions are allowed or prohibited for the data. Therefore, one of the factors that must be considered when developing business rules for a DLP solution is data sensitivity. Data sensitivity is the degree to which the data is confidential, valuable, or critical to the organization or its stakeholders. Data sensitivity determines the level of protection and control that the data requires, and the potential impact or risk of data loss. Data availability, data ownership, and data integrity are also important factors for data security, but they are not specific to DLP solutions. References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 4:
Data Security, page 191; CISSP Official (ISC)2 Practice Tests, Third Edition, Domain 2: Asset Security, Question 2.15, page 80.