Valid CISSP Dumps shared by EduDump.com for Helping Passing CISSP Exam! EduDump.com now offer the newest CISSP exam dumps, the EduDump.com CISSP exam questions have been updated and answers have been corrected get the newest EduDump.com CISSP dumps with Test Engine here:
You have been tasked to develop an effective information classification program. Which one of the following steps should be performed FIRST?
Correct Answer: D
Explanation/Reference: Explanation: The following outlines the first three necessary steps for a proper classification program: 1. Define classification levels. 2. Specify the criteria that will determine how data are classified. 3. Identify data owners who will be responsible for classifying data Steps 4-10 omitted. Incorrect Answers: A: Establishing procedures for periodically reviewing the classification and ownership is not one of the first steps in the classification program. It is one of the last steps (step 8 out of 10). B: Specifying the security controls required for each classification level is not one of the first steps in the classification program. It is step 5 out of 10. C: Identifying the responsible data custodian level is not one of the first steps in the classification program. It is step 4 out of 10. References: Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 114