CRISC Certified in Risk and Information Systems Control – Question621

Which of the following is the FIRST step in managing the risk associated with the leakage of confidential data?

A.
Conduct an awareness program for data owners and users
B. Maintain and review the classified data inventory
C. Implement mandatory encryption on data
D. Define and implement a data classification policy

Correct Answer: A