Systems Security Certified Practitioner – SSCP – Question0112

Which of the following is the FIRST step in protecting data's confidentiality?

A.
Install a firewall
B. Implement encryption
C. Identify which information is sensitive
D. Review all user access rights

Correct Answer: C

Explanation:

In order to protect the confidentiality of the data. The following answers are incorrect because : Install a firewall is incorrect as this would come after the information has been identified for sensitivity levels. Implement encryption is also incorrect as this is one of the mechanisms to protect the data once it has been identified.
Review all user access rights is also incorrect as this is also a protection mechanism for the identified information. Reference : Shon Harris AIO v3 , Chapter-4 : Access Control , Page : 126