Systems Security Certified Practitioner – SSCP – Question0328

Which of the following would be the best criterion to consider in determining the classification of an information asset?

A.
Value
B. Age
C. Useful life
D. Personal association

Correct Answer: A

Explanation:

Information classification should be based on the value of the information to the organization and its sensitivity (reflection of how much damage would accrue due to disclosure).
Age is incorrect. While age might be a consideration in some cases, the guiding principles should be value and sensitivity.
Useful life. While useful lifetime is relevant to how long data protections should be applied, the classification is based on information value and sensitivity.
Personal association is incorrect. Information classification decisions should be based on value of the information and its sensitiviry.
References CBK, pp. 101 -102.