正解:B
Validating that assets are protected according to assigned classification is the primary role of the IS auditor in an organization's information classification process. An IS auditor should evaluate whether the information security controls are adequate and effective in safeguarding the information assets based on their classification levels. The other options are not the primary role of the IS auditor, but rather the responsibilities of the information owners, custodians, or security managers. References:
* CISA Review Manual (Digital Version), Chapter 6, Section 6.2.31
* CISA Review Questions, Answers & Explanations Database, Question ID 206