正解:A
Whenclassifying information, it is most important to align the classification to business risk, because it ensures that the information is protected according to its value andimpact to the organization34. Business risk considers factors such as legal, regulatory, contractual, operational, reputational, and financial implications of information disclosure or compromise34. Aligning information classification to business risk also helps to prioritize and allocate resources for information security measures. Security policy, data retention requirements, and industry standards are important considerations for information classification, but not as important as business risk. References: 3: CISA Review Manual(Digital Version), Chapter 5, Section 5.4.2 4:
CISA Online Review Course, Module 5, Lesson 4