ある組織では、クラウド サービスによってホストされる Web アプリケーションを使用しています。このアプリケーションには、毎月電子メールでベンダーに送信されるデータが入力されます。アプリケーションに関連するリスクを分析する際に、最初に考慮すべき事項は次のうちどれですか。
正解:C
Data classification is the process of assigning labels or categories to data based on its sensitivity, value, and criticality to the organization. Data classification is the first consideration when analyzing the risk associated with the web application hosted by a cloud service, as it determines the level of protection and controls required for the data. Data classification can help the organization to comply with legal, regulatory, and contractual obligations, such as GDPR,CCPA, and PCI DSS, and to prevent data breaches, leaks, or losses.
Data classification can also help the organization to evaluate the suitability and trustworthiness of the cloud service provider, and to negotiate the terms and conditions of the service level agreement (SLA).
References:
*ISACA, Cloud Computing: Business Benefits With Security, Governance and Assurance Perspectives, 2009, p. 141
*ISACA, Data Classification: What It Is, Why You Should Care and How to Perform It2