medium
Single Answer
0Sakis is determining which controls from the baseline should be applied to a given system or software package. How should he decide?
Answer Options
A
Consult the custodians of the data.
B
Select based on the data classification of the data it stores or handles.
C
Apply the same controls to all systems.
D
Consult the business owner of the process the system or data supports.
Correct Answer: B
Explanation
The controls implemented from a security baseline should match the data classification of the data used or stored on the system. Custodians are trusted to ensure the day-to-day security of the data and should do so by ensuring that the baseline is met and maintained. Business owners often have a conflict of interest between functionality and data security, and applying the same controls everywhere is expensive and may not meet business needs.