exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 322 discussion

Actual exam question from Isaca's CISM
Question #: 322
Topic #: 1
[All CISM Questions]

Which of the following departments should be responsible for classifying customer relationship management (CRM) system data on a database server maintained by IT?

  • A. Sales
  • B. Information security
  • C. Human resources (HR)
  • D. IT
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
acf4e9a
Highly Voted 1 year, 3 months ago
Selected Answer: A
Classification of data always done by data owner. In this case data in CRM system is certainly owned by sales function. IT function just supports the custodian role and should not be classifying the data so the most appropriate option is A sales department.
upvoted 5 times
...
afoo1314
Most Recent 9 months, 3 weeks ago
Selected Answer: A
Business owner. In this case, CRM own by sales.
upvoted 1 times
...
yottabyte
10 months, 1 week ago
A is the clear choice, Sales people will provide the customers so they provide the majority of input of their sales to be entered into the DB.
upvoted 1 times
...
oluchecpoint
11 months, 2 weeks ago
Selected Answer: A
Option A - Sales dept
upvoted 1 times
...
oluchecpoint
1 year, 4 months ago
B. Information security Information security teams are responsible for ensuring the confidentiality, integrity, and availability of data, especially sensitive data like customer information. They are well-equipped to define data classification standards and access controls to protect CRM data from unauthorized access or breaches. While other departments such as Sales or IT may have a role in using or maintaining the CRM system, the primary responsibility for data classification and security should rest with the Information Security department to ensure compliance with data protection regulations and best practices.
upvoted 1 times
oluchecpoint
11 months, 2 weeks ago
Option A - Sales dept
upvoted 1 times
...
Ejanla
11 months, 2 weeks ago
Really, your answer is wrong
upvoted 1 times
...
...
Agamennore
1 year, 4 months ago
Selected Answer: A
IMHO is A because is the process owner that know how to classificate the system/application
upvoted 2 times
...
Hugo1717
1 year, 4 months ago
Selected Answer: B
The correct answer is B. Information security. Explanation: The responsibility for classifying customer relationship management (CRM) system data on a database server maintained by IT should fall under the purview of the information security department. Here's why: B. Information security: Information security is responsible for ensuring the confidentiality, integrity, and availability of sensitive data, including customer data stored in CRM systems. Classifying data and determining appropriate access controls and security measures to protect that data is a core function of the information security department.
upvoted 2 times
...
AaronS1990
1 year, 4 months ago
Selected Answer: B
Well we can all agree the bloody sales department doesn't classify people's data. personal data is amongst the most sensitive data you can manage so this would fall to the IT Sec B
upvoted 2 times
SHERLOCKAWS
1 year ago
I agree with your answer as what you say is really what I've seen happening in practice. But for ISACA it would be sales as they are the business owner of the CRM. That's why for the exam I would support answer A.
upvoted 1 times
...
...
sham222
1 year, 6 months ago
Selected Answer: B
The keyword here is "classifying" which would imply the setting up of the data fields and marking them as HBI, MBI, LBI, etc. Sales just fills in the data as it's gathered...but the setting up of the CRM and linking the backend to it, and classifying all the data involved wouldn't be a function of the sales team.
upvoted 1 times
...
chanke
1 year, 7 months ago
Selected Answer: A
So typically Sales department is in control of the CRM (Customer Relation Manager) which is software used to track customer acquisition to move along with buying the product. Thinking along that they will typically hand it down to IT and information security but overall the Sales team would be the first line hence being the data owner. They will label the classifications and move them down the line.
upvoted 3 times
...
richck102
1 year, 7 months ago
Selected Answer: D
vote IT
upvoted 1 times
richck102
1 year, 7 months ago
funny question... if not B , C , D ....then A :)
upvoted 1 times
...
...
cheesesteak
1 year, 9 months ago
The responsibility for classifying customer relationship management (CRM) system data on a database server maintained by IT typically lies with the information security department. Answer B, "Information security", is the department that is typically responsible for overseeing and managing the classification and protection of data, including customer data, within an organization's IT systems. This includes determining the appropriate classification levels for data based on the organization's data classification policy, defining access controls and permissions, implementing encryption and other security measures, and monitoring and auditing data access and usage. While other departments such as Sales, HR, and IT may have input or involvement in the process, the information security department is typically responsible for ensuring that appropriate data classification practices are in place for CRM system data and other sensitive data within an organization.
upvoted 2 times
...
ccKane
1 year, 11 months ago
Why not IT? They are responsible of the DB and therefore that the classification is applied within the CRM?
upvoted 1 times
Rowlandmarc
1 year, 10 months ago
IT are not the business owners or deciders... in essence we supply the systems for our customers... Sales etc
upvoted 5 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...