Question 1 of 30
An enterprise is developing its storage security framework, aiming to align with ISO/IEC 27040:2015. They have decided to implement a tiered storage approach, categorizing data based on its sensitivity and regulatory compliance requirements. Highly sensitive customer financial records will reside on a highly secured, encrypted storage tier with strict access controls, while less critical internal operational logs will be placed on a more accessible, less protected tier. What is the fundamental security principle guiding this data segregation strategy within the context of ISO/IEC 27040:2015?
Applying security controls commensurate with the risk and value of the data asset.
Ensuring all data is subject to the highest level of encryption regardless of classification.
Prioritizing storage availability over data confidentiality for all data types.
Implementing a single, uniform security policy across all storage media.

Preparing for ISO/IEC 27040:2015 - Storage Security Foundation? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free