An IS auditor discovers that an organization has a data classification policy but has not assigned an owner to each information asset. Which of the following represents the GREATEST risk associated with this finding?
-
A
Inconsistent application of security controls across different systems.
-
B
Lack of accountability for ensuring information assets are appropriately protected.
-
C
Increased costs for data storage due to improper data handling.
-
D
Inability to classify new information assets as they are created.