According to the CISM Review Manual (Digital Version), Chapter 3, Section 3.2.1, Information owners are responsible for developing an information classification framework based on business needs1. They are also responsible for defining and maintaining the classification scheme, policies, and procedures for their information assets1.
The CISM Review Manual (Digital Version) also states that information owners should collaborate with other stakeholders, such as information security managers, information security steering committees, senior management, and legal counsel, to ensure that the classification framework is aligned with the organization’s objectives and complies with applicable laws and regulations1.
The CISM Exam Content Outline also covers the topic of information classification frameworks in Domain 3 — Information Security Program Development and Management (27% exam weight)2. The subtopics include:
3.2.1 Information Classification Frameworks
3.2.2 Information Classification Policies
3.2.3 Information Classification Procedures
3.2.4 Information Classification Training
I hope this answer helps you prepare for your CISM exam. Good luck! ????