A data owner disputes the classification label on tables an intruder read — how do you settle the intrusion's grade?
answer
- the grade depends on another team's asset
- provisional, but keep moving
- sample the columns the records name
- accountable owner, not the loudest voice
- worst-case-always destroys the signal
basics
~20 sGrade on what the columns actually contain, not only on the label. Hold the conservative grade as explicitly provisional, sample the real values from the columns the query records name, escalate to whoever is accountable for the label rather than to whoever disputes it, and record the basis.
solid answer
~60 sRecognise what the dispute really is: your grade depends on an input owned by another team, and that input has a known error rate. Three moves. First, do not let the argument stall the clock — hold the higher grade as an explicitly provisional operating grade so preservation, staffing and containment keep moving, and label it as pending resolution rather than as settled. Second, replace opinion with evidence: the query records name the exact columns read, so sample those columns and judge the contents, which is a stronger basis than either party's view of the catalogue entry. Third, route the decision to the accountable owner in the data governance chain — the person who owns the label, not necessarily the engineer disputing it — and record what was decided, on what evidence, by whom and when, because the grade drives assessments someone will audit later. Afterwards, treat the dispute as a catalogue defect and fix the entry, plus agree a standing tiebreak so the next incident does not relitigate it.
go deeper
Know that the severity of a data intrusion depends on how the data was classified, and that the classification is owned by a data owner rather than by the security team.
Be able to explain how you would test a disputed label with evidence — the query records name the columns, so the columns can be sampled — rather than by arguing over the catalogue entry.
Show that you keep the incident moving on a provisional conservative grade, gather sampled evidence, and record the basis and the decider so the grade can be defended long after the incident closes.
Own the standing arrangement: a named accountable owner per dataset, a tiebreak authority for live disputes, grades that cite the label version used, and an argued position on why permanent worst-case grading is a bad policy.
## The dispute is a dependency problem, not a technical one Grading an intrusion by reach requires an input the security function does not own: the classification of the datasets that were reachable. That label lives in a data catalogue maintained by data owners, it is often set once at table creation and never revisited, and it is frequently wrong in both directions. So when a data owner says *that table is not regulated, your grade is inflated*, they may be right, they may be defending their own consequence, and either way the disagreement is happening while an incident is live and a grade is already driving spend. ## Do not let the dispute stop the clock The first failure mode is a live incident that pauses while two teams argue about a label. Prevent it by separating the **operating grade** from the **exposure conclusion**. The operating grade is yours: it sets preservation scope, staffing, containment urgency and who is awake. Hold it at the conservative value and mark it explicitly provisional-pending-classification, so nobody reads the number as a settled statement about disclosure. The exposure conclusion — whether obligations attach to what was read — is a legal assessment that runs on its own track and will want the same evidence you are gathering anyway. Keeping them apart means the dispute delays neither. ## Replace the argument with sampled evidence The strongest available move is to stop grading the label and start grading the contents. The query-audit records name the columns actually touched. Pull the schema for those columns and sample real values. A column named `CUSTOMER_REF` may hold an opaque surrogate key, in which case the owner is right; it may hold national identifiers, in which case the catalogue is wrong and the label was too low, not too high. Evidence beats both parties' recollection, it is defensible under later questioning, and it converts an argument about authority into a finding. Do this within the incident's own handling rules: you are sampling data that is already implicated, so keep the sample minimal, keep it inside the case handling, and record that it was taken for grading purposes. ## Route the decision to the accountable owner The person disputing the label is not always the person accountable for it. Data governance normally names an owner per dataset; that is the chain to escalate through, and the escalation should be short and specific — here are the columns, here is the sample, here is the label of record, we need a decision within the hour. If nobody is named as accountable, that absence is itself a finding worth more than this incident. What you must not do is let the grade be set by whoever is most available or most insistent. Record the decision as an artefact: the label version used, the evidence it rested on, who decided, and when. Six months later, when someone asks why the organisation did or did not treat this as a disclosure, that record is the answer, and its absence is the problem. ## Why 'always take the higher label' is not the policy The tempting rule is to grade every disputed table at its worst plausible classification. As a momentary default during an incident, that is right. As a standing policy, it corrodes the grading system: grades that are always maximal stop carrying information, teams learn to discount them, responders are burned on non-events, and assessments started on a wrong basis create their own cost and their own credibility problem. Conservative default plus a fast evidence-based resolution is the position that survives; permanent worst case is not. ## Fix the input, not just this incident The dispute is a signal that the catalogue is unreliable, and a catalogue whose accuracy is only ever tested during an intrusion will be wrong during the next one too. The durable outputs are: correct this entry; name an accountable owner for every dataset that has none; establish a tiebreak authority for label disputes during live incidents so the argument is pre-decided; require that an incident grade cite the label version it used; and sample high-label tables periodically rather than waiting for an incident to discover the drift. Those are organisational commitments with cost attached, which is why they belong to whoever owns the grading standard rather than to the analyst holding the case. ## What an interviewer is listening for That you keep the incident moving, that you reach for evidence rather than authority, that you know whose decision it actually is, that you write down the basis, and that you can say plainly why the easy rule — always assume the worst — is a bad standing policy even though it is the right default at 03:00.
- Why not simply take the higher classification whenever a label is disputed?As a momentary default during a live incident it is correct. As a standing policy it destroys the grade's information content: teams discount every grade, responders are burned on non-events, and external assessments started on a wrong basis carry their own cost and credibility damage. Conservative default plus fast evidence-based resolution is the durable position.
- The owner turns out to be right and the label was over-strict. What happens to the grade?Downgrade on the positive evidence — the sampled columns, the schema — and record the basis, the evidence and who decided. Then correct the catalogue entry, because the same wrong label will otherwise inflate the next incident too, and tell the people who were mobilised on the higher grade why it moved.
- What do you change afterwards so this dispute does not recur?Name an accountable owner for every dataset that lacks one, establish a tiebreak authority for label disputes during live incidents, require incident grades to cite the label version used, and sample high-label tables periodically so drift is found outside an intrusion rather than during one.
saying these in an interview costs you the question
- Pauses the incident until the label dispute is resolved
- Grades on the catalogue label without ever looking at the columns
- Lets whoever is most insistent in the channel set the classification
- Adopts permanent worst-case grading as the standing policy
- Changes the grade without recording the evidence or the decider