ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityMedium
A research institution collects and processes genetic data for scientific studies. This data is highly sensitive and requires stringent protection. According to best practices, who is ultimately accountable for determining the classification level of this genetic data and approving its access requirements?
- AThe legal and compliance department
- BThe data owner (e.g., lead researcher or department head)
- CThe system owner of the research database
- DThe Chief Information Security Officer (CISO)
Show answer & explanationAnswer & explanation
Correct answer: B. The data owner (e.g., lead researcher or department head)
The data owner is ultimately accountable for classifying data and approving access. While the CISO advises on security, the system owner manages the system, and legal advises on compliance, it is the data owner (often a business or research head) who understands the data's value, sensitivity, and regulatory implications from a business perspective, making them responsible for its classification and access decisions.
Why the other options are wrong
- A. The legal department advises on compliance and legal requirements, but does not typically classify data or approve access directly.
- C. The system owner is responsible for the system that hosts the data, not the data itself or its classification.
- D. The CISO is responsible for the overall security program and advises on security, but not the ultimate owner of specific data sets.
Data Owner
The individual or entity with ultimate responsibility for the protection, integrity, and usage of specific data assets, making decisions on classification and access.
- Accountable for data's lifecycle, not just its technical aspects.
- Often a business unit head who understands the data's value.
- Works with data custodians and other stakeholders to implement controls.
Memory trick: Owner knows data's worth, Custodian protects its birth.