ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityEasy

A financial institution is implementing a new data classification scheme. The Chief Information Security Officer (CISO) is defining the roles and responsibilities for managing the lifecycle of sensitive customer data. Which role is ultimately accountable for determining the classification level of specific datasets and authorizing access to them?

  1. AData Custodian
  2. BSystem Owner
  3. CData Steward
  4. DData Owner
Show answer & explanation

Correct answer: D. Data Owner

The Data Owner is the individual or entity ultimately accountable for the protection of specific data, including its classification and access authorization. They define the data's value and sensitivity.

Why the other options are wrong

  • A. The Data Custodian is responsible for the technical implementation and maintenance of data protection controls, but not the classification itself.
  • B. The System Owner is responsible for the system hosting the data, not the data's classification or access rules.
  • C. The Data Steward focuses on data quality, integrity, and compliance with policies, acting on behalf of the Data Owner.

Data Owner

An individual or entity with ultimate accountability for the protection, classification, and authorized use of specific data assets.

  • Ultimately accountable for data lifecycle
  • Determines classification and access permissions
  • Often a business unit manager or executive

Memory trick: Owners Own, Custodians Care, Stewards Steer, Systems Secure.

More Asset Security questions