ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityEasy
A system administrator is configuring access controls for a critical financial application. The application processes highly sensitive customer transaction data. According to best practices in asset security, which role is ultimately responsible for defining the classification of this data and approving its access requirements?
- AData Owner
- BChief Information Officer (CIO)
- CData Custodian
- DSecurity Administrator
Show answer & explanationAnswer & explanation
Correct answer: A. Data Owner
The Data Owner is the individual or role with ultimate responsibility for the data, including its classification, protection, and use. They are typically a business unit manager or executive who understands the data's value to the organization.
Why the other options are wrong
- B. While the CIO has overall responsibility for information systems, the specific classification and access approval for particular data sets typically falls to the Data Owner.
- C. The Data Custodian implements and manages the controls, but does not define the classification.
- D. The Security Administrator implements security controls based on classifications defined by the Data Owner.
Data Owner
The individual or role, typically a senior business manager, who has ultimate responsibility for the data, including its classification, protection requirements, and ensuring its compliance with regulations.
- Accountable for data's value and risk.
- Defines data classification.
- Approves access and usage policies.
Memory trick: Owner rules, Custodian cares, User works, Administrator secures.