ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityEasy
A financial services organization is reviewing its data handling practices for customer Personally Identifiable Information (PII). According to best practices and regulatory compliance, which role is ultimately accountable for determining the classification level and protection requirements for this PII?
- AChief Information Security Officer (CISO)
- BData Owner
- CData Processor
- DData Custodian
Show answer & explanationAnswer & explanation
Correct answer: B. Data Owner
The Data Owner is the individual or entity ultimately responsible for the data, including its classification, protection, and compliance with regulations. While others play crucial roles, the ultimate accountability rests with the owner.
Why the other options are wrong
- A. The CISO is responsible for the overall security program but not the ultimate owner of specific data sets.
- C. Data Processors handle data on behalf of the Data Owner but are not accountable for its classification.
- D. Data Custodians are responsible for the safe keeping, transport, storage, and processing of data.
Data Owner
The individual or entity with ultimate responsibility for the data, including its accuracy, integrity, and protection.
- Responsible for data classification.
- Determines protection requirements.
- Accountable for compliance.
Memory trick: Owners Own the Outcome, Custodians Carry the Cargo, Users Utilize the info.