nerdexam
CompTIA

CAS-001 · Question #458

Which of the following is the information owner responsible for?

The correct answer is B. Determining the proper classification levels for data within the system. The information owner (also called data owner) is a business role - typically a senior manager or executive - who is accountable for a specific data set or information asset. Their primary responsibility is determining the appropriate classification level for that data (e.g…

Enterprise Security

Question

Which of the following is the information owner responsible for?

Options

  • ADeveloping policies, standards, and baselines.
  • BDetermining the proper classification levels for data within the system.
  • CIntegrating security considerations into application and system purchasing decisions.
  • DImplementing and evaluating security controls by validating the integrity of the data.

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    89% (39)
  • C
    7% (3)
  • D
    2% (1)

Explanation

The information owner (also called data owner) is a business role - typically a senior manager or executive - who is accountable for a specific data set or information asset. Their primary responsibility is determining the appropriate classification level for that data (e.g., public, internal, confidential, top secret) and defining who should have access to it. This is correct answer B. The distractors represent responsibilities of other roles: Option A (developing policies, standards, and baselines) is the responsibility of the Chief Information Security Officer (CISO) or security management. Option C (integrating security into purchasing decisions) belongs to the security architect or procurement team. Option D (implementing and evaluating security controls) is the responsibility of the system/security administrator or the information custodian - not the owner. The information custodian handles day-to-day maintenance and protection of data on behalf of the owner.

Topics

#data classification#information ownership#security roles#data governance

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice