CAS-002 · Question #623
Which of the following is the information owner responsible for?
The correct answer is B. Determining the proper classification levels for data within the system. The information owner is the business unit or individual responsible for classifying data based on its sensitivity and value to the organization.
Question
Which of the following is the information owner responsible for?
Options
- ADeveloping policies, standards, and baselines.
- BDetermining the proper classification levels for data within the system.
- CIntegrating security considerations into application and system purchasing decisions.
- DImplementing and evaluating security controls by validating the integrity of the data.
How the community answered
(24 responses)- A4% (1)
- B92% (22)
- C4% (1)
Why each option
The information owner is the business unit or individual responsible for classifying data based on its sensitivity and value to the organization.
Developing policies, standards, and baselines is the responsibility of senior management or the CISO, not the information owner.
The information owner (also called data owner) holds business responsibility for the data and is the authoritative party for determining its classification level - such as confidential, internal, or public. This classification then drives the security controls applied by custodians. No other role has the contextual business knowledge to make this determination.
Integrating security considerations into purchasing decisions falls under the security architect or CISO role, not the information owner.
Implementing and evaluating security controls is the responsibility of the data custodian or security administrator, not the information owner.
Concept tested: Information owner data classification responsibilities
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf
Topics
Community Discussion
No community discussion yet for this question.