nerdexam
CompTIA

CAS-002 · Question #623

Which of the following is the information owner responsible for?

The correct answer is B. Determining the proper classification levels for data within the system. The information owner is the business unit or individual responsible for classifying data based on its sensitivity and value to the organization.

Enterprise Security

Question

Which of the following is the information owner responsible for?

Options

  • ADeveloping policies, standards, and baselines.
  • BDetermining the proper classification levels for data within the system.
  • CIntegrating security considerations into application and system purchasing decisions.
  • DImplementing and evaluating security controls by validating the integrity of the data.

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    92% (22)
  • C
    4% (1)

Why each option

The information owner is the business unit or individual responsible for classifying data based on its sensitivity and value to the organization.

ADeveloping policies, standards, and baselines.

Developing policies, standards, and baselines is the responsibility of senior management or the CISO, not the information owner.

BDetermining the proper classification levels for data within the system.Correct

The information owner (also called data owner) holds business responsibility for the data and is the authoritative party for determining its classification level - such as confidential, internal, or public. This classification then drives the security controls applied by custodians. No other role has the contextual business knowledge to make this determination.

CIntegrating security considerations into application and system purchasing decisions.

Integrating security considerations into purchasing decisions falls under the security architect or CISO role, not the information owner.

DImplementing and evaluating security controls by validating the integrity of the data.

Implementing and evaluating security controls is the responsibility of the data custodian or security administrator, not the information owner.

Concept tested: Information owner data classification responsibilities

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf

Topics

#data classification#information owner#security roles#data governance

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice