CAS-003 · Question #443
A security engineer is employed by a hospital that was recently purchased by a corporation. Throughout the acquisition process, all data on the virtualized file servers must be shared by departments…
The correct answer is C. which users will have access to which data. Data ownership is the principle that determines who has the authority to grant or restrict access to specific data sets. During an acquisition, establishing data ownership is critical to defining cross-organizational access controls.
Question
A security engineer is employed by a hospital that was recently purchased by a corporation. Throughout the acquisition process, all data on the virtualized file servers must be shared by departments within both organizations. The security engineer considers data ownership to determine:
Options
- Athe amount of data to be moved.
- Bthe frequency of data backups.
- Cwhich users will have access to which data
- Dwhen the file server will be decommissioned
How the community answered
(29 responses)- A7% (2)
- B3% (1)
- C90% (26)
Why each option
Data ownership is the principle that determines who has the authority to grant or restrict access to specific data sets. During an acquisition, establishing data ownership is critical to defining cross-organizational access controls.
The volume of data to be migrated is a logistical and technical decision made by storage administrators, not a function of data ownership.
Backup frequency is an operational and availability decision driven by RTO/RPO requirements, not by who owns the data.
Data ownership identifies the person or role responsible for a dataset and gives them authority to determine who may access it. In an acquisition scenario, clarifying ownership across both organizations is the prerequisite step before any access provisioning decisions can be made, ensuring that sensitive data is only shared with appropriately authorized users.
Decommissioning timelines are infrastructure and project management decisions typically made by IT leadership, independent of data ownership classification.
Concept tested: Data ownership and access control authorization
Source: https://csrc.nist.gov/glossary/term/data_owner
Topics
Community Discussion
No community discussion yet for this question.