nerdexam
Isaca

CGEIT · Question #650

Senior management is concerned about the unauthorized use of third-party data that is stored within the enterprise's data repositories. Which of the following is the BEST way to address this concern?

The correct answer is C. Establish data ownership with clear accountabilities.. To address unauthorized use of third-party data, establishing clear data ownership and accountability is the best first step to define who is responsible for its protection and proper handling.

Submitted by khalil_dz· Apr 18, 2026Governance of Enterprise IT

Question

Senior management is concerned about the unauthorized use of third-party data that is stored within the enterprise's data repositories. Which of the following is the BEST way to address this concern?

Options

  • ACommunicate consequences for staff who misuse third-party data.
  • BEnsure all third-party data in transit is encrypted.
  • CEstablish data ownership with clear accountabilities.
  • DEstablish optimal retention periods for third-party data.

How the community answered

(45 responses)
  • A
    7% (3)
  • B
    22% (10)
  • C
    60% (27)
  • D
    11% (5)

Why each option

To address unauthorized use of third-party data, establishing clear data ownership and accountability is the best first step to define who is responsible for its protection and proper handling.

ACommunicate consequences for staff who misuse third-party data.

While communicating consequences is important for deterrence, it is a reactive measure and doesn't proactively prevent unauthorized access or use as effectively as clearly defined ownership and accountability.

BEnsure all third-party data in transit is encrypted.

Encrypting data in transit protects against interception during transfer, but it does not address unauthorized use *once the data is stored* or accessed within the enterprise's repositories.

CEstablish data ownership with clear accountabilities.Correct

Establishing clear data ownership with defined accountabilities is the best way to address concerns about unauthorized use because it assigns specific individuals or roles the responsibility for managing, protecting, and authorizing access to the data, thereby reducing the likelihood of misuse. This foundational step ensures someone is accountable for enforcing policies and controls.

DEstablish optimal retention periods for third-party data.

Establishing optimal retention periods addresses the duration of data storage, but it does not directly prevent unauthorized use during the period the data is legitimately retained.

Concept tested: Data governance and ownership

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security/data-classification-governance

Topics

#Data Governance#Data Ownership#Accountability#Information Security Management

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice