nerdexam
(ISC)2

CGRC · Question #267

Which of the following is NOT a responsibility of a data owner? Response:

The correct answer is A. Maintaining and protecting data. The primary responsibility of a data owner is to determine the classification of data, establish security requirements, and authorize access, rather than the day-to-day operational tasks of maintaining and protecting the data. The latter tasks are typically delegated to data…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following is NOT a responsibility of a data owner? Response:

Options

  • AMaintaining and protecting data
  • BEnsuring that the necessary security controls are in place
  • CDelegating responsibility of the day-to-day maintenance of the data protection mechanisms to the
  • DApproving access requests

How the community answered

(31 responses)
  • A
    94% (29)
  • B
    3% (1)
  • D
    3% (1)

Why each option

The primary responsibility of a data owner is to determine the classification of data, establish security requirements, and authorize access, rather than the day-to-day operational tasks of maintaining and protecting the data. The latter tasks are typically delegated to data custodians or system administrators.

AMaintaining and protecting dataCorrect

Maintaining and protecting data, especially the day-to-day operational tasks, is typically the responsibility of the data custodian or IT department, not the data owner. The data owner is responsible for policy, classification, and ultimate accountability for the data.

BEnsuring that the necessary security controls are in place

Data owners are responsible for ensuring that necessary security controls are defined and implemented for their data, as they are accountable for its protection.

CDelegating responsibility of the day-to-day maintenance of the data protection mechanisms to the

Data owners delegate the operational responsibility for data protection mechanisms to data custodians or system administrators, aligning with their role as accountable parties who set policy rather than perform daily tasks.

DApproving access requests

Approving access requests is a key responsibility of a data owner, as they have the authority to grant or deny access based on data sensitivity and organizational policy.

Concept tested: Roles and responsibilities - Data owner

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-16.pdf

Topics

#Data Owner#Roles and Responsibilities#Data Governance#Information Security Roles

Community Discussion

No community discussion yet for this question.

Full CGRC Practice