nerdexam
(ISC)2

CGRC · Question #357

An organizational official with statutory or operational authority for specified information and responsibility for establishing the controls for its generation, collection, processing…

The correct answer is C. Information Owner. This question asks for the title of an official responsible for specific information and its entire lifecycle, including establishing controls.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

An organizational official with statutory or operational authority for specified information and responsibility for establishing the controls for its generation, collection, processing, dissemination, and disposal is known as the:

Response:

Options

  • AInformation System Owner
  • BAuthorizing Official
  • CInformation Owner
  • DCommon Control Provider

How the community answered

(51 responses)
  • A
    2% (1)
  • B
    8% (4)
  • C
    86% (44)
  • D
    4% (2)

Why each option

This question asks for the title of an official responsible for specific information and its entire lifecycle, including establishing controls.

AInformation System Owner

An Information System Owner is responsible for the system that processes information, not necessarily the inherent value or specific lifecycle management of the information itself.

BAuthorizing Official

An Authorizing Official is responsible for making the risk-based decision to authorize an information system to operate, not for owning specific information.

CInformation OwnerCorrect

An Information Owner (also known as a Data Owner) is an organizational official with statutory or operational authority over specific information and holds the responsibility for establishing controls for its entire lifecycle. This includes guiding its generation, collection, processing, dissemination, and disposal to ensure its confidentiality, integrity, and availability. This role focuses on the data itself, determining its value and protection requirements.

DCommon Control Provider

A Common Control Provider is an entity that provides security controls that can be inherited by multiple systems, not an owner of specific information.

Concept tested: Information Owner role and responsibilities

Source: https://csrc.nist.gov/glossary/term/information_owner

Topics

#Information Owner#Roles and Responsibilities#Information Governance#Data Stewardship

Community Discussion

No community discussion yet for this question.

Full CGRC Practice