nerdexam
Isaca

CISM · Question #304

Which of the following roles should be PRIMARILY responsible for assigning sensitivity levels to an organization's information assets?

The correct answer is D. Data owner. Data owners are the individuals - typically senior managers or business unit leaders - who have ultimate accountability for specific information assets and are therefore responsible for defining how sensitive that data is and what protections it requires. A data custodian (C)…

Submitted by haru.x· Apr 18, 2026Information Security Governance

Question

Which of the following roles should be PRIMARILY responsible for assigning sensitivity levels to an organization's information assets?

Options

  • ARisk owner
  • BBusiness stakeholder
  • CData custodian
  • DData owner

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    4% (1)
  • D
    89% (24)

Explanation

Data owners are the individuals - typically senior managers or business unit leaders - who have ultimate accountability for specific information assets and are therefore responsible for defining how sensitive that data is and what protections it requires. A data custodian (C) implements and maintains the controls the data owner specifies, but does not set the classification itself. A business stakeholder (B) may have interest in the data but lacks the formal accountability to make classification decisions. A risk owner (A) is accountable for managing a particular risk, which is a separate governance concern from classifying the underlying assets. Memory tip: Think "owner = decision maker" - just as a property owner decides how to use their land, the data owner decides how sensitive the data is; the custodian just tends to it.

Topics

#Data owner#Roles and responsibilities#Information asset classification#Data sensitivity

Community Discussion

No community discussion yet for this question.

Full CISM Practice