nerdexam
Isaca

CISM · Question #871

Who should give final approval for granting access rights to third parties?

The correct answer is D. Data owner. The data owner is the business-side individual (typically a senior manager or executive) who is accountable for a specific set of data and has the authority to determine who may access it. Granting third-party access is a business decision that carries legal, compliance, and…

Submitted by ashley.k· Apr 18, 2026Information Security Governance

Question

Who should give final approval for granting access rights to third parties?

Options

  • AInformation security manager
  • BData custodian
  • CContract manager
  • DData owner

How the community answered

(46 responses)
  • B
    2% (1)
  • C
    2% (1)
  • D
    96% (44)

Explanation

The data owner is the business-side individual (typically a senior manager or executive) who is accountable for a specific set of data and has the authority to determine who may access it. Granting third-party access is a business decision that carries legal, compliance, and risk implications-authority that rests with the data owner. The data custodian manages data technically but does not own it and cannot authorize access. The information security manager establishes policy frameworks. The contract manager handles the contractual relationship but does not hold accountability for the data itself.

Topics

#Data ownership#Roles and responsibilities#Third-party access#Information governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice