nerdexam
(ISC)2

CISSP · Question #564

Once the types of information have been identified, who should an information security practitioner work with to ensure that the information is properly categorized?

The correct answer is A. Information Owner (IO). Information categorization requires collaboration with the Information Owner, who has the authority and accountability to classify data based on its sensitivity and business value.

Submitted by deeparc· Mar 5, 2026Asset Security

Question

Once the types of information have been identified, who should an information security practitioner work with to ensure that the information is properly categorized?

Options

  • AInformation Owner (IO)
  • BSystem Administrator
  • CBusiness Continuity (BC) Manager
  • DChief Information Officer (CIO)

How the community answered

(30 responses)
  • A
    93% (28)
  • B
    3% (1)
  • C
    3% (1)

Why each option

Information categorization requires collaboration with the Information Owner, who has the authority and accountability to classify data based on its sensitivity and business value.

AInformation Owner (IO)Correct

The Information Owner (IO) is the individual responsible for the business function that relies on the data and holds the authority to formally classify and categorize it. Security practitioners work with IOs because they understand the data's sensitivity, regulatory requirements, and business impact, making them the authoritative source for proper categorization decisions.

BSystem Administrator

The System Administrator is responsible for implementing and maintaining technical controls on systems, not for determining the business value or sensitivity classification of the information itself.

CBusiness Continuity (BC) Manager

The Business Continuity Manager focuses on ensuring organizational resilience and recovery planning during disruptions, and is not the designated authority for data classification or categorization.

DChief Information Officer (CIO)

While the CIO provides strategic IT leadership and oversight, they delegate the specific responsibility of information categorization to the Information Owner who has direct accountability for the data.

Concept tested: Information ownership roles and data classification responsibility

Source: https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final

Topics

#Information owner#Data classification#Roles and responsibilities

Community Discussion

No community discussion yet for this question.

Full CISSP Practice