nerdexam
(ISC)2

CISSP · Question #864

Which of the following roles has the obligation to ensure that a third party provider is capable of processing and handling data in a secure manner and meeting the standards set by the organization?

The correct answer is B. Data Owner. The role that has the obligation to ensure that a third party provider is capable of processing and handling data in a secure manner and meeting the standards set by the organization is the data owner. A data owner is a person or an entity that has the authority or the…

Submitted by valeria.br· Mar 5, 2026Asset Security

Question

Which of the following roles has the obligation to ensure that a third party provider is capable of processing and handling data in a secure manner and meeting the standards set by the organization?

Options

  • AData Custodian
  • BData Owner
  • CData Creator
  • DData User

How the community answered

(60 responses)
  • A
    2% (1)
  • B
    88% (53)
  • C
    3% (2)
  • D
    7% (4)

Explanation

The role that has the obligation to ensure that a third party provider is capable of processing and handling data in a secure manner and meeting the standards set by the organization is the data owner. A data owner is a person or an entity that has the authority or the responsibility for the data or the information within an organization, and that determines or defines the classification, the usage, the protection, or the retention of the data or the information. A data owner has the obligation to ensure that a third party provider is capable of processing and handling data in a secure manner and meeting the standards set by the organization, as the data owner is ultimately accountable or liable for the security or the quality of the data or the information, regardless of who processes or handles the data or the information. A data owner can ensure that a third party provider is capable of processing and handling data in a secure manner and meeting the standards set by the organization, by performing the tasks or the functions such as conducting due diligence, establishing service level agreements, defining security requirements, monitoring performance, or auditing compliance.

Topics

#data owner#data governance#third-party risk management#data responsibility

Community Discussion

No community discussion yet for this question.

Full CISSP Practice