CRISC · Question #400
Who should be accountable for authorizing information system access to internal users?
The correct answer is D. Information owner. The information owner should be accountable for authorizing information system access to internal users because they are ultimately responsible for the data's classification, protection, and who can legitimately access it.
Question
Who should be accountable for authorizing information system access to internal users?
Options
- AInformation security officer
- BInformation security manager
- CInformation custodian
- DInformation owner
How the community answered
(41 responses)- A2% (1)
- C2% (1)
- D95% (39)
Why each option
The information owner should be accountable for authorizing information system access to internal users because they are ultimately responsible for the data's classification, protection, and who can legitimately access it.
An Information Security Officer is responsible for developing and implementing security policies and advising on security, not typically for day-to-day access authorization decisions.
An Information Security Manager manages the security program and team but does not typically have the business context to authorize access for specific data, which belongs to the owner.
An Information Custodian is responsible for the technical protection and maintenance of the information system (e.g., IT department), not for deciding who should access the data contained within.
The information owner, also known as the data owner, is the person or entity ultimately responsible for the specific data or information system. They have the ultimate authority and accountability for determining its value, classifying it, and deciding who should have access, based on business need and organizational policy. This ensures that access is granted by someone who understands the data's criticality and purpose.
Concept tested: Information owner responsibilities
Source: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr-information-security-roles-and-responsibilities
Topics
Community Discussion
No community discussion yet for this question.