nerdexam
Isaca

CRISC · Question #400

Who should be accountable for authorizing information system access to internal users?

The correct answer is D. Information owner. The information owner should be accountable for authorizing information system access to internal users because they are ultimately responsible for the data's classification, protection, and who can legitimately access it.

Submitted by lukas.cz· Apr 18, 2026Governance

Question

Who should be accountable for authorizing information system access to internal users?

Options

  • AInformation security officer
  • BInformation security manager
  • CInformation custodian
  • DInformation owner

How the community answered

(41 responses)
  • A
    2% (1)
  • C
    2% (1)
  • D
    95% (39)

Why each option

The information owner should be accountable for authorizing information system access to internal users because they are ultimately responsible for the data's classification, protection, and who can legitimately access it.

AInformation security officer

An Information Security Officer is responsible for developing and implementing security policies and advising on security, not typically for day-to-day access authorization decisions.

BInformation security manager

An Information Security Manager manages the security program and team but does not typically have the business context to authorize access for specific data, which belongs to the owner.

CInformation custodian

An Information Custodian is responsible for the technical protection and maintenance of the information system (e.g., IT department), not for deciding who should access the data contained within.

DInformation ownerCorrect

The information owner, also known as the data owner, is the person or entity ultimately responsible for the specific data or information system. They have the ultimate authority and accountability for determining its value, classifying it, and deciding who should have access, based on business need and organizational policy. This ensures that access is granted by someone who understands the data's criticality and purpose.

Concept tested: Information owner responsibilities

Source: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr-information-security-roles-and-responsibilities

Topics

#Information owner#Access authorization#Roles and responsibilities#Accountability

Community Discussion

No community discussion yet for this question.

Full CRISC Practice