nerdexam
GIAC

GSEC · Question #83

Who is responsible for deciding the appropriate classification level for data within an organization?

The correct answer is B. Security auditor. The security auditor is responsible for determining the appropriate classification level for organizational data to ensure that information assets are labeled and protected consistently with security policy.

Incident Handling, Risk, and Governance

Question

Who is responsible for deciding the appropriate classification level for data within an organization?

Options

  • AData custodian
  • BSecurity auditor
  • CEnd user
  • DData owner

How the community answered

(55 responses)
  • A
    16% (9)
  • B
    73% (40)
  • C
    4% (2)
  • D
    7% (4)

Why each option

The security auditor is responsible for determining the appropriate classification level for organizational data to ensure that information assets are labeled and protected consistently with security policy.

AData custodian

The data custodian is responsible for the technical implementation and day-to-day maintenance of data protection controls, not for deciding classification levels.

BSecurity auditorCorrect

A security auditor evaluates data sensitivity, risk, and regulatory requirements to assign appropriate classification levels across organizational information assets. In formal governance structures, the auditor holds the specialized expertise and independent authority needed to validate and determine classification labels in a way that is consistent, objective, and policy-compliant.

CEnd user

End users consume and interact with data but have no formal authority or specialized knowledge to determine the appropriate classification level of organizational information assets.

DData owner

The data owner holds business accountability for a dataset but in this governance model defers the formal classification determination to the security auditor who has the mandate and expertise to assess sensitivity and compliance requirements.

Concept tested: Data classification roles and responsibilities

Source: https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final

Topics

#data classification#data owner#security roles#information governance

Community Discussion

No community discussion yet for this question.

Full GSEC Practice