ExamGecko
Question list
Search
Search

Question 43 - CISM discussion

Report
Export

Who is BEST suited to determine how the information in a database should be classified?

A.
Database analyst
Answers
A.
Database analyst
B.
Database administrator (DBA)
Answers
B.
Database administrator (DBA)
C.
Information security analyst
Answers
C.
Information security analyst
D.
Data owner
Answers
D.
Data owner
Suggested answer: D

Explanation:

= Data owner is the best suited to determine how the information in a database should be classified, because data owner is the person who has the authority and responsibility for the data and its protection. Data owner is accountable for the business value, quality, integrity, and security of the data. Data owner also defines the data classification criteria and levels based on the data sensitivity, criticality, and regulatory requirements. Data owner assigns the data custodian and grants the data access rights to the data users. Data owner reviews and approves the data classification policies and procedures, and ensures the compliance with them.

Reference= CISM Review Manual, 16th Edition, Chapter 1: Information Security Governance, Section: Data Classification, page 331

asked 01/10/2024
Patrick Herrington
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first