Question

Difficulty: HardData Governance, Classification, and Privacy Controls

A regional hospital network is deploying an automated Data Loss Prevention (DLP) system across its Electronic Health Record (EHR) databases. The database administration team has configured technical access controls, automated encrypted backups, and database audit logs. However, during a compliance audit, the team discovers that data sensitivity levels and user authorization baselines for custom health datasets were never formally defined or authorized. Which of the following responsibilities must be assigned to the Data Owner to resolve this compliance deficiency?

  1. Determining the data classification tier and approving business access authorization baselines for the dataset.Answer
  2. B
    Implementing technical access control lists (ACLs) and database encryption at rest based on established security requirements.
  3. C
    Performing routine data backups and verifying system recovery procedures according to retention schedules.
  4. D
    Configuring network-level firewalls and identity provider authentication protocols for database ingress traffic.

Answer

Determining the data classification tier and approving business access authorization baselines for the dataset.
The Data Owner is a senior manager or executive accountable for the specific information asset. The Data Owner is responsible for determining data sensitivity classifications, establishing rules for data handling, and approving access authorization baselines. In this scenario, defining missing data sensitivity levels and authorizing access policies is the exclusive governance responsibility of the Data Owner.

Step-by-Step Solution

1
Analyze the operational duties described in the scenario.
Identified technical tasks already completed (configuring access controls, running backups, audit logging) vs missing governance tasks (defining classification tiers, approving business access baselines).
CompTIA Security+ distinguishes between governance accountability (Data Owner) and technical implementation (Data Custodian).
2
Evaluate the specific role requirements of the Data Owner.
The Data Owner is the business executive or manager accountable for determining data classification, defining security requirements, and authorizing access permissions.
Technical custodians execute controls, but business owners hold accountability for dataset policy and classification.
3
Select the option that represents governance and classification authority.
Determining classification tiers and approving business access baselines aligns directly with Data Owner responsibilities.
This resolves the identified audit finding by establishing proper data governance authority.

Key Concept

Data Governance Roles: Data Owner vs. Data Custodian
Rate this question