Question

Difficulty: MediumData Governance, Classification, and Privacy Controls

An enterprise software company is updating its data governance program following an internal compliance assessment. A senior database administrator has been tasked with configuring database permissions, executing automated daily backups, and applying technical data loss prevention tags. The product management team requests that a key customer telemetry dataset be reclassified from Restricted to Confidential to enable easier integration with an external analytics vendor. Which of the following best describes the correct operational procedure for handling this request?

  1. The business data owner must evaluate and approve the reclassification request, while the database administrator acts as the data custodian responsible for technical enforcement.Answer
  2. B
    The database administrator should reclassify the dataset independently, as technical personnel managing data infrastructure maintain final authority over classification tags.
  3. C
    The database administrator must require single sign-on authentication for the vendor, which automatically grants authorization to downgrade dataset sensitivity labels.
  4. D
    The database administrator should deploy a compensating deterrent control, such as a non-disclosure agreement, to eliminate the need for data classification governance.

Answer

The business data owner must evaluate and approve the reclassification request, while the database administrator acts as the data custodian responsible for technical enforcement.
In enterprise data governance, the business data owner holds ultimate accountability for defining data classification rules and approving access rights. The database administrator functions as the data custodian, responsible for applying technical safeguards, managing access controls, and maintaining backups under the direction of the data owner.

Step-by-Step Solution

1
Differentiate governance roles between data owner and data custodian.
Identified that the business department head or data owner holds policy authority, whereas technical staff (DBA) fulfill custodian duties.
Data governance frameworks require separation between business accountability and operational management.
2
Evaluate the request to modify data classification levels.
Determined that changing sensitivity from Restricted to Confidential requires formal approval from the data owner.
Reclassifying data affects risk exposure, compliance compliance, and access entitlement rules across the enterprise.
3
Assign technical implementation duties to the data custodian.
The database administrator implements the owner's decision by updating access control lists and enforcement policies.
Custodians execute security controls and maintain data structure based on established governance decisions.

Key Concept

Data Owner vs. Data Custodian Responsibilities
Rate this question