Question

Difficulty: MediumData Governance, Classification, and Privacy Controls

An enterprise organization is establishing its formal data governance framework to satisfy regulatory compliance requirements. Match each data governance role on the left with its primary operational responsibility on the right.

  • Data OwnerDetermines data classification levels, defines access permissions, and accepts overall business risk for the data asset.
  • Data CustodianConfigures database access control lists, performs scheduled backups, and implements technical encryption controls.
  • Data StewardEnsures data quality, maintains accurate metadata tagging, and handles day-to-day data domain governance.
  • Data Protection Officer (DPO)Monitors enterprise compliance with privacy laws, conducts impact assessments, and liaises with regulatory authorities.

Answer

Data Owner matches with determining data classification and defining access permissions; Data Custodian matches with configuring access control lists, performing backups, and implementing technical encryption; Data Steward matches with ensuring data quality, metadata tagging, and day-to-day domain governance; Data Protection Officer matches with monitoring privacy compliance, conducting impact assessments, and liaising with regulators.
Each role correctly aligns with its defined responsibility in enterprise governance: the Data Owner defines classification and access policy; the Data Custodian manages technical security implementation and backups; the Data Steward enforces data quality and metadata standards; and the Data Protection Officer oversees privacy compliance and regulatory relations.

Step-by-Step Solution

1
Differentiate governance accountability from operational execution.
Identify Data Owner as the business authority defining classification tiers and access rights, whereas Data Custodian executes technical security controls.
CompTIA Security+ distinguishes between executive accountability (owner) and technical operational maintenance (custodian).
2
Identify domain-level data quality and regulatory oversight responsibilities.
Map Data Steward to operational metadata and data quality maintenance, and Data Protection Officer to independent privacy law compliance and regulatory liaison duties.
Data Stewards focus on operational data integrity and classification accuracy, while DPOs oversee broad regulatory compliance and privacy impact assessments.

Key Concept

Data Governance Roles and Responsibilities
Rate this question