Soru

Zorluk: ZorData Governance, Classification, and Privacy Controls

An enterprise security manager is defining an updated data governance and privacy enforcement framework to ensure compliance with global regulations. Match each data governance role or privacy mechanism on the left to its corresponding operational responsibility or functional objective on the right.

  • Data OwnerHolds ultimate business accountability for specifying data classification levels and defining access rules based on sensitivity.
  • Data CustodianImplements technical safeguards, manages encryption keys, configures access control lists, and performs database backups.
  • Data Protection Officer (DPO)Oversees organizational privacy compliance, evaluates Data Protection Impact Assessments (DPIAs), and acts as regulatory liaison.
  • Data ControllerDetermines the overall legal basis, scope, and business purpose for processing personal data belonging to data subjects.

Cevap

Data Owner pairs with defining classification and access requirements. Data Custodian pairs with implementing technical controls, key management, and backups. Data Protection Officer (DPO) pairs with privacy compliance oversight, DPIA evaluation, and supervisory liaison. Data Controller pairs with determining the purpose and legal basis for data processing.
The correct pairings accurately reflect standard governance frameworks. The Data Owner is accountable for data classification and policy setting. The Data Custodian implements technical protection mechanisms and manages daily system operations. The DPO provides regulatory oversight and leads privacy impact assessments. The Data Controller establishes the lawful purpose and parameters for personal data collection and processing.

Adım Adım Çözüm

1
Differentiate governance roles between operational execution, business accountability, legal entity status, and compliance oversight.
Identified that technical database administration tasks belong to the custodian, while policy determination belongs to the owner.
CompTIA Security+ requires clear separation of duties between technical implementation (custodian) and strategic business ownership (owner).
2
Map regulatory compliance and privacy oversight responsibilities.
Linked the Data Protection Officer (DPO) to DPIA reviews and independent regulatory communication.
Under privacy frameworks like GDPR, the DPO serves an advisory and monitoring function rather than executing technical maintenance.
3
Differentiate the Data Controller's legal role from internal data ownership.
Associated Data Controller with defining the legal basis and purpose for processing personal data.
The Data Controller establishes the processing objectives and compliance framework for personal data.

Anahtar Kavram

Data Governance Roles and Responsibilities
Bu soruyu puanla