Soru

Zorluk: OrtaData Governance, Classification, and Privacy Controls

A hospital network is formalizing its data governance framework to prepare for a multi-cloud Electronic Health Record (EHR) migration. To ensure proper separation of duties, leadership is defining governance roles for handling sensitive patient information. Which of the following responsibilities belong specifically to the data owner rather than the data custodian? (Select TWO.)

  1. Determining the data classification level and defining access control requirements based on regulatory requirementsCevap
  2. Approving data disclosure requests and authorizing baseline access permissions for organizational rolesCevap
  3. C
    Executing routine database backups, patch management, and applying technical encryption controls on storage volumes
  4. D
    Verifying user credentials and identity claims using multi-factor authentication tokens prior to session establishment

Cevap

The responsibilities specifically assigned to the data owner are determining data classification levels and defining access control requirements, as well as approving data disclosure requests and authorizing baseline access permissions.
The correct responses identify the core administrative responsibilities of a data owner: setting classification levels, defining access rules according to regulatory standards, and granting formal approvals for data disclosure and role access. Data owners are business leaders accountable for data security policies rather than technical implementation.

Adım Adım Çözüm

1
Analyze the core distinction between data owner and data custodian roles in security governance.
Identified that data owners hold ultimate administrative and business accountability for data assets, whereas data custodians carry out hands-on technical management and maintenance.
Separation of duties requires separating policy-defining authority (owner) from technical control execution (custodian).
2
Evaluate each option against data owner responsibilities.
Determining sensitivity classification levels, defining access requirements, and approving formal access disclosures are business decision-making functions belonging to the data owner.
Only business managers or executives acting as data owners have the authority to classify data and grant access approvals.
3
Distinguish data custodian tasks and general authentication controls from data owner duties.
Technical system tasks such as backups, patching, storage encryption, and identity verification belong to system administration, data custodians, or technical authentication systems.
Attributing routine technical operation or authentication handling to data owners confuses practical technical management with administrative governance ownership.

Anahtar Kavram

Data Owner vs. Data Custodian Responsibilities
Bu soruyu puanla