A hospital network is formalizing its data governance framework to prepare for a multi-cloud Electronic Health Record (EHR) migration. To ensure proper separation of duties, leadership is defining governance roles for handling sensitive patient information. Which of the following responsibilities belong specifically to the data owner rather than the data custodian? (Select TWO.)
- Determining the data classification level and defining access control requirements based on regulatory requirementsCevap
- Approving data disclosure requests and authorizing baseline access permissions for organizational rolesCevap
- CExecuting routine database backups, patch management, and applying technical encryption controls on storage volumes
- DVerifying user credentials and identity claims using multi-factor authentication tokens prior to session establishment
Cevap
The responsibilities specifically assigned to the data owner are determining data classification levels and defining access control requirements, as well as approving data disclosure requests and authorizing baseline access permissions.
The correct responses identify the core administrative responsibilities of a data owner: setting classification levels, defining access rules according to regulatory standards, and granting formal approvals for data disclosure and role access. Data owners are business leaders accountable for data security policies rather than technical implementation.
Adım Adım Çözüm
Anahtar Kavram
Data Owner vs. Data Custodian Responsibilities