An enterprise software company is updating its data governance program following an internal compliance assessment. A senior database administrator has been tasked with configuring database permissions, executing automated daily backups, and applying technical data loss prevention tags. The product management team requests that a key customer telemetry dataset be reclassified from Restricted to Confidential to enable easier integration with an external analytics vendor. Which of the following best describes the correct operational procedure for handling this request?
- The business data owner must evaluate and approve the reclassification request, while the database administrator acts as the data custodian responsible for technical enforcement.Cevap
- BThe database administrator should reclassify the dataset independently, as technical personnel managing data infrastructure maintain final authority over classification tags.
- CThe database administrator must require single sign-on authentication for the vendor, which automatically grants authorization to downgrade dataset sensitivity labels.
- DThe database administrator should deploy a compensating deterrent control, such as a non-disclosure agreement, to eliminate the need for data classification governance.
Cevap
The business data owner must evaluate and approve the reclassification request, while the database administrator acts as the data custodian responsible for technical enforcement.
In enterprise data governance, the business data owner holds ultimate accountability for defining data classification rules and approving access rights. The database administrator functions as the data custodian, responsible for applying technical safeguards, managing access controls, and maintaining backups under the direction of the data owner.
Adım Adım Çözüm
Anahtar Kavram
Data Owner vs. Data Custodian Responsibilities