Soru

Zorluk: Çok zorData Governance, Classification, and Privacy Controls

During an enterprise security audit following a corporate reorganization, a financial institution discovers that the database administration team has been independently creating access control lists and adjusting retention schedules for repositories containing customer financial records. When interviewed, the database administrators stated that because they manage the storage servers and backup scripts, they are responsible for determining who receives access and how long records are maintained. Which role should the organization enforce to ensure that business accountability for data classification and access authorization is properly separated from operational system maintenance?

  1. Data OwnerCevap
  2. B
    Data Custodian
  3. C
    Data Processor
  4. D
    System Administrator

Cevap

Data Owner
The correct role is the Data Owner. In enterprise data governance frameworks, the data owner is a high-level business manager or department head accountable for the specific data asset. The data owner determines data classification levels, defines access guidelines, enforces business retention rules, and authorizes user access. Operational staff like database administrators must take direction from the data owner rather than setting policy independently.

Adım Adım Çözüm

1
Analyze the operational issue described in the scenario.
Database administrators (technical operational personnel) are inappropriately making business governance decisions regarding data classification, access rights, and retention periods.
Technical staff maintaining infrastructure should not have sole authority over business risk decisions.
2
Differentiate between governance accountability and technical administration roles within CompTIA Security+ frameworks.
The Data Owner retains legal and business accountability for establishing data sensitivity labels, access rights, and lifecycle policies, whereas the Data Custodian implements those decisions technically.
Proper separation of duties requires delegating policy creation to business owners and technical execution to custodians.
3
Identify the target governance role needed to rectify the audited deficiency.
Assigning business authority to the Data Owner ensures that data access and retention decisions align with corporate governance and regulatory compliance.
Only the Data Owner has the organizational authority to determine who requires access based on business operations.

Anahtar Kavram

Data Role Separation of Duties (Data Owner vs. Data Custodian)
Tahmini Süre:1m 30s
Bu soruyu puanla