Soru

Zorluk: OrtaData Governance, Classification, and Privacy Controls

During an internal compliance audit of an online education organization, a security manager discovers that the database administration (DBA) team currently defines data sensitivity levels, determines retention schedules, and approves external data-sharing requests for student records. The DBAs also manage database backups, patch management, and access control list (ACL) configurations. Which of the following recommendations should the security manager make to properly align data governance responsibilities?

  1. Reassign data classification authority, retention policy rules, and access approval decisions to the executive business unit leader as the Data Owner, while keeping the database administration team as Data Custodians for technical controls.Cevap
  2. B
    Formally designate the database administration team as the Data Owner because their direct management of server storage gives them final authority over data handling decisions.
  3. C
    Transfer both classification decision-making and technical database maintenance duties exclusively to the Data Protection Officer to centralize governance and operational execution.
  4. D
    Reclassify data access authorization requests as a physical security control so that access provisioning can be handled directly by IT helpdesk personnel without business oversight.

Cevap

Reassign data classification authority, retention policy rules, and access approval decisions to the executive business unit leader as the Data Owner, while keeping the database administration team as Data Custodians for technical controls.
The correct option properly separates business accountability from technical implementation. The Data Owner is typically a business executive or department head who understands the business value of the information and is responsible for defining classification levels, establishing retention guidelines, and granting access authorization. The Data Custodian (in this case, the database administration team) is responsible for implementing the technical safeguards, managing backups, configuring database encryption, and applying system updates in accordance with directives from the Data Owner.

Adım Adım Çözüm

1
Analyze the operational roles currently held by the database administration team
Identified that DBAs are performing both business accountability functions (classification, retention policies, access approval) and technical execution duties (backups, patching, ACL implementation).
Governance frameworks require clear separation between business ownership and technical implementation.
2
Differentiate between Data Owner and Data Custodian roles
The Data Owner (business lead) holds ultimate decision-making authority for data classification, policy requirements, and access rights. The Data Custodian (DBAs/IT staff) implements technical controls to safeguard data according to those policies.
Segregation of duties ensures operational personnel do not set policies for data they maintain.
3
Select the proper remediation strategy
Reassign data ownership responsibilities to the business unit leader while retaining DBAs in their technical custodian role.
This aligns governance practices with standard security framework expectations.

Anahtar Kavram

Data Owner vs. Data Custodian Responsibilities
Tahmini Süre:1m 30s
Bu soruyu puanla