Who is ultimately responsible to ensure that information assets are categorized and adequate
measures are taken to protect them?

A.
Data Custodian
B.
Executive Management
C.
Chief Information Security Officer
D.
Data/Information/Business Owners
Answer should be “D”
Data Owners:
The data owner is the person who has ultimate organizational responsibility for data. The
owner is typically the CEO, president, or a department head (DH). Data owners identify
the classification of data and ensure that it is labeled properly. They also ensure it has
adequate security controls based on the classification and the organization’s security
policy requirements. Owners may be liable for negligence if they fail to perform due
diligence in establishing and enforcing security policies to protect and sustain sensitive
data
0
0