Domain 2: Understanding Data Roles Flashcards

1
Q

Who has the primary responsibility of protecting the data and assets?

A

Data Owner/Information Owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Who is the person who has ultimate organizational responsibility for data?

A

Data Owner/Information Owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Who is typically the chief executive officer (CEO), president, or a department head?

A

Data Owner/Information Owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Who identifies the classification of data?

A

Data Owner/Information Owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Who ensures the data is labeled properly?

A

Data Owner/Information Owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who insures that the data has adequate security controls based on the classification and the organization’s security policy requirements?

A

Data Owner/Information Owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who may be liable for negligence if they fail to perform due diligence in establishing and enforcing security policies to protect and sustain sensitive data?

A

Data Owner/Information Owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Establishes the rules for appropriate use and protection of the subject data/information (rules of behavior)

A

Data Owner/Information Owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Provides input to information system owners regarding the security requirements and security controls for the information system(s) where the information resides.

A

Data Owner/Information Owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Decides who has access to the information system and what types of privileges or access rights.

A

Data Owner/Information Owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Assists in the identification and assessment of the common security controls where the information resides.

A

Data Owner/Information Owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Persons and organizations responsible for the collection and use of data.

A

Data Controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Determines the purposes for which and the means by which personal data is processed.

A

Data Controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

The entity that determines the “how” and the “why” of personal data collection and use.

A

Data Controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Outsourcing data to other organizations.

A

Data Processors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

A natural or legal person, public authority, agency, or other body, which processes personal data solely on behalf of the data controller.

A

Data Processor

17
Q

An employer that collects personal information on employees for payroll

A

Data Controller

18
Q

An employer collects personal information on employees for payroll who passes the payroll information to a third-party company to process the payroll. What is the third-party known as?

A

Data Processor

19
Q

Helps protect the integrity and security of data by ensuring that is is properly stored and protected.

A

Data Custodian

20
Q

Ensures that data is properly stored and protected.

A

Data Custodian

21
Q

Ensures that the data is backed up by following guidelines in the backup policy.

A

Data Custodian

22
Q

Personnel within an IT department or system security administrators.

A

Data Custodians

23
Q

Responsible for assigning permissions to data.

A

Data Custodian

24
Q

Usually a member of senior management. Can delegate some day-to-day duties. Cannot delegate total responsbility.

A

Data Owner

25
Q

Usually someone in the IT department. DOES NOT DECIDE what controls are needed, but does implement controls for the data owner.

A

Data Custodian

26
Q

Responsible for granting appropriate access to personnel (often via RBAC).

A

Data Administrators

27
Q

Any person who accesses data via a computing system to accomplish work tasks.

28
Q

Can overlap with the responsibilities of the system owner or be the same role.

A

Business/Mission Owners

29
Q

Owns asset or system that processes sensitive data and associated security plans.

A

Asset Owners

30
Q

The person or entity that controls processing of data.

A

Data Controller