Section 7.61 Data Ownership Flashcards

Objectives 14 Explain the importance of using appropriate cryptographic solutions. Objectives 3.3 Compare and contrast strategies to protect data. Objectives 4.2 Explain the security implications of proper hardware, software, and data asset management. Objectives 4.4 Explain security alerting, monitoring concepts and tools. Objectives 5.1 Summarise elements of effective security governance.

1
Q

Data Ownership

A

Process of identifying the individual responsible for maintaining the confidentiality, integrity, availability, and privacy of information assets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Data Owner

Data Owner

A

A senior executive responsible for labeling information assets and ensuring they
are protected with appropriate controls

Not the creator of the data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Data Controller

A

Entity responsible for determining data storage, collection, and usage purposes
and methods, as well as ensuring the legality of these processes

Holds ultimate accountability to any breeches of privacy and cannot delegate this responsibility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Data Processor

A

A group or individual hired by the data controller to assist with tasks like data
collection and processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Data Steward

A

Focuses on data quality and metadata, ensuring data is appropriately labeled and
classified, often working under the data owner

Ensure Data is appropriately classified

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Data Custodian

A

Responsible for managing the systems on which data assets are stored, including
enforcing access controls, encryption, and backup measures

Sytem administators

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Privacy Officer

A

Oversees privacy-related data, such as personally identifiable information (PII),
sensitive personal information (SPI), or protected health information (PHI),
ensuring compliance with legal and regulatory frameworks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Data Ownership Responsibility

A

The IT department (CIO or IT personnel) should NOT be the data owner: data owners should be individuals from the BUSINESS SIDE who understand the data’s
content and can make informed decisions about classification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Selection of Data Owners

A

Data owners should be designated within their respective departments based on their knowledge of the data and its significance within the organisation

Note: Proper data ownership is essential for maintaining data security, compliance, and effective data management within an organization. Different roles contribute to safeguarding and managing data appropriately

How well did you know this?
1
Not at all
2
3
4
5
Perfectly