exam questions

Exam CSSLP All Questions

View all questions & answers for the CSSLP exam

Exam CSSLP topic 1 question 78 discussion

Actual exam question from ISC's CSSLP
Question #: 78
Topic #: 1
[All CSSLP Questions]

Which of the following statements best describes the difference between the role of a data owner and the role of a data custodian?

  • A. The custodian makes the initial information classification assignments, and the operations manager implements the scheme.
  • B. The data owner implements the information classification scheme after the initial assignment by the custodian.
  • C. The custodian implements the information classification scheme after the initial assignment by the operations manager.
  • D. The data custodian implements the information classification scheme after the initial assignment by the data owner.
Show Suggested Answer Hide Answer
Suggested Answer: retention, and recovery of data. The data owner delegates these responsibilities to the custodian. Answer: B, A, and C are incorrect. These are not the valid 🗳️
The data owner is responsible for ensuring that the appropriate security controls are in place, for assigning the initial classification to the data to be protected, for approving access requests from other parts of the organization, and for periodically reviewing the data classifications and access rights. Data owners are primarily responsible for determining the data's sensitivity or classification levels, whereas the data custodian has the responsibility for backup, answers.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
74gjd_37
5 months, 2 weeks ago
Selected Answer: D
D. The data custodian implements the information classification scheme after the initial assignment by the data owner is the statement that best describes the difference between the role of a data owner and a data custodian. The data owner is responsible for classifying information based on its sensitivity, value, and criticality to an organization. Once this task is done, they define access rights and control policies for each classification level (e.g., Public, Confidential, Private). In contrast, a data custodian has operational responsibility for protecting classified assets or sensitive information according to rules established by owners while ensuring compliance with industry regulations. Custodians implement technical controls such as firewalls or anti-virus software; manage user access permissions/revoking; and maintain confidentiality/integrity as part of day-to-day business operations activities.
upvoted 1 times
...
4e3rv21rq3vq2q
1 year, 8 months ago
Selected Answer: D
Correct Answer: D
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago