Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 132 discussion

Actual exam question from ISC's CISSP
Question #: 132
Topic #: 1
[All CISSP Questions]

A project manager for a large software firm has acquired a government contract that generates large amounts of Controlled Unclassified Information (CUI). The organization's information security manager had received a request to transfer project-related CUI between systems of differing security classifications. What role provides the authoritative guidance for this transfer?

  • A. PM
  • B. Information owner
  • C. Data Custodian
  • D. Mission/Business Owner
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
dev46
Highly Voted 2 years, 2 months ago
Selected Answer: C
Information/ data owner does the classification and can delegate job for transfer to custodian
upvoted 5 times
...
e58c193
Most Recent 7 months, 3 weeks ago
Selected Answer: C
B. OSG 9th Edition PG. 207. Data owners often delegate day-day tasks to the custodian.
upvoted 1 times
...
homeysl
8 months, 1 week ago
Selected Answer: B
Data owner = authority
upvoted 1 times
...
gjimenezf
10 months, 2 weeks ago
Selected Answer: B
key word is authoritative, that is the data/information owner
upvoted 3 times
Kyanka
8 months, 2 weeks ago
Agreed. In real life, the owner normally has to approve transfer between different classification levels. Not sure what they expect on a test, though.
upvoted 1 times
...
...
maawar83
10 months, 3 weeks ago
Scope: Information Owner: Focuses on the strategic management, policies, and decision-making related to specific data assets. Data Custodian: Primarily concerned with the technical implementation, storage, and security of data assets. Decision-Making Authority: Information Owner: Holds decision-making authority regarding data policies, access controls, and overall data strategy. Data Custodian: Implements decisions made by the information owner and focuses on technical execution. Accountability: Information Owner: Ultimately accountable for the governance, quality, and strategic use of the data assets they own. Data Custodian: Accountable for the secure storage, processing, and technical aspects of data management. Involvement in Governance: Information Owner: Actively involved in data governance, policy creation, and ensuring alignment with organizational goals. Data Custodian: Implements and enforces governance policies but may not be directly involved in setting high-level data strategy.
upvoted 1 times
...
YesPlease
11 months, 2 weeks ago
Selected Answer: B
Answer B) Information Owner https://blog.idatainc.com/data-governance-roles
upvoted 1 times
...
homeysl
1 year, 1 month ago
Selected Answer: B
B. OSG 9th Edition. Keyword "authoritative".
upvoted 1 times
...
MShaaban
1 year, 3 months ago
I go with B. Data custodian doesn’t have any authoritative over data, they are just responsible for the day to day activities including data backup etc, after being advised by the Information Owner.
upvoted 2 times
...
dyndevil
1 year, 4 months ago
Answer:C Data Owner has ultimate responsibility of the data and hence the classification of the data. Once classification is decided, it is delegated to Data Custodian to carry out the task.
upvoted 1 times
...
Jacobmy98
1 year, 4 months ago
Selected Answer: B
I think its B due to "authoritative" being used. plus 9th edition Page 204 has insight on data owners being the main personnel to make those decisions.
upvoted 4 times
...
Bach1968
1 year, 4 months ago
Selected Answer: C
data owner, or data custodian, may seem the correct answer/s
upvoted 1 times
...
babaseun
1 year, 6 months ago
Selected Answer: B
CISSP 9th Edition, Page 204....
upvoted 3 times
jackdryan
1 year, 6 months ago
B is correct
upvoted 1 times
...
...
Rollingalx
1 year, 8 months ago
I go with B The National Institute of Standards and Technology (NIST) Special Publication 800-171, which provides guidance for protecting CUI in nonfederal systems and organizations, states that the "information owner is responsible for identifying and marking CUI and specifying the safeguarding or dissemination controls to be applied to the information."
upvoted 2 times
...
crazywai1221
1 year, 8 months ago
Selected Answer: C
i voted C, owner only classified data
upvoted 1 times
...
Alex71
1 year, 9 months ago
Selected Answer: B
The authoritative guidance for the transfer of Controlled Unclassified Information (CUI) between systems of differing security classifications is provided by the Information Owner. The Information Owner is responsible for ensuring that the information is appropriately protected and managed throughout its lifecycle, including during transfer between systems. In this case, the Information Owner should consult with the organization's information security manager and follow any applicable policies, procedures, and guidelines for handling CUI.
upvoted 3 times
...
JohnyDal
1 year, 9 months ago
Selected Answer: B
data/info owner
upvoted 2 times
...
oban
1 year, 10 months ago
Selected Answer: D
D. Mission/Business Owner is the role that provides the authoritative guidance for the transfer of project-related Controlled Unclassified Information (CUI) between systems of differing security classifications. The mission/business owner is responsible for the overall mission or business objectives of the organization and has the authority to make decisions about the handling of project-related CUI, including the transfer of CUI between systems with differing security classifications. A. The Project Manager (PM) is responsible for the planning, execution, and closing of the project, but not for the Security/protective measures of the information/data. B. Information owner is responsible for determining the level of protection and access controls required for the CUI. C. Data Custodian is responsible for the physical and technical protection of the information and systems containing the CUI. Source: openai
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...