CISM Certified Information Security Manager – Question0283

Who is responsible for ensuring that information is classified?

A.
Senior management
B. Security manager
C. Data owner
D. Custodian

Correct Answer: C

Explanation:

Explanation:
The data owner is responsible for applying the proper classification to the data. Senior management is ultimately responsible for the organization. The security officer is responsible for applying security protection relative to the level of classification specified by the owner. The technology group is delegated the custody of the data by the data owner, but the group does not classify the information.