mediumMultiple Choice
CISA Practice Question: Is implementing a data classification policy and…
An organization is implementing a data classification policy and needs to assign ownership for sensitive data. Which of the following is the most appropriate role to assign as the data owner?
⚠ Common exam trap
Many candidates confuse the data owner (business accountability) with the data custodian (technical implementation) or the data steward (compliance oversight), leading candidates to incorrectly select the CISO or system administrator.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The head of the business unit that creates and uses the data
The data owner is the person or entity with ultimate accountability for a specific dataset, typically a senior business manager who understands the data's value, legal requirements, and usage context. In this scenario, the head of the business unit that creates and uses the data is best positioned to classify the data, authorize access, and ensure compliance with the data classification policy, as they have direct business responsibility for the data's lifecycle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The chief information security officer (CISO)
Why it's wrong here
The CISO sets security strategy, policy and risk appetite across the organisation, but does not own individual data assets or decide their classification and access rules. Data ownership sits with the business function that creates and uses the data. The CISO role would be correct for approving the classification policy itself.
- ✗
The system administrator of the database
Why it's wrong here
A database system administrator operates and maintains the platform hosting the data, but holds no business accountability for its content, classification or authorised use. Ownership belongs to the business function generating the data. This role would be the correct choice for implementing technical access controls, not for owning data.
- ✓
The head of the business unit that creates and uses the data
Why this is correct
The data owner is a business role accountable for a data domain's classification, protection requirements and access decisions. The head of the business unit that creates and uses the data holds the requisite business context and authority, unlike IT custodians or security staff who implement controls on the owner's behalf.
- ✗
The legal counsel responsible for compliance
Why it's wrong here
Legal counsel advises on regulatory obligations affecting data but does not own the asset or determine its business classification and access decisions. Ownership rests with the business function that creates and uses the data. Legal counsel would be the right role for interpreting compliance requirements, not for data ownership.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.