Courseiva
mediumMultiple Choice

CISA Practice Question: Is implementing a data classification policy and…

An organization is implementing a data classification policy and needs to assign ownership for sensitive data. Which of the following is the most appropriate role to assign as the data owner?

⚠ Common exam trap

Many candidates confuse the data owner (business accountability) with the data custodian (technical implementation) or the data steward (compliance oversight), leading candidates to incorrectly select the CISO or system administrator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The head of the business unit that creates and uses the data

The data owner is the person or entity with ultimate accountability for a specific dataset, typically a senior business manager who understands the data's value, legal requirements, and usage context. In this scenario, the head of the business unit that creates and uses the data is best positioned to classify the data, authorize access, and ensure compliance with the data classification policy, as they have direct business responsibility for the data's lifecycle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The chief information security officer (CISO)

    Why it's wrong here

    The CISO sets security strategy, policy and risk appetite across the organisation, but does not own individual data assets or decide their classification and access rules. Data ownership sits with the business function that creates and uses the data. The CISO role would be correct for approving the classification policy itself.

  • ✗

    The system administrator of the database

    Why it's wrong here

    A database system administrator operates and maintains the platform hosting the data, but holds no business accountability for its content, classification or authorised use. Ownership belongs to the business function generating the data. This role would be the correct choice for implementing technical access controls, not for owning data.

  • ✓

    The head of the business unit that creates and uses the data

    Why this is correct

    The data owner is a business role accountable for a data domain's classification, protection requirements and access decisions. The head of the business unit that creates and uses the data holds the requisite business context and authority, unlike IT custodians or security staff who implement controls on the owner's behalf.

  • ✗

    The legal counsel responsible for compliance

    Why it's wrong here

    Legal counsel advises on regulatory obligations affecting data but does not own the asset or determine its business classification and access decisions. Ownership rests with the business function that creates and uses the data. Legal counsel would be the right role for interpreting compliance requirements, not for data ownership.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.