Courseiva
easyMultiple Choice

CISA Practice Question: When implementing a data classification policy,…

When implementing a data classification policy, which of the following roles is PRIMARILY responsible for assigning classification labels to data?

⚠ Common exam trap

ISACA often tests the distinction between data owner (who assigns classification) and data custodian (who implements controls), leading candidates to mistakenly choose the custodian because they confuse technical implementation with business ownership.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data owner.

The data owner is the senior manager or business process owner who has the authority to determine the sensitivity and criticality of the data. They are primarily responsible for assigning classification labels because they understand the business impact if the data is compromised. This role defines the classification level (e.g., Public, Internal, Confidential, Restricted) based on the data's value and legal or regulatory requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data custodian.

    Why it's wrong here

    The custodian operates and protects assets under the owner's direction — backups, access provisioning, storage media — but does not decide sensitivity. Custodians would be the right answer if the question asked who implements the controls that safeguard data once its classification has been determined.

  • ✓

    Data owner.

    Why this is correct

    The data owner holds accountability for the data asset and understands its sensitivity and business context, so they assign classification labels. This satisfies the policy requirement that labelling decisions rest with the accountable business role rather than custodians or users.

  • ✗

    Data user.

    Why it's wrong here

    Data users consume and handle data under assigned labels, so they lack the authority to set classification themselves. The tempting draw is that users often know data content best, but ownership and accountability sit with the data owner, who defines and assigns labels; users merely comply with handling rules.

  • ✗

    Data steward.

    Why it's wrong here

    The steward manages data quality, definitions and metadata on the owner's behalf, but label assignment rests with the data owner, who is accountable for the asset's value and sensitivity. Stewards would be correct if the question concerned maintaining data standards and glossary definitions.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.