1/19
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
An organization determines that customer information should only be used for specific business purposes and establishes the requirements for how that information may be processed. Which role is primarily responsible for making these decisions?
A. Data Custodian
B. Data Subject
C. Data Controller
D. Data Processor
C. Data Controller
Data Controller → Why and how is personal data processed? Determines the purposes and means of processing personal or business data.
A database administrator configures access controls, encryption, backups, and other technical safeguards according to the organization's data-protection requirements. Which data governance role best describes this individual?
A. Data Owner
B. Data Subject
C. Data Custodian
D. Data Controller
C. Data Custodian
Data Custodian: The IT or technical staff responsible for the physical and system infrastructure, such as data storage, backups, encryption, and access control implementation.
Which role is responsible for establishing and enforcing business rules and policies governing how data should be managed and protected?
A. Data Steward
B. Data Custodian
C. Data Subject
D. Data Processor
A. Data Steward
Data Steward → What rules/policies should govern the data?
Which role has ultimate responsibility and accountability for a particular set of organizational data?
A. Data Custodian
B. Data Owner
C. Data Processor
D. Data Subject
B. Data Owner
Data Owner → Who has ultimate accountability/authority over it?
A data owner establishes a requirement that confidential customer records must be encrypted. A security administrator then configures the database to enforce encryption. Which role is the security administrator performing?
A. Data Owner
B. Data Controller
C. Data Steward
D. Data Custodian
D. Data Custodian
Data Custodian → Implementing the controls
A company creates a policy stating that employee records must be retained for seven years and must only be accessed by authorized personnel. Which role would primarily be responsible for developing and maintaining these data governance rules?
A. Data Subject
B. Data Steward
C. Data Custodian
D. Data Processor
B. Data Steward
Data Steward → What rules/policies should govern the data?
An organization has established policies describing how sensitive data must be classified, retained, accessed, and protected. Which role is primarily responsible for maintaining these data governance rules?
A. Data Subject
B. Data Custodian
C. Data Steward
D. Data Processor
C. Data Steward
A database administrator configures role-based access controls based on requirements established by the organization. Which role is the administrator performing?
A. Data Steward
B. Data Custodian
C. Data Subject
D. Data Owner
B. Data Custodian
Data Custodian: Actually implements the controls
Which statement BEST describes the difference between a data steward and a data custodian?
A. The steward owns the data, while the custodian is the person the data describes.
B. The steward establishes and manages data governance requirements, while the custodian implements controls to protect the data.
C. The custodian establishes and manages data governance requirements, while the steward implements controls to protect the data.
D. The steward is responsible for collecting data, while the custodian determines who owns it.
B.
A data steward determines that employees should only have access to customer information necessary for their job functions. Who would typically be responsible for configuring the technical access controls that enforce this requirement?
A. Data Custodian
B. Data Subject
C. Data Controller
D. Data Processor
A. Data Custodian
Data Owner
Ultimately responsible for a data asset
Data Steward
Determines the rules/policies governing the data
Data Custodian
Actually implements the controls that are required to meet the policy/rule requirements set by the Data Steward
Data Controller
Determines the purposes and means of processing the data. WHY the data is being processed.
Data Processor
Processes/uses the data on behalf of and strictly according to the instructions of the Data Controller.
Where does the Data Processor get its instructions from?
A. Steward
B. Controller
C. Owner
D. Subject
B. Controller
Where does the Data Processor get its instructions from?
The Data Controller
Data Subject
The person who’s data is being processed/used/is about
Data Protection Officer (DPO)
A high-level compliance manager overseeing an organization's overall data privacy framework and regulatory adherence
DPO
Data Protection Officer.