During a data classification review, a dispute arises over what protection level a customer database should carry. Who is the most appropriate party to decide the classification level of that information asset?
- AThe database administrator, because they configure the technical access controls and backups for the system
- BThe information security manager, because they author the security policy and the classification scheme
- CThe business data owner, because they understand the value of the information and accountability rests with them Correct
- DThe internal audit team, because they independently assess whether controls match the assigned classification
Why A is wrong: Tempting because the administrator handles the asset day to day, but that is a custodian role responsible for safeguarding data, not for judging its business value.
Why B is wrong: Tempting because the security manager defines the scheme, but they facilitate classification rather than decide the sensitivity of data they do not own.
Why C is correct: Correct because the data owner is accountable for the asset, understands its business worth, and is therefore best placed to assign and approve its classification.
Why D is wrong: Tempting because audit checks the outcome, but its independence would be compromised if it set the classification it later reviews.