Comprehensive and Detailed Explanation:
The CGEIT Review Manual 8th Edition, in its Governance of Enterprise IT domain, addresses data governance to ensure proper management and protection of data, including third-party data. Establishing data ownership with clear accountabilities ensures that specific individuals or roles are responsible for overseeing third-party data, preventing unauthorized use through defined policies and controls. For example, a data owner can enforce access restrictions and monitor usage. The manual likely references COBIT 2019’s APO14-Managed Data, which emphasizes data ownership for governance.
Option A: Communicate consequences is reactive and less effective than proactive ownership.
Option B: Encrypt data in transit addresses security but not unauthorized internal use.
Option D: Retention periods manage data lifecycle but don’t directly prevent misuse.
Double Verification: The answer aligns with COBIT’s APO14 and the CGEIT domain’s focus on data governance. Data ownership is a core ISACA principle for data protection.
ISACA CGEIT Review Manual 8th Edition, Domain 1: Governance of Enterprise IT (focus on data governance).
COBIT 2019, APO14-Managed Data.
ISACA Glossary (for definitions of data ownership), available at https://www.isaca.org/resources/glossary.
Submit