Data owners are responsible for determining the classification of data based on its sensitivity, value, and business impact. They understand the context in which the data is used and can best evaluate its importance and risk profile.
“Data owners are responsible for defining the classification and protection requirements of their data.”
— CISM Review Manual 15th Edition, Chapter 2: Information Risk Management, Section: Data Classification Roles*
The ISO may assist in developing the classification scheme, but the final responsibility lies with the data owner.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit