Which of the following roles is accountable for the confidentiality integrity and availability of information within an enterprise?
Correct Answer: B
The data owner is the role that is accountable for the confidentiality, integrity, and availability of information within an enterprise, because the data owner is the person who has the authority and responsibility to classify, label, and protect the information assets according to their value and sensitivity1. The data owner also defines the business requirements for the information security and ensures that the data custodian implements the appropriate controls to safeguard the information2. The data owner is also part of the IT governance domain 4:
Value Delivery3. References := 1: Data Classification Standard3, page 42: 3 Pillars of Data Security:
Confidentiality, Integrity & Availability43: CGEIT Review Manual 2023, ISACA, page 155.