正解:B
Comprehensive and Detailed Step-by-Step Explanation:
Thedata owneris the individual or entity responsible for classifying, protecting, and defining access permissions to data. They ensure that only authorized personnel can access, modify, or distribute data based on business needs and regulatory requirements.
* Data Owner (Correct Answer - B)
* The data owner is responsible forsetting user permissionsbased on job roles and business requirements.
* According toISACA's CISA Review Manual and COBIT 2019, the data owner determines access levels while IT personnel enforce them.
* Example:A finance department head (data owner) determines that only certain accountants should access sensitive payroll data.
* IT Operations Manager (Incorrect - A)
* Oversees IT infrastructure but does not define data access controls.
* Database Administrator (DBA) (Incorrect - C)
* Implements and enforces security settings but follows rules set by the data owner.
* Information Security Manager (Incorrect - D)
* Provides security guidance but does not decide specific access permissions.
References:
* ISACA CISA Review Manual
* COBIT 2019 Framework
* NIST 800-53 (Security and Privacy Controls for Federal Information Systems)