SY0-701 Question 418
Single answerRoles and responsibilities for systems and data: Owners , Controllers , Processors , Custodians/stewardsA healthcare company stores patient billing records in a SaaS platform. The finance director decides which billing data must be collected, how long it must be retained, and which employees are allowed to access it. The cloud provider stores the records and performs automated backups based on the contract. Meanwhile, the internal IT operations team applies access control lists, restores files when requested, and ensures the backups complete successfully. During an audit, the company must identify which role is responsible for determining the classification and retention requirements for the billing records. Which role is responsible?
- A
Data owner
- B
Data custodian/steward
- C
Data processor
- D
Data controller
Show answer and explanation
Correct answer: A
Explanation
The best answer is data owner. In Security+ role assignments, the data owner is the person or business unit with authority over the data and responsibility for decisions such as classification, retention, and access requirements. The custodian/steward implements and operates the controls that protect the data, while a processor handles data on behalf of the organization under defined instructions. The controller role is most often used in privacy and regulatory contexts to describe the entity that determines the purposes and means of processing personal data. In practice, exam questions often distinguish owner from custodian by asking who defines the rules versus who enforces them. This aligns with common security governance guidance such as NIST concepts around information ownership and operational responsibilities, as well as privacy governance concepts reflected in regulations like GDPR.
- A. Correct.
Correct. The data owner is the role within the organization that determines how data should be classified, who should have access, and what business rules apply, such as retention requirements. In this scenario, the finance director is acting as the data owner because they decide what data is collected, who may access it, and how long it must be kept.
- B. Incorrect.
Incorrect. A data custodian or steward is typically responsible for implementing and maintaining the protections and handling of data according to the owner's requirements. In this scenario, the internal IT operations team fits this role because they manage ACLs, restores, and backup operations, but they do not define classification or retention policy.
- C. Incorrect.
Incorrect. A data processor processes data on behalf of another entity and follows the instructions of the party that determines the purpose and means of processing. The SaaS provider in this scenario is acting as a processor by storing records and performing backups under contract. A common misconception is to assume the processor owns responsibility for policy decisions simply because it hosts the data.
- D. Incorrect.
Incorrect. A data controller determines the purposes and means of processing personal data, a term commonly used in privacy frameworks such as GDPR. Although the finance director's activities resemble controller responsibilities in a privacy context, Security+ role questions about organizational responsibility for classifying and retaining business data typically map that responsibility to the data owner. This option is plausible because controller is a real governance role, but it is not the best answer for this question's focus on internal data ownership.