<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CISSP - Data Owners to Determine the Classification Required for the Data in Exam Preparation</title>
    <link>https://community.isc2.org/t5/Exam-Preparation/CISSP-Data-Owners-to-Determine-the-Classification-Required-for/m-p/38748#M3218</link>
    <description>data owner is respective to the entity; so the engineering firm has a data owner; the business that use the drawing also has a data owner.</description>
    <pubDate>Mon, 31 Aug 2020 13:22:40 GMT</pubDate>
    <dc:creator>sergeling</dc:creator>
    <dc:date>2020-08-31T13:22:40Z</dc:date>
    <item>
      <title>CISSP - Data Owners to Determine the Classification Required for the Data</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/CISSP-Data-Owners-to-Determine-the-Classification-Required-for/m-p/38740#M3216</link>
      <description>&lt;P&gt;I'm working through the CISSP Self-Guided Certification and I have a question:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why are we looking to allow the Data Owner to create the Classification?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe I'm not looking at this incorrectly, but if a user at a company is creating the data, lets say a design engineer at an engineering firm creates a drawing of a device. Who would be the "Data Owner" in that scenario? Would it be the user that created it and maintains it or business that the user works for?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 11:55:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/CISSP-Data-Owners-to-Determine-the-Classification-Required-for/m-p/38740#M3216</guid>
      <dc:creator>TDwyer2</dc:creator>
      <dc:date>2020-08-31T11:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP - Data Owners to Determine the Classification Required for the Data</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/CISSP-Data-Owners-to-Determine-the-Classification-Required-for/m-p/38743#M3217</link>
      <description>&lt;P&gt;Let me see if I can help and hopefully not make it more confusing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Data Classification system is typically developed by Information Security in conjunction with the Business.&amp;nbsp; This helps define the number of classes of data and allows for the proper control and security measures to be put into place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As to your example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;a user at a company is creating the data, lets say a design engineer at an engineering firm creates a drawing of a device. Who would be the "Data Owner" in that scenario? Would it be the user that created it and maintains it or business that the user works for?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First a design engineer typically would have a client (that client could be an external contract or the engineering firm itself).&amp;nbsp; If the engineer is being paid by the engineering firm to develop devices, then the company they work for would be the data owner.&amp;nbsp; In this case, the engineer would most likely work within a business unit/department and the manager would be the data owner.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If however it is a client than a different scenario drops into play.&amp;nbsp; Its called a contract and the contract should define who owns the drawing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A simplier example would be:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In accounting, there is a need to create a new spreadsheet for reporting purposes.&amp;nbsp; The IT development department may develop the spreadsheet and may in some cases do database joins, etc to compile or fill in the information.&amp;nbsp; In this case, the data belongs to the accounting department and it would make them the data owner.&amp;nbsp; IT typically does not own any data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps, if not, let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 12:46:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/CISSP-Data-Owners-to-Determine-the-Classification-Required-for/m-p/38743#M3217</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2020-08-31T12:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP - Data Owners to Determine the Classification Required for the Data</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/CISSP-Data-Owners-to-Determine-the-Classification-Required-for/m-p/38748#M3218</link>
      <description>data owner is respective to the entity; so the engineering firm has a data owner; the business that use the drawing also has a data owner.</description>
      <pubDate>Mon, 31 Aug 2020 13:22:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/CISSP-Data-Owners-to-Determine-the-Classification-Required-for/m-p/38748#M3218</guid>
      <dc:creator>sergeling</dc:creator>
      <dc:date>2020-08-31T13:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP - Data Owners to Determine the Classification Required for the Data</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/CISSP-Data-Owners-to-Determine-the-Classification-Required-for/m-p/38841#M3219</link>
      <description>&lt;P&gt;I think that whoever the organization designated as the Data Owner for the engineering firm is the data owner for that information/drawing. Since several different people create data throughout the organization, the data owner should have developed security classification guidance for users/personnel to reference to help ensure that data is properly classified throughout the organization.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 18:22:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/CISSP-Data-Owners-to-Determine-the-Classification-Required-for/m-p/38841#M3219</guid>
      <dc:creator>Joelharris788</dc:creator>
      <dc:date>2020-08-31T18:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP - Data Owners to Determine the Classification Required for the Data</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/CISSP-Data-Owners-to-Determine-the-Classification-Required-for/m-p/38868#M3220</link>
      <description>&amp;gt; Joelharris788 (Viewer) posted a new reply in Exam Preparation on 08-31-2020&lt;BR /&gt;&lt;BR /&gt;&amp;gt; I think that whoever the organization designated as the Data Owner for&lt;BR /&gt;&amp;gt; the engineering firm is the data owner for that information/drawing. Since&lt;BR /&gt;&amp;gt; several different people create data throughout the organization, the data owner&lt;BR /&gt;&amp;gt; should have developed security classification guidance for users/personnel to&lt;BR /&gt;&amp;gt; reference to help ensure that data is properly classified throughout the&lt;BR /&gt;&amp;gt; organization.&lt;BR /&gt;&lt;BR /&gt;I suspect that you guys are overthinking this. I *strongly* suspect that the&lt;BR /&gt;original question turns on the DAC/MAC distinction.&lt;BR /&gt;&lt;BR /&gt;In discretionary access control, the owner tends to be simply the person who&lt;BR /&gt;creates the file. Under a mondatory access control system, the data owner assigns&lt;BR /&gt;sensitivity, but access is granted by the system, checking senistivity against&lt;BR /&gt;clearance.&lt;BR /&gt;&lt;BR /&gt;Under a formal non-discretionary access control system, an access control office&lt;BR /&gt;may play the role of the data owner (or steward) in granting access. However, I&lt;BR /&gt;doubt that any of you would have work with such a system: they are pretty&lt;BR /&gt;ancient.&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@gmail.com rmslade@outlook.com rslade@computercrime.org&lt;BR /&gt;Wrinkles should merely indicate where smiles have been. - Mark Twain&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413" target="_blank"&gt;https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413&lt;/A&gt;</description>
      <pubDate>Mon, 31 Aug 2020 19:23:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/CISSP-Data-Owners-to-Determine-the-Classification-Required-for/m-p/38868#M3220</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-08-31T19:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP - Data Owners to Determine the Classification Required for the Data</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/CISSP-Data-Owners-to-Determine-the-Classification-Required-for/m-p/38889#M3222</link>
      <description>&lt;P&gt;Thank you, that clears it up a little bit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my example, something I have worked with for several years, the data owner would be the business and most of what the engineers are doing is modifying current designs for a customer under a contract. So inevitably the contract could stipulate how the data can be used/retained, but the business would be the owner.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Watching the videos, the instructor keeps saying "data owner" &amp;amp; "asset owner." I keep thinking its the creator of the data that owns it, which most times it would the person, like an author of a book, but it could easily be the business since the user could work for a business, like a game designer.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 12:40:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/CISSP-Data-Owners-to-Determine-the-Classification-Required-for/m-p/38889#M3222</guid>
      <dc:creator>TDwyer2</dc:creator>
      <dc:date>2020-09-01T12:40:06Z</dc:date>
    </item>
  </channel>
</rss>

