shieldCISSP Practice Domain 2 — Asset Security Q60 of 120

Which role is responsible for enforcing access control rules on behalf of the data owner on the systems where data resides?

A CISSP practice question covering Domain 2: Asset Security. Try answering before reading the explanation below.

Show options & answer
A
Data subject
B
Data custodian
✓ Correct answer
C
Data controller
D
Data processor
Why "Data custodian" is the right answer

Custodians (typically IT/operations staff) implement and operate the technical controls per the owner's classification and access decisions. Owners are accountable; custodians execute.

Take the full CISSP practice test
120 questions, instant explanations, study-video links on every miss. No account.
Start full test →