Who is responsible for protecting an asset that has value, while in one's possession?

Prepare for the ISSAP Exam with challenging questions and insights. Enhance your understanding using flashcards and detailed explanations. Master your skills for success!

Multiple Choice

Who is responsible for protecting an asset that has value, while in one's possession?

Explanation:
Protecting an asset while it is in someone’s possession is the responsibility of the custodian. The custodian is the party charged with safekeeping and implementing the day-to-day security controls for the asset—controls like access management, storage, backups, monitoring, and incident response. They turn policy into practice and ensure the asset remains protected during handling and when in use. The data owner or controller sets the business requirements, defines what must be protected, and bears accountability for risk and policy decisions, but they typically do not perform routine protective duties. Confidentiality is a security objective, not a role. In this context, the custodian is the best fit for the responsibility of protecting the asset during possession.

Protecting an asset while it is in someone’s possession is the responsibility of the custodian. The custodian is the party charged with safekeeping and implementing the day-to-day security controls for the asset—controls like access management, storage, backups, monitoring, and incident response. They turn policy into practice and ensure the asset remains protected during handling and when in use.

The data owner or controller sets the business requirements, defines what must be protected, and bears accountability for risk and policy decisions, but they typically do not perform routine protective duties. Confidentiality is a security objective, not a role. In this context, the custodian is the best fit for the responsibility of protecting the asset during possession.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy