In the issue of making decisions in the reduction of risk for a particular piece of information, there are bound to be people that would act as ‘information owners” which are usually the persons most associated with the information such as the Head of Human Resources owning personnel information. The most appropriate owners are the individuals that best understand the information’s value and the possible threats to it.
In the real world, these information owners routinely designate appropriate individuals on staff to make security-related assessments for specific cases. Notwithstanding this truth, information owners should be aware of such decisions made related to the information most especially for information protected by regulation.
If you enjoyed this post, make sure you subscribe to my RSS feed!




