Who Enforces Access Controls for CRM Data in CISM?

Answer Correct answer: A — The data custodian is responsible for technically enforcing authorized and controlled access to the CRM system per the data owner’s directives.

An organization has implemented a new customer relationship management (CRM) system. Who should be responsible for enforcing authorized and controlled access to the CRM data?

  1. The data custodian Correct Answer
  2. The data owner
  3. Internal IT audit
  4. The information security manager

Community Votes

A
73%
B
27%

73% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the precise division of duties between data owners and custodians, with the common trap being confusing authorization responsibility with technical enforcement.

This CISM question tests the critical distinction between data ownership and custodianship roles. While the data owner authorizes access, community consensus and ISACA guidelines confirm the data custodian is responsible for technically enforcing those controls.

Many candidates select the data owner because they associate authorized access with business accountability, overlooking that ISACA explicitly assigns the enforcement of implemented controls to the custodian.

Community Discussion (7 comments)

60d8b7d 👍 6 Selected: A
The data owner determines who should have the authority to access the data. The data custodian ENFORCES the authority recommended by the data owner. It's A for me.
SHERLOCKAWS 👍 1 Selected: B
Answer is B: The data owner. B. The data owner. Because access must be authorized, and authorization decisions belong to the data owner. The custodian just carries out those decisions. Custodian enforces access technically. Owner enforces access organizationally and is ultimately responsible for making sure access is appropriate.
ITAbi 👍 1 Selected: B
Data Owner
Infosecnerd 👍 1
B The data owner should be responsible for enforcing authorized and controlled access to the CRM data. The data owner is typically responsible for determining access rights and ensuring that access controls are implemented and maintained in accordance with the organization's policies and data protection requirements.
bronay 👍 1 Selected: A
A. Data custodian
oluchecpoint 👍 1 Selected: A
Data custodian
ats20 👍 1 Selected: B
Data owner

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The data custodian holds the operational responsibility for implementing and technically enforcing access controls as directed by business leadership. In ISACA’s governance framework, enforcement refers to the configuration, monitoring, and maintenance of security mechanisms, which falls squarely under the custodian’s mandate. For the CRM system, this means managing user provisioning, permissions, and audit logs according to established policies.

Why the Other Options Are Wrong

The data owner determines classification and grants authorization but does not perform technical enforcement, making option B incorrect despite the word authorized in the prompt. Internal IT audit provides independent assurance rather than operational control execution, eliminating option C. The information security manager oversees the broader security program and policy development but does not directly manage individual system access enforcement, ruling out option D.

Community Comment Notes

Candidates frequently debate this scenario due to overlapping terminology, but the distinction hinges on authorization versus implementation. Comment #1 correctly highlights that the owner determines authority while the custodian enforces it technically. Comment #2 reinforces this by noting that custodians carry out the decisions, though some learners mistakenly equate organizational accountability with hands-on control execution.

Official Reference

Exam Strategy

When answering ISACA role-based questions, isolate the exact verb in the stem. Words like determines, authorizes, or is accountable for point to the owner, while implements, maintains, or enforces consistently point to the custodian or technical operator.

Frequently Asked Questions

Why isn't the data owner responsible for enforcing access controls?

The data owner authorizes and classifies data but delegates technical implementation and daily enforcement to the custodian.

How does CISM differentiate between authorization and enforcement?

Authorization is a business decision made by the owner, while enforcement involves configuring and maintaining technical controls executed by the custodian.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide