Who Enforces Access Controls for CRM Data in CISM?
An organization has implemented a new customer relationship management (CRM) system. Who should be responsible for enforcing authorized and controlled access to the CRM data?
Community Votes
73% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the precise division of duties between data owners and custodians, with the common trap being confusing authorization responsibility with technical enforcement.
This CISM question tests the critical distinction between data ownership and custodianship roles. While the data owner authorizes access, community consensus and ISACA guidelines confirm the data custodian is responsible for technically enforcing those controls.
Many candidates select the data owner because they associate authorized access with business accountability, overlooking that ISACA explicitly assigns the enforcement of implemented controls to the custodian.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The data custodian holds the operational responsibility for implementing and technically enforcing access controls as directed by business leadership. In ISACA’s governance framework, enforcement refers to the configuration, monitoring, and maintenance of security mechanisms, which falls squarely under the custodian’s mandate. For the CRM system, this means managing user provisioning, permissions, and audit logs according to established policies.Why the Other Options Are Wrong
The data owner determines classification and grants authorization but does not perform technical enforcement, making option B incorrect despite the word authorized in the prompt. Internal IT audit provides independent assurance rather than operational control execution, eliminating option C. The information security manager oversees the broader security program and policy development but does not directly manage individual system access enforcement, ruling out option D.Community Comment Notes
Candidates frequently debate this scenario due to overlapping terminology, but the distinction hinges on authorization versus implementation. Comment #1 correctly highlights that the owner determines authority while the custodian enforces it technically. Comment #2 reinforces this by noting that custodians carry out the decisions, though some learners mistakenly equate organizational accountability with hands-on control execution.Official Reference
Exam Strategy
When answering ISACA role-based questions, isolate the exact verb in the stem. Words like determines, authorizes, or is accountable for point to the owner, while implements, maintains, or enforces consistently point to the custodian or technical operator.
Frequently Asked Questions
Why isn't the data owner responsible for enforcing access controls?
The data owner authorizes and classifies data but delegates technical implementation and daily enforcement to the custodian.
How does CISM differentiate between authorization and enforcement?
Authorization is a business decision made by the owner, while enforcement involves configuring and maintaining technical controls executed by the custodian.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →