DSP-06: Is the ownership and stewardship of all relevant personal and sensitive data
documented?
A data responsibility matrix can be defined, documented, and communicated. The matrix should include, but is not limited to: a. Data type. b. The associated obligations (regulatory, contractual, or otherwise). c. The persons or roles responsible for the data. d. The frequency at which the documented personal and sensitive data should be reviewed.
Control implemented
Control ownership
Description
Document ownership and stewardship of all relevant documented personal
and sensitive data. Perform review at least annually.
Data Ownership and Stewardship
DSP-06: Is data ownership and stewardship documentation reviewed at least annually?
A data responsibility matrix can be defined, documented, and communicated. The matrix should include, but is not limited to: a. Data type. b. The associated obligations (regulatory, contractual, or otherwise). c. The persons or roles responsible for the data. d. The frequency at which the documented personal and sensitive data should be reviewed.
Control implemented
Control ownership
Description
Document ownership and stewardship of all relevant documented personal
and sensitive data. Perform review at least annually.