問題文
A design team has to name the parties that carry each of the two categorization tasks, if the system also handles information that identifies people. Which order does the risk management framework lay down, and what follows where the decision is turned down?
選択肢
- Carrying out the categorization falls to the system owner together with the information owner or steward, and reviewing and approving the result falls to the authorizing official or a designated representative along with the senior agency official for privacy, and where the system handles information that identifies people the privacy official reviews and approves ahead of the authorizing official, and where the decision is turned down the system owner runs the categorization again and sends the adjusted result back, in that approval-order rule.
- Carrying out the categorization work falls to the authorizing official or to a designated representative, and reviewing and approving the result then falls to the system owner together with the information owner or steward along with the senior agency official for privacy, and where the system handles information that identifies people the privacy official reviews and approves ahead of the authorizing official, and where the decision is turned down the system owner runs the categorization again and sends the adjusted result back, in that approval-order rule.
- Carrying out the categorization falls to the system owner together with the information owner or steward, and reviewing and approving the result falls to the authorizing official or a designated representative along with the senior agency official for privacy, and where the system handles information that identifies people the privacy official reviews and approves after the authorizing official, and where the decision is turned down the authorizing official adjusts the result and records it against the system, in that approval-order rule.
- Carrying out the categorization work falls to the authorizing official or to a designated representative, and reviewing and approving the result then falls to the system owner together with the information owner or steward along with the senior agency official for privacy, and where the system handles information that identifies people the privacy official reviews and approves after the authorizing official, and where the decision is turned down the authorizing official adjusts the result and records it against the system, in that approval-order rule.