Data Security Roles: Owner, Custodian, Controller and Processor for CISSP
What each data security role does, how owner differs from custodian and controller from processor, and why accountability never transfers with the work.
What the organisation owns, who is answerable for it, and how it is handled from creation to destruction: classification, the data roles, the states data moves through, retention, and the end of a product or a medium. Small in weighting, and a frequent source of confusable pairs.
The ISC2 CISSP exam outline lists these areas for Domain 2 and gives the domain a weighting of 10%. The wording below is a plain-English paraphrase; the outline itself is the source.
What each data security role does, how owner differs from custodian and controller from processor, and why accountability never transfers with the work.
What End of Life and End of Support mean, why only the second date is a security cliff, and how CISSP scenarios may test the difference between them.
The process of assigning sensitivity labels to information so that handling, storage, and access requirements follow from the label, and controls are selected to match it.
The senior business role accountable for a data set: the owner classifies the data, approves access, and sets protection requirements, and that accountability cannot be delegated.
The technical role that implements data protection on the owner's behalf: backups, access permissions, patching, and secure storage. Responsible for the work, never accountable for the data.
The three conditions data occupies (at rest in storage, in transit across networks, in use during processing), each demanding its own distinct protection mechanisms.
The residual data that remains on storage media after deletion or formatting, recoverable until the media is properly cleared, purged, or destroyed.
Content-inspection technology that identifies sensitive data and enforces policy to stop it leaving the organisation, deployed at the network edge, on endpoints, or as discovery scans.
A policy enforcement point between users and cloud services that delivers visibility, compliance, data security, and threat protection, including discovery of shadow IT.
Reading is half of it. Scenario questions in this domain tend to turn on the distinctions above, and the quickest way to find out which ones you hold is to answer some. The CISSP practice tests cover all eight domains with an explanation for every answer, and the free assessment gives you a baseline first.