CISSP GLOSSARY · RISK MANAGEMENT & GOVERNANCE

Data owner

The senior business role accountable for a data set: the owner classifies the data, approves access, and sets protection requirements, and that accountability cannot be delegated.

The data owner is the senior manager or executive accountable for a specific set of data. The owner decides its data classification, approves who may access it, sets the protection requirements technical teams must implement, and periodically reviews both the classification and the access list. Ownership is a business role, not an IT role: the owner is chosen for accountability over the data’s value, not for any ability to administer the systems that hold it.

The distinction that decides questions is accountable versus responsible. The owner can delegate the work of protection to a data custodian, and almost always does, but can never delegate the accountability itself. If classified data leaks because backups were misconfigured, the custodian answers for the misconfiguration; the owner answers for the data. Exam options that hand classification decisions to the security team, IT, or the custodian are traps: those roles advise and implement, they do not decide.

Exam relevance: if a scenario asks who classifies data, who approves access to it, or who is ultimately accountable for its protection, the answer is the data owner. The nearest confusable is the data custodian, who is responsible for implementing the owner’s decisions but accountable for none of them. If the question mentions performing backups or applying permissions, that is the custodian; if it mentions deciding, approving, or accepting risk, that is the owner.