A data owner is the person, usually a senior business manager, who holds ultimate accountability for a specific set of data, including its classification, protection, and acceptable use.
The data owner decides how sensitive the data is and who may access it, then sets the policy. The hands-on tasks are delegated to a data custodian, often in IT, who implements backups, access controls, and technical safeguards. The owner stays accountable even though the custodian does the day-to-day work. For instance, the head of HR might own employee records, classify them as confidential, and approve who can view them, while the IT team acts as custodian and enforces those decisions.
A recurring exam trap is confusing the owner and the custodian. Accountability stays with the owner; responsibility for implementation sits with the custodian. Ownership should rest with the business rather than with IT, because the business understands the value and regulatory context of the data. Assigning ownership to a technical team is a classic governance error.
Why does the data owner role matter for the CISSP exam?
It belongs to Domain 2, Asset Security, which covers data roles, classification, and handling. Questions frequently test whether you can distinguish the owner, the custodian, and the user. Study the role within Domain 2 Asset Security.