CISSP Resources · Domain 2 — Asset Security
Data Owner vs Data Controller vs Data Custodian
One of the most common CISSP exam traps: two answers are technically correct but only one role has the authority the question is asking about. This guide separates the four roles you need to know cold.
The 30-second version
- Data Owner — decides what the data is worth and who gets access. A business role, not a technical one.
- Data Controller — a GDPR term. Decides why and how personal data is processed. Legally accountable to regulators.
- Data Custodian — implements and maintains controls. Runs backups, patches the database, provisions access the way the Owner specified.
- Data Processor — a GDPR term. Handles personal data on the Controller's instructions.
Side-by-side
| Role | Responsibility | Authority | Accountable? |
|---|---|---|---|
| Data Owner | Classifies the data, defines protection requirements, approves access. | Senior business/management role. Ultimately accountable for the data. | Yes — the buck stops here for how the data is classified, protected, and used. |
| Data Controller (GDPR) | Determines the purposes and means of processing personal data. Legal responsibility for compliance. | Legal/regulatory role under privacy law (GDPR, UK DPA, similar). Often the organisation itself. | Yes — legally accountable to regulators and data subjects for lawful processing. |
| Data Custodian | Implements and maintains controls the Data Owner specified: backups, access provisioning, patching, encryption at rest. | Technical/operational role (DBA, sysadmin, storage team). Does not decide classification. | Operationally responsible for day-to-day protection, not for what the data is or how it may be used. |
| Data Processor (GDPR) | Processes personal data on behalf of the Data Controller, only on documented instructions. | Third party or internal team acting under contract with the Controller. | Limited — must follow Controller's instructions and secure the data; Controller remains accountable to regulators. |
Who is responsible for X?
Classifying the data: Data Owner. Not the custodian, not IT, not security.
Approving who gets access: Data Owner. Custodians provision the access the Owner approves.
Running nightly backups and applying database patches: Data Custodian.
Deciding the lawful basis for processing personal data: Data Controller.
Processing personal data under a signed agreement on the Controller's instructions: Data Processor.
Being ultimately accountable if the data is misclassified or mishandled: Data Owner (organisationally) and Data Controller (legally, for personal data).
CISSP exam tips
- If the question is about classification, access approval, or acceptable use, the answer is almost always Data Owner.
- If the question mentions GDPR, personal data, lawful basis, or regulators, switch into privacy-law vocabulary: Controller vs Processor.
- If the question is about backups, patching, encryption at rest, or storage administration, the answer is Data Custodian.
- Watch for "BEST" and "PRIMARY" — a Custodian may technically do the work, but the Owner is the one accountable for the decision.
Practise these role questions
Domain 2 (Asset Security) questions on Domain Eight test these distinctions with scenario-based, best-answer style questions.
