๐Ÿงพ CISSP Study Note: Data Custodian

 ๐Ÿงพ CISSP Study Note: Data Custodian


๐Ÿ” Definition

A Data Custodian is the person or role responsible for managing data on a day-to-day basis on behalf of the data owner or data controller. While they do not own the data, they ensure that it is stored, processed, and secured according to policies and requirements.


๐Ÿง  Why It Matters in Cybersecurity

The Data Custodian is essential to the practical implementation of security controls. They keep data organized, accurate, and accessible, while ensuring it remains protected and compliant with organizational or regulatory standards.


๐Ÿ‘ค Role vs. Responsibility

Role Responsibility
Data Owner Defines data classification, access policies, and use.
Data Custodian Implements the owner’s policies, manages data storage, backup, access, and integrity.

Think of the Data Owner as the policymaker, and the Data Custodian as the policy enforcer.


๐Ÿ”ง Key Responsibilities of a Data Custodian

Task Description
Data Storage Ensuring data is stored securely and efficiently (on-prem, cloud, hybrid).
Access Provisioning Granting/revoking user access according to owner’s instructions.
Backups & Recovery Regularly backing up data and testing recovery procedures.
Audit Support Maintaining logs and documentation for audits or forensic review.
Data Integrity Making sure data remains unaltered unless authorized.

๐Ÿ›ก️ Security Functions

  • Enforces encryption at rest/in transit

  • Maintains access control lists (ACLs)

  • Executes patching and configuration management

  • Coordinates with IT/security teams to maintain compliance


✅ Example (CISSP-Style)

The head of IT storage for a university acts as data custodian for student records. They implement encryption, enforce access permissions based on registrar policies, perform weekly backups, and prepare logs for audits.
✅ Though they don’t define who gets access, they enforce and maintain the system as directed by the registrar (data owner).


๐Ÿ“– Found In CISSP Domains

Domain Focus
๐Ÿ“˜ Domain 1: Security and Risk Management Covers roles and responsibilities, including data owner vs. custodian distinctions.
๐Ÿ“˜ Domain 7: Security Operations Details the operational duties related to access management, backup, and incident support.

๐Ÿ”‘ Memory Hook

“The custodian doesn’t own the data—they care for it.”
They’re the guardian, not the ruler of the data.


Comments

Popular posts from this blog

๐Ÿงญ CISSP Study Note: Guidelines

๐Ÿ’ธ CISSP Study Note: Risk Transference

๐Ÿ“ CISSP Study Note: Standards