๐งพ CISSP Study Note: Data Custodian
๐งพ CISSP Study Note: Data Custodian
๐ Definition
A Data Custodian is the person or role responsible for managing data on a day-to-day basis on behalf of the data owner or data controller. While they do not own the data, they ensure that it is stored, processed, and secured according to policies and requirements.
๐ง Why It Matters in Cybersecurity
The Data Custodian is essential to the practical implementation of security controls. They keep data organized, accurate, and accessible, while ensuring it remains protected and compliant with organizational or regulatory standards.
๐ค Role vs. Responsibility
| Role | Responsibility |
|---|---|
| Data Owner | Defines data classification, access policies, and use. |
| Data Custodian | Implements the owner’s policies, manages data storage, backup, access, and integrity. |
Think of the Data Owner as the policymaker, and the Data Custodian as the policy enforcer.
๐ง Key Responsibilities of a Data Custodian
| Task | Description |
|---|---|
| Data Storage | Ensuring data is stored securely and efficiently (on-prem, cloud, hybrid). |
| Access Provisioning | Granting/revoking user access according to owner’s instructions. |
| Backups & Recovery | Regularly backing up data and testing recovery procedures. |
| Audit Support | Maintaining logs and documentation for audits or forensic review. |
| Data Integrity | Making sure data remains unaltered unless authorized. |
๐ก️ Security Functions
-
Enforces encryption at rest/in transit
-
Maintains access control lists (ACLs)
-
Executes patching and configuration management
-
Coordinates with IT/security teams to maintain compliance
✅ Example (CISSP-Style)
The head of IT storage for a university acts as data custodian for student records. They implement encryption, enforce access permissions based on registrar policies, perform weekly backups, and prepare logs for audits.
✅ Though they don’t define who gets access, they enforce and maintain the system as directed by the registrar (data owner).
๐ Found In CISSP Domains
| Domain | Focus |
|---|---|
| ๐ Domain 1: Security and Risk Management | Covers roles and responsibilities, including data owner vs. custodian distinctions. |
| ๐ Domain 7: Security Operations | Details the operational duties related to access management, backup, and incident support. |
๐ Memory Hook
“The custodian doesn’t own the data—they care for it.”
They’re the guardian, not the ruler of the data.
Comments
Post a Comment