TechKnowSurge
NIST CSF GV.RR-02 NIST 800-53 PM-23 NIST 800-53 PM-19 NIST CSF GV.OC-03 NIST 800-53 PT-3
InteractiveSecurityFree

Whose Job Is It?

Sort workplace situations to the data role behind them — subject, controller, processor, steward, owner, custodian, or Data Protection Officer.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Every card in this activity has the same question behind it: what is this person or organization actually doing with the data? Is it about them, are they deciding what happens to it, are they doing the work, are they approving who gets in, or are they putting the protections in place? Seven roles sound like a lot to hold at once, but most of them come in pairs where one side decides and the other side carries out the decision — and once you see the pairs, the sort mostly takes care of itself. The first pair is controller and processor. The controller has a say in what happens to the data: what gets collected, what it is for, how long it is kept. The processor does the work on the controller's behalf. Often they are the same organization, but when a company hands the work to an outside firm — a payroll service, a newsletter platform, a cloud provider — the outside firm becomes the processor and the company that hired it stays the controller. The trap here is the cloud company storing millions of bank records. That much data makes it feel like it must be in charge, but volume is not the test. The bank's contract says what may be done with the records, so the bank decides and the cloud company carries it out. The hospital that outsources its billing is the mirror image: it hands off the work, not the decision, so it is still the controller. The second pair is owner and custodian, and it is the easiest pair to mix up because both are involved in access. The data owner says yes or no on who should see the data. The custodian — usually IT — is the one who technically puts that decision in place by managing the access list and the protections. The trap is the system administrator who adds the new analyst to the payroll access list. They are the person who literally gives access, so they look like the owner, but they are acting on the finance director's approval; the director is the owner. The database administrator who can open every table is the same lesson from the other side: having technical reach over all of the data does not make you the person who decides who else gets in. Stewards sit alongside these pairs. They are the people and groups inside the organization who use the data in their daily work — the service rep, the HR team, the billing clerk. They need access, but they neither approve it nor set it up, and using the data constantly does not make them its owner. The Data Protection Officer sits above all of it: one person, required by laws such as GDPR, who is responsible across every other role for the data being kept safe. The last DPO card is the owner/DPO boundary — an owner approves access to a particular dataset, while the DPO answers for protection across the whole organization. The data subject is the one role that does not handle the data at all. It is the person the data is about — the applicant, the patient, the shopper. The trap is the customer who asks the store to delete her records. Because she is giving an instruction about the data, it is tempting to file her with the controllers or the DPO, but she is exercising the right to be forgotten as the person the data describes. The lesson points out that more and more laws now treat the subject, not the company that collected the data, as its owner — which is why her request carries weight in the first place.

What you'll learn

Aligned to

NIST CSF
GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced.
GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.
NIST 800-53
PM-23 Data Governance Body
PM-19 Privacy Program Leadership Role
PT-3 Personally Identifiable Information Processing Purposes

Key terms

Data Subject
An individual whose personal data is being collected and processed by another party.
Data Controller
The entity that determines the purposes and means of processing personal data and is responsible for its lawful use.
Data Processor
An entity that processes personal data on behalf of the data controller, sometimes as a third party.
Data Steward
A person or group appointed by the data controller to actively manage and use data in day-to-day operations.
Data Owner
The individual or role accountable for approving access to a specific data set and ensuring the right people have appropriate access.
Data Custodian
The IT or administrative group responsible for technically managing access rights and permissions to data.
Right to Be Forgotten
A regulatory right that allows data subjects to request the deletion of their personal data from an organization's records.
Data Sovereignty
The concept that data is subject to the laws and regulations of the geographic region in which it originates or is collected.
Data Governance
The policies, processes, and standards that define how organizational data is managed, protected, and retained throughout its life cycle.

Topics

Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →