Articles

Owner, custodian and service owner: three names on one asset

Three hats on one asset: who sets the rules, who runs it, and what the register names.

Reading: 5 minCybersecurity Governance

Article cover: Owner, custodian and service owner: three names on one asset

One asset carries three jobs; the vocabulary names only two. Somebody answers for whether the asset is protected and used as agreed; somebody holds and operates it; somebody keeps the service it delivers running. NIST defines the system owner and the information owner or steward, never service owner, and does not use custodian as an asset role at all.

Three jobs on one asset

SP 800-39 draws the picture in a footnote: the information system owner is “the central point of contact between the authorization process and the owners of components of the system” — the components themselves, the information processed, stored or transmitted by the system, and the mission or business function it serves (footnote 73; nist-sp800-39.txt lines 4382–4386). SP 800-100 assumes the same split: the security plan reflects input from “information owners, the system owner, and the senior agency information security officer (SAISO)” (line 3885).

one asset (a system, a component, an information set, a service)
  |
  |-- who sets the rules for the information?   information owner / steward
  |       authority over information, not over a machine
  |
  |-- who runs the system and answers for it?   system owner
  |       procurement, integration, operation, maintenance, security plan
  |
  |-- who keeps the service it delivers up?     no NIST role name
  |       "service owner" is industry vocabulary; the corpus offers
  |       business / asset / mission owner as title variants
  |
  `-- the register record (CM-8): a name, a position, or a role

The hat that sets the rules: information owner

SP 800-12r1 §3.4 defines the role: “an organizational official with statutory, management, or operational authority for specified information who is responsible for establishing the policies and procedures governing its generation, collection, processing, dissemination, and disposal” (lines 917–919). The authority is over information, not a machine, and survives sharing: it “retains that responsibility even when the data/information is shared with other organizations” (SP 800-100 footnote 58, lines 4055–4056). §8.2.3 adds the operational decisions — the rules for use and protection, and who has access and with what privileges (lines 4039–4046).

The hat that runs it: system owner

SP 800-100 §8.2.2 makes the system owner “the agency official responsible for the overall procurement, development, integration, modification, and operation and maintenance of the information system” (line 4015). SP 800-37r2 writes the coordination into the task: “In coordination with the information owner/steward, the system owner decides who has access to the system (and with what types of privileges or access rights)” (lines 7851–7852), footnote 122 allowing that the decision “may reside with the information owner/steward” (lines 7865–7866).

The third hat has no NIST name

grep -a -c -i "service owner" over all 24 converted publications returns zero. The job is documented — §8.2.2 puts “operation and maintenance” with the system owner — but nobody here is appointed a service owner. The corpus offers title variants instead: “program managers or business/asset owners” (SP 800-37r2 footnote 121, line 7863) and “business/asset/mission owners” (SP 800-100 footnote 57, lines 4052–4053). So the name is either a title variant of the system owner or the organisation’s own name for the mission owner in footnote 73.

“Custodian”: one word, six unrelated uses

The word is not a role in the current corpus: grep -a -n -i custodian hits eight files, and the one role-shaped use in SP 800-53r5 is media transport: “Employ an identified custodian during transport of system media outside of controlled areas”, discussed as a “point of contact” whose responsibilities “can be transferred from one individual to another if an unambiguous custodian is identified” (lines 11882–11887) — a person escorting an artefact, not an owner. Cite it as MP-5(3) CUSTODIANS, not MP-6(3) (MP-5 MEDIA TRANSPORT, line 11834; SP 800-53A r5 MP-05(03), line 20152). Elsewhere the word is incidental or metaphorical (a data custodian, line 23439; “the information custodian” for sanitisation policy, SP 800-88r2 line 1509; “approved custodian services”, SP 800-161r1-upd1 line 6523; “receiving custodians of the risk management discipline”, NISTIR 8286r1 line 596). Only the superseded SP 800-12 (October 1995, withdrawn 21 June 2017) makes it an asset role: access is “specified by the owner (or custodian) of the resource” (line 10380). The corpus calls that person a system administrator (SP 800-53r5 §1.2, line 1462) and gives them no ownership.

What the register has to name

CM-8 prescribes evidence, not a role model. The inventory must include “organization-defined information deemed necessary to achieve effective system component accountability” (lines 7821–7822), and CM-8(4) requires “a means for identifying by [Selection (one or more): name; position; role], individuals responsible and accountable for administering those components” (lines 7915–7919), so that the organisation can reach them when a component is the source of a breach or needs replacing (lines 7920–7923). SP 800-128 narrows the record to one name: “the authority over and responsibility for each component is with only one system owner” (lines 1197–1199). The Selection permits a position or a role; the purpose is to reach a person: “The network team” satisfies the first and fails the second.

Delegating a hat without moving accountability

SP 800-100 §8.2.5 shows how far delegation reaches: the information system security officer (ISSO) is “assigned responsibility by the SAISO, authorizing official, management official, or information system owner” — four appointing roles, one job (lines 4080–4082). SP 800-37r2 footnote 123 lets the authorizing official “designate an individual other than the system owner to compile and assemble the information for the authorization package” (lines 7868–7870). CSF 2.0 requires these appointments to be “established, communicated, understood, and enforced” (GV.RR-02). Delegating the work is normal; the accountability does not travel with it (see the L1 sheet on accountability).

Level and prerequisites

L2 — operational: name the hats, record the names, know which hat carries which decision. Prerequisites are the L1 ownership vocabulary and a working idea of an asset inventory; inventory controls, RACI and service criticality are sibling sheets.

Where to go next

References

  • NIST — SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations — https://doi.org/10.6028/NIST.SP.800-53r5 — CM-8(a)(5) accountability information (lines 7821–7822), CM-8(4) ACCOUNTABILITY INFORMATION (lines 7915–7923), the §1.2 role list that names system administrators (line 1462), and MP-5(3) CUSTODIANS (lines 11882–11887).
  • NIST — SP 800-53A Rev. 5, Assessing Security and Privacy Controls — https://doi.org/10.6028/NIST.SP.800-53Ar5 — the assessment procedures that number the two enhancements used here: CM-08(04) ACCOUNTABILITY INFORMATION (line 12953) and MP-05(03) CUSTODIANS (line 20152).
  • NIST — SP 800-12 Rev. 1, An Introduction to Information Security — https://doi.org/10.6028/NIST.SP.800-12r1 — §3.4 Information Owner/Steward, the role definition quoted in the body (lines 915–919).
  • NIST — SP 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations — https://doi.org/10.6028/NIST.SP.800-37r2 — the access-decision sentence and the coordination with the information owner/steward (lines 7851–7852), footnote 121 on the program manager / business-asset-owner title variants (line 7863), footnote 122 (lines 7865–7866) and footnote 123 on the designated individual (lines 7868–7870).
  • NIST — SP 800-39, Managing Information Security Risk — https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf — footnote 73 on the system owner as focal point and the owners of components, of information and of mission and business functions (lines 4382–4386).
  • NIST — SP 800-100, Information Security Handbook: A Guide for Managers — https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-100.pdf — §8.2.2 information system owner (lines 4013–4030), §8.2.3 information owner (lines 4032–4046), §8.2.5 ISSO (lines 4078–4082), footnote 57 on the title variants (lines 4052–4053) and footnote 58 on shared information (lines 4055–4056).
  • NIST — SP 800-128, Guide for Security-Focused Configuration Management of Information Systems — https://doi.org/10.6028/NIST.SP.800-128 — §2.3.4 component inventory, including the one-component one-system-owner sentence (lines 1186, 1197–1199).
  • NIST — SP 800-88 Rev. 2, Guidelines for Media Sanitization — https://doi.org/10.6028/NIST.SP.800-88r2 — §4.7.2 the CIO as “information custodian” for sanitisation policy (line 1509).
  • NIST — SP 800-161r1-upd1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations — https://doi.org/10.6028/NIST.SP.800-161r1-upd1 — the MP-5 supplemental C-SCRM guidance naming “approved custodian services” for media transport and storage (line 6523). The archived SP 800-161 Rev. 1 (5 May 2022, withdrawn by NIST on 1 November 2024) carries the same sentence at its line 6086; only the current update is cited.
  • NIST — NISTIR 8286r1, Integrating Cybersecurity and Enterprise Risk Management (ERM) — https://doi.org/10.6028/NIST.IR.8286r1 — the metaphor “receiving custodians of the risk management discipline” (line 596).
  • NIST — The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 — https://doi.org/10.6028/NIST.CSWP.29 — GV.RR-02, roles, responsibilities and authorities established, communicated, understood and enforced (line 795).
  • NIST — SP 800-12 (October 1995), An Introduction to Computer Security: The NIST Handbook — superseded (withdrawn 21 June 2017 by SP 800-12 Rev. 1) — https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-12.pdf — the legacy wording that uses “custodian” as an asset role (lines 10380, 10397) and “data owner” (line 1396); quoted only as legacy vocabulary, never as current guidance.

The register with what each source supports, how it was read and which pointers were corrected is in