1
1

00:00:00,510  -->  00:00:02,100
<v Instructor>Data ownership.</v>
2

2

00:00:02,100  -->  00:00:05,280
In this lesson, we are going to talk about data ownership
3

3

00:00:05,280  -->  00:00:07,890
and some of the things that are important inside of it.
4

4

00:00:07,890  -->  00:00:09,690
Now, when we talk about data ownership
5

5

00:00:09,690  -->  00:00:12,750
this is the process of identifying the person responsible
6

6

00:00:12,750  -->  00:00:15,480
for the confidentiality, integrity, availability
7

7

00:00:15,480  -->  00:00:18,150
and privacy of the information assets.
8

8

00:00:18,150  -->  00:00:19,740
Now, you might think that the data owner
9

9

00:00:19,740  -->  00:00:21,480
is the person who created that file,
10

10

00:00:21,480  -->  00:00:23,430
but that's not what we're talking about.
11

11

00:00:23,430  -->  00:00:25,800
In an enterprise environment there are different roles
12

12

00:00:25,800  -->  00:00:28,500
that fall under this idea of data ownership.
13

13

00:00:28,500  -->  00:00:30,990
These include things like the data owner themself,
14

14

00:00:30,990  -->  00:00:33,330
the data steward, the data custodian,
15

15

00:00:33,330  -->  00:00:35,070
and the privacy officer.
16

16

00:00:35,070  -->  00:00:36,780
Let's take a look at each of these.
17

17

00:00:36,780  -->  00:00:38,790
First we have our data owner.
18

18

00:00:38,790  -->  00:00:41,280
This is going to be a senior executive role
19

19

00:00:41,280  -->  00:00:43,050
and they have the ultimate responsibility
20

20

00:00:43,050  -->  00:00:45,390
for maintaining the confidentiality, integrity,
21

21

00:00:45,390  -->  00:00:48,210
and availability of the information asset.
22

22

00:00:48,210  -->  00:00:51,630
So, what is their real role here as the data owner?
23

23

00:00:51,630  -->  00:00:53,340
It's not the person who created the file,
24

24

00:00:53,340  -->  00:00:54,930
it's this senior executive.
25

25

00:00:54,930  -->  00:00:56,820
And this data owner is going to be responsible
26

26

00:00:56,820  -->  00:00:58,590
for labeling the asset and ensuring
27

27

00:00:58,590  -->  00:01:01,170
that it's protected with the appropriate controls.
28

28

00:01:01,170  -->  00:01:04,920
So the data owner is going to say, this type of information
29

29

00:01:04,920  -->  00:01:06,330
when we're dealing with, let's say
30

30

00:01:06,330  -->  00:01:08,310
the balance sheets for the corporation
31

31

00:01:08,310  -->  00:01:11,130
they should be protected as financial information.
32

32

00:01:11,130  -->  00:01:13,680
So anybody who creates it will now follow my rules
33

33

00:01:13,680  -->  00:01:15,780
and label it as financial information.
34

34

00:01:15,780  -->  00:01:17,580
And we are going to protect financial information
35

35

00:01:17,580  -->  00:01:21,150
by doing X, Y, and Z, whatever those controls are.
36

36

00:01:21,150  -->  00:01:23,340
Now, the data steward is a role that's focused
37

37

00:01:23,340  -->  00:01:26,490
on the quality of the data and the associated metadata.
38

38

00:01:26,490  -->  00:01:28,140
This data steward is going to be somebody
39

39

00:01:28,140  -->  00:01:30,570
who is working for the data owner.
40

40

00:01:30,570  -->  00:01:33,000
They're going to be involved with making sure
41

41

00:01:33,000  -->  00:01:36,000
that the data is appropriately labeled and classified.
42

42

00:01:36,000  -->  00:01:38,490
So, we said that all financial data
43

43

00:01:38,490  -->  00:01:40,200
should be labeled financial data
44

44

00:01:40,200  -->  00:01:41,910
and it should be taken care of this way.
45

45

00:01:41,910  -->  00:01:43,470
That's going to be the role of the data steward
46

46

00:01:43,470  -->  00:01:45,570
to make sure that's actually done.
47

47

00:01:45,570  -->  00:01:47,250
Now, as we go down even further
48

48

00:01:47,250  -->  00:01:49,260
we get to our data custodian.
49

49

00:01:49,260  -->  00:01:51,150
This is a role that's responsible for handling
50

50

00:01:51,150  -->  00:01:52,380
the management of the system
51

51

00:01:52,380  -->  00:01:54,450
on which the data assets are stored.
52

52

00:01:54,450  -->  00:01:56,790
So, who might be a data custodian?
53

53

00:01:56,790  -->  00:01:58,680
Well, a system administrator.
54

54

00:01:58,680  -->  00:02:00,480
These are the people responsible for enforcing
55

55

00:02:00,480  -->  00:02:03,030
the access control, the encryption, and the backup
56

56

00:02:03,030  -->  00:02:05,700
and recovery measures that protect this data
57

57

00:02:05,700  -->  00:02:08,850
based on the requirements set forth by that data owner.
58

58

00:02:08,850  -->  00:02:12,180
And so you can see how this all goes upward as you go.
59

59

00:02:12,180  -->  00:02:13,920
Then we have our privacy officer.
60

60

00:02:13,920  -->  00:02:16,590
Now, this is a role that's responsible for the oversight
61

61

00:02:16,590  -->  00:02:18,780
of any kind of privacy related data.
62

62

00:02:18,780  -->  00:02:22,770
Things like PII, SPI, or PHI, any of those things
63

63

00:02:22,770  -->  00:02:24,870
that are managed by the company fall under the realm
64

64

00:02:24,870  -->  00:02:26,250
of the privacy officer.
65

65

00:02:26,250  -->  00:02:28,020
This is the person who's going to really be on the hook
66

66

00:02:28,020  -->  00:02:29,070
if you have a data breach,
67

67

00:02:29,070  -->  00:02:30,990
because normally when you have a data breach,
68

68

00:02:30,990  -->  00:02:32,100
what people are concerned about
69

69

00:02:32,100  -->  00:02:34,710
is the private user data that has been expelled.
70

70

00:02:34,710  -->  00:02:36,720
And so that is going to be what they're focused on.
71

71

00:02:36,720  -->  00:02:38,160
They have to make sure that we are complying
72

72

00:02:38,160  -->  00:02:40,230
with the legal and regulatory frameworks
73

73

00:02:40,230  -->  00:02:41,670
and make sure that we have the right purpose,
74

74

00:02:41,670  -->  00:02:43,110
limitations, and consent,
75

75

00:02:43,110  -->  00:02:45,360
we're doing data minimization, data sovereignty,
76

76

00:02:45,360  -->  00:02:47,580
data retention, all the stuff we've been talking about
77

77

00:02:47,580  -->  00:02:50,910
in this section falls under that privacy officer.
78

78

00:02:50,910  -->  00:02:54,000
Now, the real question is who should own the data?
79

79

00:02:54,000  -->  00:02:55,470
Now, in a lot of organizations
80

80

00:02:55,470  -->  00:02:58,440
they try to make the CIO or the IT department
81

81

00:02:58,440  -->  00:03:01,740
be in charge of all the information and be the data owners.
82

82

00:03:01,740  -->  00:03:05,430
But that is the wrong answer because as the IT personnel
83

83

00:03:05,430  -->  00:03:08,580
we don't know about the data, we know about the systems.
84

84

00:03:08,580  -->  00:03:10,860
We should be the data custodians.
85

85

00:03:10,860  -->  00:03:13,260
Instead, the data owners should be somebody
86

86

00:03:13,260  -->  00:03:15,330
from the business side, the people who are
87

87

00:03:15,330  -->  00:03:16,980
creating this information.
88

88

00:03:16,980  -->  00:03:19,500
And each data owner can actually be specified
89

89

00:03:19,500  -->  00:03:21,300
inside their own departments.
90

90

00:03:21,300  -->  00:03:23,880
So for instance, you might have the accounting department
91

91

00:03:23,880  -->  00:03:26,100
have their leader be the data owner
92

92

00:03:26,100  -->  00:03:28,650
and they would have a data owner over their information.
93

93

00:03:28,650  -->  00:03:30,960
Because if I, as the IT person,
94

94

00:03:30,960  -->  00:03:33,120
am looking at some accounting data,
95

95

00:03:33,120  -->  00:03:34,590
I don't know it well enough to be able
96

96

00:03:34,590  -->  00:03:36,540
to classify it at the right level.
97

97

00:03:36,540  -->  00:03:37,770
And so this is one of those things
98

98

00:03:37,770  -->  00:03:39,030
that I think is really important
99

99

00:03:39,030  -->  00:03:42,000
that the IT people should not be the data owners.
100

100

00:03:42,000  -->  00:03:44,010
And the data owners should really be the people
101

101

00:03:44,010  -->  00:03:45,630
who know more about the data
102

102

00:03:45,630  -->  00:03:47,490
based on the content of the company.
103

103

00:03:47,490  -->  00:03:49,680
If your company is a software development company
104

104

00:03:49,680  -->  00:03:51,210
then the software design department
105

105

00:03:51,210  -->  00:03:52,590
should probably be the data owner.
106

106

00:03:52,590  -->  00:03:53,820
If you're an accounting firm
107

107

00:03:53,820  -->  00:03:56,490
it should be the financial department or the CFO,
108

108

00:03:56,490  -->  00:03:58,200
somebody who knows about the data
109

109

00:03:58,200  -->  00:03:59,310
who can make the right decisions
110

110

00:03:59,310  -->  00:04:01,200
as far as labeling and classification,
111

111

00:04:01,200  -->  00:04:03,100
that is who should be your data owner.
