A control owner is accountable for the ongoing operation and review of a security control.
Ownership does not mean the person performs every task. A control owner may coordinate IT, security, operations, HR, procurement, or a service provider, but should be able to explain:
- What the control is intended to achieve
- Who performs the related work
- What evidence shows it is working
- How often it is reviewed
- What happens when there is a gap
Assigning a real role is more useful than naming a fictional department or using a shared label such as “the business.” For a practical model, see ISO 27001 control ownership: how to assign accountability.
