Cyber Risk Compendium

Control owner

The control owner is responsible for implementing and operating a specific Control on a day-to-day basis — for example, the person who configures and maintains a firewall ruleset or runs a phishing awareness programme.

Control owners report on the operating effectiveness of their control to the Stakeholders who imposed it, and flag when a control degrades or when an is needed. A single control may cover multiple risks, so the control owner's work often has an outsized effect on the organisation's overall risk posture.