Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Who should own data governance when CDO and…
Governance, Ownership & Risk

Who should own data governance when CDO and CISO responsibilities overlap in government?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

Data governance should be shared, but the responsibilities must be explicit. The CDO side typically drives data strategy, stewardship, and operational efficiency, while the CISO side focuses on risk, protection, and assurance. When those roles are aligned, organizations can make better decisions about data use, cloud adoption, and security controls without creating duplicated authority or blind spots.

Why shared ownership works better than a single owner

In government, data governance is rarely a clean handoff between the CDO and CISO. The CDO usually owns the policy, stewardship model, data quality expectations, and business value decisions; the CISO owns the protection model, control assurance, and risk acceptance boundaries. If one role is made singularly accountable, you usually get either weak governance or over-restricted data use.

The practical test is whether the organisation can define who decides on data classification, who approves use cases, who enforces controls, and who signs off exceptions. That division is what prevents duplicate authority, conflicting directives, and the common failure mode where data is “owned” in theory but unmanaged in practice.

When that split is written down clearly, the governance model becomes easier to operate across cloud platforms, shared services, and cross-department data exchange. The CDO can push for reuse and standardisation while the CISO ensures the same data is protected consistently as it moves across systems and trust boundaries.

Where CDO and CISO responsibilities overlap in practice

The overlap is usually not about who “owns” data as an asset, but who owns the decisions around it. Both roles have a stake in classification, retention, access controls, lineage, third-party sharing, and policy exceptions, but their decision lenses differ. The CDO asks whether the data supports the mission, reporting, and analytics model; the CISO asks whether the access path, handling, and oversight are safe enough.

That means some decisions should be joint by design. Data classification schemes, records retention rules, cloud sharing patterns, and exception handling are strongest when the CDO defines the business requirement and the CISO defines the control boundary. In contrast, day-to-day stewardship, metadata quality, and data domain ownership are usually better kept on the CDO side, with security standards and monitoring on the CISO side.

A useful way to reduce friction is to map each governance decision to one accountable owner and one required reviewer. For example, the CDO can own the “why and what” of the data, while the CISO owns the “how safely” and the conditions under which access or movement is allowed. NIST Privacy Framework is a useful reference point for this kind of data-centric governance, because it reinforces classification, risk management, and control selection around data use.

What good governance looks like in a government setting

Good governance is explicit, documented, and operational. The organisation should be able to show who owns the data policy, who approves exceptions, who monitors control effectiveness, and who escalates unresolved disagreements. If those answers vary by department, the overlap between CDO and CISO has become an accountability gap rather than a shared model.

At the practitioner level, the most important evidence is not a charter alone, but a working operating model: RACI, approval thresholds, review cadence, and escalation paths. That operating model should also cover cloud adoption and cross-agency data sharing, because those are the places where business pressure and security control decisions collide most often.

In practice, government teams often benefit from aligning the shared model with a formal control baseline so the CDO and CISO are not debating principles in isolation. Controls for access, auditability, configuration, and data protection should be anchored in a common assurance model such as NIST SP 800-53 Rev 5 Security and Privacy Controls, which gives both sides a common vocabulary for governance and enforcement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeShared data governance needs clear access boundaries and decision rights.
AU-6 — Audit Review, Analysis, and ReportingOverlapping governance roles require evidence of who approved data decisions and exceptions.
PL-2 — System and Communications Protection Policy and ProceduresGovernment data governance depends on documented policy, roles, and review procedures.
Recommendation — Assign least-privilege access and separate approval rights for data use exceptions. Review audit evidence to verify who approved classification, access, and exception decisions. Document data governance roles, responsibilities, and escalation paths in enforceable policy.
ISO/IEC 27001:2022A.5.15 — Access controlData governance overlap must resolve who authorizes and limits access to information assets.
A.5.34 — Privacy and protection of PIIGovernment data governance often includes privacy obligations and controlled data use.
Recommendation — Define access approval and review responsibilities between data and security owners. Align stewardship and security controls for personal and sensitive government data.

Practitioner Guidance

What to prioritise: Decide first who owns policy, who owns protection, and who owns exceptions. If those three are not separated, the overlap will turn into duplicated sign-off or, worse, gaps where neither side believes it must act.

What to verify: Check that the governance model names a single accountable owner for each decision type, not just for the data domain itself. The strongest test is whether a steward, a security reviewer, and an exception approver can all explain their role without conflicting.

Common mistake: Treating “shared ownership” as shared accountability for everything. That usually dilutes responsibility; the better model is shared governance with explicit decision rights, clear handoffs, and one final owner per decision.

Practitioner takeaway: In government, the CDO and CISO should share data governance, but not ambiguity. The model works only when business stewardship and security assurance are jointly designed, yet individually accountable.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org