business owner
An organizational role (not a job title) assigned to a senior official who holds accountability for one or more missions, business functions, or business processes that one or more information systems are built to support. In the NIST Risk Management Framework, the business owner is responsible for defining the mission and business functions and processes that a system is intended to support, and assists in developing organization-wide tailored control baselines. Mission or business owners coordinate with authorizing officials, system owners, and security and privacy officers to ensure that security and privacy requirements flow into organizational procurements and acquisitions. In practice the role is used to anchor risk decisions to organizational impact — the business owner is the party who can articulate what harm to the supported mission or function actually means in operational and strategic terms, and who therefore participates in risk acceptance alongside (but distinctly from) the system owner and authorizing official.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- An organizational role (not a job title) assigned to a senior official who holds accountability for one or more missions, business functions, or business processes that one or more information systems are built to support. In the NIST Risk Management Framework, the business owner is responsible for defining the mission and business functions and processes that a system is intended to support, and assists in developing organization-wide tailored control baselines. Mission or business owners coordinate with authorizing officials, system owners, and security and privacy officers to ensure that security and privacy requirements flow into organizational procurements and acquisitions. In practice the role is used to anchor risk decisions to organizational impact — the business owner is the party who can articulate what harm to the supported mission or function actually means in operational and strategic terms, and who therefore participates in risk acceptance alongside (but distinctly from) the system owner and authorizing official.DR-088 backfill from the noun definition column