Business/mission owner
The senior official accountable for a line of business or a mission, who defines what its supporting systems and data must achieve and weighs their protection against business need.
Full guide: Data Security Roles: Owner, Custodian, Controller and Processor for CISSP
The business or mission owner is the executive accountable for a business function or, in government, a mission. NIST SP 800-37 Rev. 2 describes the mission or business owner as a senior official with specific mission or line-of-business responsibilities and a security or privacy interest in the systems that support them. The role decides what those systems must do, supplies the business view of impact during categorisation and business impact analysis, and balances the cost of protection against the needs of the function.
The role is broader than the more specific ownership roles, and in a smaller organisation one manager may hold several of them. The data owner is accountable for a particular data set and the system owner for a particular system; the business or mission owner is accountable for the process those serve. In commercial practice the business owner is commonly the role that weighs delivery against security and accepts the resulting risk, advised by the security function, which informs the decision but does not own it. In the NIST Risk Management Framework, formal acceptance of a system’s risk rests with the authorizing official, a role the mission or business owner may also hold.
Exam relevance: a scenario is likely to turn on who decides versus who advises or implements. Candidates are expected to place business and mission owners with data and system owners on the accountable side, and security teams and data custodians on the advising and implementing side.