Data user

Anyone who accesses data to perform their job, bound by the acceptable use policy and by the handling requirements that follow from the data's classification.

Full guide: Data Security Roles: Owner, Custodian, Controller and Processor for CISSP

A data user is a person, or sometimes a process acting for one, who reads, creates or changes data in the course of their work. Their obligations are to use only the access they have been granted, to handle data according to the handling requirements its data classification imposes, to follow the acceptable use policy, and to report suspected misuse or incidents.

Users do not decide who gets access or how data is classified; that is the data owner. Nor do they run the protective controls, which is the data custodian’s work. A user’s access is shaped by least privilege and need to know, and it is checked through periodic access reviews. The ISC2 outline lists the role as “users/subjects” under objective 2.4, but a user and a data subject are different things: the user works with the data, while the subject is the individual that personal data describes. An employee can be both at once, as a user of the HR system and as a data subject in their own personnel record.

Exam relevance: a scenario is likely to describe an employee mishandling data or sharing it outside their role. Candidates are expected to recognise the user’s responsibility to follow policy, and to avoid answers that give users the owner’s authority over classification or access decisions.