System owner
The role accountable for an IT system or platform that stores or processes data, as distinct from the data owner, who is accountable for the information itself.
Full guide: Data Security Roles: Owner, Custodian, Controller and Processor for CISSP
The system owner is the role accountable for an information system and its security throughout its life. NIST SP 800-37 Rev. 2 describes the system owner as the official responsible for the system’s procurement, development, integration, modification, operation, maintenance and disposal, and for developing and maintaining its security and privacy plans in coordination with the security and privacy officers. The system owner makes sure the platform is operated in line with the controls its data requires.
The confusion to avoid is with the data owner, called the information owner in NIST terms. The data owner is accountable for the information, deciding its classification and who may access it; the system owner is accountable for the system that stores or processes it. The two are kept separate because they often do not align: one system can hold data from several owners, and one data set can span several systems. Day-to-day operation is commonly delegated to a data custodian or to system administrators, and a business or mission owner may be accountable for the business process the system supports.
Exam relevance: a scenario is likely to ask who should make sure a server meets the controls a classification requires, or who decides who may read the records on it. Candidates are expected to give decisions about the platform to the system owner and decisions about the data to the data owner.