Asset & Data Management · AD-Q09

Question: Are data owners and custodians formally assigned with a documented lifecycle (create, use, share, store, archive, dispose)?

Objective — Why This Matters

Clear ownership ensures decisions are made by accountable people and that lifecycle rules are applied consistently. Without owners and lifecycle stages, controls drift, data proliferates, and obligations are missed.

Maturity Levels (0–5)

0 — Unaware
No defined data owners; lifecycle unmanaged.
1 — Ad Hoc
Some teams know who to ask; lifecycle is implied, not documented.
2 — Defined
RACI established for key data domains; lifecycle policy approved.
3 — Managed
Owners listed in inventory; lifecycle checkpoints enforced (creation, sharing, archiving, disposal).
4 — Integrated
Lifecycle embedded in systems and workflows; exceptions time-bound and approved.
5 — Optimized
Lifecycle effectiveness reviewed; metrics reduce orphaned or stale data.

How to Level Up

From → To Actions
0 → 1 Nominate data owners for top domains (customer, employee, finance, product).
1 → 2 Approve lifecycle policy with entry/exit criteria and disposal methods.
2 → 3 Link owners and lifecycle stage to the data inventory; add creation and disposal checkpoints.
3 → 4 Automate lifecycle steps in systems (retention, archive rules, sharing approvals).
4 → 5 Review lifecycle outcomes quarterly; remove redundant, obsolete, trivial data.

People / Process / Technology Enablers

Evidence Required

Metrics / KPIs

Low-Cost / Open-Source Options (MSME)

Purpose Tool Notes
RACI & policy Markdown in Git Version history and approvals.
Inventory Sheets / Airtable Add owner, custodian, lifecycle stage.
Automation Cloud lifecycle rules Auto-archive and expire objects.

Common Pitfalls

Compliance Mapping

Standard Clauses / Notes
ISO/IEC 27001 A.5.9 (asset ownership), A.5.12 (retention).
NIST CSF 2.0 ID.AM, PR.DS-5.
DPDP Act 2023 Storage limitation, accountability.
NIRMATA Scoring AD-Q09 Level ≥3 requires owners in inventory + lifecycle checkpoints evidence.