# Control Ownership Without Theatre

*@18xBan · GRC Series · Chapter 06*

![](https://cdn.hashnode.com/uploads/covers/6aa9ab6f5e60cef18e9a8e9b/874de28d-9c0f-41cc-87f2-9974c8bee5af.png align="center")

Eighteen controls on Wayne's list, and not one owner who'd been told.

* * *

## Monday, 9:05 AM: "Password resets are broken"

The first support ticket lands in Deskline at 9:05. By 9:40 there are 31.

Every one says the same thing: *I clicked "forgot password" and nothing arrived.*

Priya finds the cause in twenty minutes. MailRelay, the US service that sends Wayne's transactional email, stopped accepting Wayne's API key at midnight. The key was created in 2021.

Then she finds the warning. MailRelay sent it three weeks ago:

> *We're retiring API keys created before 2023. Rotate your key by Sunday or sending will stop.*

It went to `engineering@wayne-industries.example`, a distribution list with 14 people on it.

Fourteen people received it. Several opened it. Nobody acted, because everybody assumed somebody else would.

Priya rotates the key, and resets start working again at 10:12. Nothing leaked. Customers were just locked out for a morning.

At 10:30, Dan walks over.

"Who owns MailRelay?"

You open the flow register you finished last week. Flow F4, transactional email to MailRelay, has a name in the owner column. But that owner decides *whether* customer data should go to MailRelay. Nobody owns the running of it: the key, the vendor notices, the renewal.

So you go looking for every other place Wayne has a name that doesn't mean anything.

![](https://cdn.hashnode.com/uploads/covers/6aa9ab6f5e60cef18e9a8e9b/7e29af00-cf60-42e7-add0-5d8fcc66ced1.png align="center")

Monday morning: 31 tickets, one expired key, and a warning 14 people saw.

* * *

## Everyone owns it, so nobody does

Think of the sink in an office kitchen.

The mugs belong to everyone. So the pile grows until one person snaps and washes the lot. Then it builds up again, because nothing changed.

Security controls work the same way. A **control** is anything that reduces a risk: a setting, a process, a review. A control with "everyone" as its owner is that sink.

Psychologists call it the **bystander effect**: the more people who could act, the less likely any one of them does. A distribution list is a bystander machine.

That's what this post is about. The goal isn't a matrix with a name in every cell. It's a name that changes what happens when something goes wrong.

![](https://cdn.hashnode.com/uploads/covers/6aa9ab6f5e60cef18e9a8e9b/2906ba20-b05e-4e3f-a7d8-d619f0ee00b8.png align="center")

Everyone's mugs, nobody's dishes.

**The unpopular truth:** a team is not an owner. "Engineering," "IT" and "Security" can't be held accountable, can't be interviewed and can't reply to an email. If a cell needs a group name to look full, it's empty.

* * *

## Wayne's list, honestly

You export Wayne's control list. It has 18 rows: the fixes and checks that came out of the first five weeks of this program. Each row has a "responsible" column that somebody filled in, mostly Dan, back when the goal was "don't leave it blank."

Here's the count.

```bash
csvcut -c "Current Roles and Responsibilities" wayne-csf-profile-current.csv \
  | tail -n +2 | sort | uniq -c | sort -rn
```

```plaintext
     11 Dan Okafor
      4 Security
      1 Engineering
      1 Everyone
      1 ""
```

*Sample output (illustrative). Wayne Industries is fictional.*

`csvcut` comes from csvkit, a free set of command-line CSV tools. It handles commas inside fields, which a plain `cut` doesn't.

Read those five lines again:

*   **Dan: 11.** The CTO, who also runs engineering, hiring and the AWS bill.
    
*   **"Security": 4.** That's you. There is one of you.
    
*   **"Engineering" and "Everyone": 2.** Nobody.
    
*   **Blank: 1.** Contractor VPN access after offboarding. It's been on Dan's worry thread since 2022.
    

**The unpopular truth:** if the CTO owns everything, the CTO owns nothing. A name repeated eleven times is a default, not a decision.

* * *

## Owner, operator, backup: three different jobs

Most ownership confusion comes from one word doing three jobs.

| Role | What they do | Wayne example (backups) |
| --- | --- | --- |
| **Control owner** | Accountable for the control working. Makes sure it's designed right, checks it actually runs, signs off the evidence, and escalates when it fails. | Priya Nair |
| **Control operator** | Does the work: runs the job, performs the review, clicks the button. | The developer on the weekly rotation |
| **Backup owner** | Steps in when the owner is away or leaves. | You |
| **Risk owner** | Decides whether the leftover risk is acceptable. Usually more senior. | Dan Okafor (confirmed in Evidence #1) |

The owner and operator can be the same person at a small company. They just shouldn't be the same person *by accident*.

You may know this as a **RACI** matrix: Responsible, Accountable, Consulted, Informed. RACI is a common project-management convention, not a security standard. Its one rule matters most: **exactly one A per row.** Two A's means two people who can each assume the other has it. That's how the MailRelay email died.

![](https://cdn.hashnode.com/uploads/covers/6aa9ab6f5e60cef18e9a8e9b/2f8f8607-92a3-4136-addf-ab662b9fda69.png align="center")

Three jobs, three names, one A per row.

* * *

## The four-question test

A name in a cell is theatre until it passes four questions. Ask them out loud, to the person, not to the spreadsheet.

1.  **Do they know?** Can the owner name the control without looking it up?
    
2.  **Can they act?** Do they have the access, authority and budget to fix it when it breaks?
    
3.  **Do they have time?** Is it realistic next to their actual job?
    
4.  **Will they notice?** When the control fails, does a signal reach *them* rather than a shared inbox?
    

You book 15 minutes with Dan and read him his eleven rows.

He recognizes four. For three more, he says, "I think Priya does that." For the other four, he laughs.

That's not a failing on Dan's part. Nobody asked him. Someone typed his name because a CTO sounded safe.

![](https://cdn.hashnode.com/uploads/covers/6aa9ab6f5e60cef18e9a8e9b/45f0c52d-87c9-4afc-8aff-24ec0bf280f0.png align="center")

Knows, can act, has time, will notice. Miss one and it's theatre.

![](https://cdn.hashnode.com/uploads/covers/6aa9ab6f5e60cef18e9a8e9b/8ba2ab0c-6c5c-4cac-b0c2-4d3581d40a5a.png align="center")

Eleven rows with Dan's name. He recognized four.

* * *

## Finding the bystander inboxes

The MailRelay notice went to a list with no owner. How many more are there?

Wayne's distribution lists live in Active Directory. AD groups have a `managedBy` attribute, which records who manages the group. You check the engineering list first.

```powershell
Get-ADGroup -Identity "engineering" -Properties mail, managedBy, member |
  Select-Object Name, mail, managedBy, @{n='Members';e={$_.member.Count}}
```

```plaintext
Name        mail                                  managedBy Members
----        ----                                  --------- -------
engineering engineering@wayne-industries.example                 14
```

*Sample output (illustrative). Wayne Industries is fictional.*

Empty. Then every mail-enabled group with no manager:

```powershell
Get-ADGroup -Filter 'mail -like "*"' -Properties mail, managedBy |
  Where-Object { -not $_.managedBy } |
  Select-Object Name, mail
```

```plaintext
Name              mail
----              ----
engineering       engineering@wayne-industries.example
all-staff         all-staff@wayne-industries.example
aws-notifications aws-notifications@wayne-industries.example
billing           billing@wayne-industries.example
it-alerts         it-alerts@wayne-industries.example
vendor-accounts   vendor-accounts@wayne-industries.example
```

*Sample output (illustrative). Wayne Industries is fictional.*

These commands need the ActiveDirectory PowerShell module (part of RSAT) and read access to the directory.

Six lists. Two of them, `aws-notifications` and `vendor-accounts`, are exactly where security and vendor warnings arrive.

Setting `managedBy` doesn't fix anything by itself. It's a pointer. The fix is that each list now has a named person who reads it, and each vendor account in the register has a named contact.

* * *

## The template: NIST's CSF 2.0 Organizational Profile

You don't need to invent an ownership matrix. NIST publishes one inside a bigger tool.

The **CSF 2.0 Organizational Profile template** is a free spreadsheet from NIST. It's built for comparing where you are (Current Profile) with where you want to be (Target Profile), outcome by outcome. Among its columns are **Current Roles and Responsibilities** and **Target Roles and Responsibilities**. That's your ownership matrix, sitting next to the status and evidence for each outcome.

Get it from the "CSF 2.0 Profiles" page on NIST's Cybersecurity Framework site, where it's listed as the Organizational Profile template (XLSX). NIST's Quick Start Guide for creating profiles walks through filling it in.

https://www.nist.gov/cyberframework/profiles : NIST CSF 2.0 Profiles page

https://www.nist.gov/cyberframework/quick-start-guides : NIST SP 1301, CSF 2.0 Organizational Profiles Quick Start Guide

NIST says to customize the template. Wayne adds four columns to the Target side: **Owner**, **Operator**, **Backup**, and **Owner acknowledged**. One name per cell, no teams.

### Field by field

| Column | What goes in it | Wayne tip |
| --- | --- | --- |
| CSF Outcome | The subcategory ID, e.g. PR.DS-11 | One outcome per row. Wayne's 18 rows cover the outcomes its fixes touch. |
| CSF Outcome Description | NIST's wording for the outcome | Copy it; don't paraphrase. |
| Included in Profile? | Yes or no | Wayne's "no" rows keep a one-line rationale. |
| Rationale | Why it's in or out | "Gotham Mutual asks" is a valid reason. |
| Current Status | Whether the outcome is achieved today, and how well | Honest words: "not done," "partial," "done, not proven." |
| Current Roles and Responsibilities | Who does it today | This is where the theatre was. |
| Current Artifacts and Evidence | What proves it today | Blank is a finding, not a formatting problem. |
| Target Roles and Responsibilities | Who should do it | Wayne splits this into the four added columns below. |
| Owner *(added)* | One accountable person | Must pass the four questions. |
| Operator *(added)* | Who performs it | A person or a named rotation. |
| Backup *(added)* | Who covers | Never the same person as the owner. |
| Owner acknowledged *(added)* | Date the owner replied "I accept" | No date means no owner. |
| Notes | Anything else | Wayne records the signal: where failures get reported. |

### Wayne before

| CSF Outcome | Current Status | Current Roles and Responsibilities | Current Artifacts and Evidence |
| --- | --- | --- | --- |
| GV.SC-02: roles for suppliers | Not done | Engineering | None |
| PR.DS-11: backups created, protected, maintained, tested | Partial | Dan Okafor | 412 job logs, 0 restore tests |
| PR.AA-03: users, services and hardware authenticated | Partial | Security | MFA on about 30% of accounts |
| PR.AA-05: access permissions managed and reviewed | Not done | *(blank)* | None |
| PR.PS-01: configuration management practices applied | Not done | Dan Okafor | None |
| DE.CM-09: computing, runtime and data monitored | Not done | Everyone | CloudTrail on, unread |

### Wayne after

| CSF Outcome | Owner | Operator | Backup | Owner acknowledged | Notes |
| --- | --- | --- | --- | --- | --- |
| GV.SC-02 | Priya Nair | Priya Nair | Dan Okafor | Tue | Vendor notices now go to `vendor-accounts`, managed by Priya. Each vendor has a named contact. |
| PR.DS-11 | Priya Nair | Weekly dev rotation | You | Tue | Failed jobs page the rotation, not a list. |
| PR.AA-03 | You | You | Dan Okafor | Tue | Owner and operator are the same person. Accepted for now, flagged. |
| PR.AA-05 | Farah Haddad | You | Dan Okafor | Wed | Offboarding starts in People & Ops, so the trigger sits with Farah. You remove VPN access. |
| PR.PS-01 | Priya Nair | GitLab Maintainers | Dan Okafor | Tue | Covers merge approvals on `main`. |
| DE.CM-09 | You | You, weekly | Priya Nair | Tue | Weekly CloudTrail review, logged. |

The after table doesn't say any of these controls work yet. Backups are still untested. MFA is still at 30%. What changed is that each gap now has one person who knows it's theirs.

After the change, the count across all 18 rows looks like this:

```bash
csvcut -c "Owner" wayne-csf-profile-target.csv \
  | tail -n +2 | sort | uniq -c | sort -rn
```

```plaintext
      6 Priya Nair
      6 You (Head of Security)
      3 Dan Okafor
      2 Farah Haddad
      1 Maya Lindqvist
```

*Sample output (illustrative). Wayne Industries is fictional.*

Dan keeps three rows he actually decides: risk acceptance, the AWS account structure, and security resourcing (GV.RR-03). Maya keeps one: leadership accountability (GV.RR-01), which is hers whether she likes it or not. Farah Haddad, who leads People & Operations, takes offboarding and security in HR practices (GV.RR-04).

![](https://cdn.hashnode.com/uploads/covers/6aa9ab6f5e60cef18e9a8e9b/15177171-1fe8-4cf7-88e1-dba3bc590667.png align="center")

The same six rows, before and after. Names changed; status didn't. Proving the controls work is a separate job.

**The unpopular truth:** most ownership matrices are written for the auditor, not for the people named in them. If the owners have never seen the sheet, it's a costume.

* * *

## Evidence #6

Getting names isn't enough. You need proof the names know.

On Tuesday you send each owner their rows, one email each:

> *You're listed as owner for the controls below. Owner means you're accountable for them working, you'll get the failure alerts, and you'll sign off the evidence. Reply "I accept," or tell me what's wrong with the assignment.*

Priya, Dan and Maya reply "I accept" on Tuesday. Farah replies Wednesday with a question: does "owner" mean she removes VPN access herself? No. She owns the trigger; you do the removal. She accepts.

Dan pushed back on one row and moved it to Priya. That's the process working.

On Friday, Dan approves the Target Profile. The sheet, the four acknowledgment emails, your own signed note for your rows, and the `managedBy` changes go in the evidence folder together.

**Evidence #6:** dated, named and acknowledged ownership for all 18 controls.

![](https://cdn.hashnode.com/uploads/covers/6aa9ab6f5e60cef18e9a8e9b/25c63ba6-dea7-4e24-838e-2c0ad6c59591.png align="center")

Four replies, one approval, one folder.

* * *

## What an auditor accepts vs rejects

ISO 27001 auditors and SOC 2 auditors both test ownership the same way: they read the document, then interview the person.

| Accepted | Rejected |
| --- | --- |
| A named individual with a role title | A team, department or distribution list |
| A dated acknowledgment from the owner | A name the owner has never seen |
| An owner who can explain the control in an interview | An owner who says, "I think Priya does that" |
| A named backup who isn't the owner | Nobody listed for leave or departure |
| Evidence signed off by the owner | Evidence nobody reviewed |
| A matrix reviewed after the last reorg | Owners who left the company |
| One person with many rows, and a note on how they cope | One person on most rows, with no comment |

![](https://cdn.hashnode.com/uploads/covers/6aa9ab6f5e60cef18e9a8e9b/cc92ec2b-598d-4c67-a17c-c71e7715058f.png align="center")

"Engineering." "Which person?"

* * *

## What you actually do on Monday

1.  **Export your control list and count the names,** like the `uniq -c` above. Anything over a third of the rows on one person needs a conversation.
    
2.  **Replace every team name with a person.** If you can't pick one, you've found a real gap.
    
3.  **Run the four questions** with each owner. Fifteen minutes each is enough.
    
4.  **Find your bystander inboxes.** Check every shared list that receives vendor, cloud or security email, and give each one a named reader.
    
5.  **Get written acknowledgment.** A one-line "I accept" reply is evidence. Silence isn't.
    
6.  **Set review triggers.** Revisit the matrix when someone changes role or leaves, and at least once a year.
    

* * *

## Framework mapping

![](https://cdn.hashnode.com/uploads/covers/6aa9ab6f5e60cef18e9a8e9b/d4b3d75f-3f8d-4b05-be7a-a1ec0fbf705c.png align="center")

Ownership, as each framework puts it.

* * *

## Maturity ladder

| Stage | 20 people | 200 people | 2,000 people |
| --- | --- | --- | --- |
| **Who owns** | The founder or CTO for most things, and that's honest | Named owners across engineering, ops and People, one A per row | Owners per business unit, with a second line checking them |
| **Where it lives** | A spreadsheet with one owner column | The CSF profile or a GRC tool, with owner, operator and backup | A GRC platform tied to the HR system, so leavers are flagged automatically |
| **Proof** | An "I accept" email | Dated acknowledgments, reviewed after role changes | Annual attestation campaigns, with interview samples by internal audit |
| **Signals** | Alerts go to the founder's phone | Alerts route to the named owner or rotation | Ownership drives ticket routing and escalation paths |
| **Failure mode** | One person burns out | Team names creep back in | Owners on paper who've never seen the control |

At 20 people, a spreadsheet with the same name on every row is fine *if that person knows and agreed*. The problem is never the spreadsheet. It's the name nobody asked.

**Where Wayne sits:** at the 200-person stage on paper, as of Friday. Every row has one owner, an operator, a backup and a date. What's untested is whether the signals really reach the owners. The next vendor notice will show whether `vendor-accounts` works.

* * *

## Cheatsheet

![](https://cdn.hashnode.com/uploads/covers/6aa9ab6f5e60cef18e9a8e9b/46e76f66-1a0f-4c7e-bd90-eba0c8dc8a2a.png align="center")

Control ownership, on one page.

* * *

## The takeaway

A name in a cell is not ownership. A person who knows, can act, has time and gets the alert is. One accountable person per control. Teams and inboxes don't count. Get it in writing: a dated "I accept" beats a full matrix. Spread the load honestly, and write down where one person still carries too much.

* * *

> ⚠️ This content is for educational purposes only. Wayne Industries is a fictional company. Nothing here is legal, audit, or compliance advice, validate against your own auditor and jurisdiction.
