nerdexam
(ISC)2

CAP · Question #200

Which of the following individuals is responsible for the final accreditation decision?

The correct answer is A. Information System Owner. In the context of this exam, the Information System Owner holds ultimate accountability for the system, including the final accreditation decision - the formal determination that the system is authorized to operate. The Certification Agent (also called Security Control…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following individuals is responsible for the final accreditation decision?

Options

  • AInformation System Owner
  • BCertification Agent
  • CUser Representative
  • DRisk Executive

How the community answered

(52 responses)
  • A
    94% (49)
  • C
    2% (1)
  • D
    4% (2)

Explanation

In the context of this exam, the Information System Owner holds ultimate accountability for the system, including the final accreditation decision - the formal determination that the system is authorized to operate. The Certification Agent (also called Security Control Assessor) conducts the technical evaluation but does not make the final authorization decision. The User Representative advocates for operational needs. The Risk Executive provides enterprise-wide risk oversight. Note: In modern NIST RMF terminology, the final authorization authority is called the Authorizing Official (AO); however, in some legacy frameworks and exam contexts, this authority is attributed to the Information System Owner as the individual bearing ultimate responsibility for the system's operation and its associated risks.

Topics

#RMF#Accreditation#Authorization Official#System Owner Responsibilities

Community Discussion

No community discussion yet for this question.

Full CAP Practice