CAP · Question #239
The Information System Security Officer (ISSO) and Information System Security Engineer (ISSE) play the role of a supporter and advisor, respectively. Which of the following statements are true…
The correct answer is C. An ISSE provides advice on the continuous monitoring of the information system. D. An ISSE provides advice on the impacts of system changes. E. An ISSO manages the security of the information system that is slated for Certification &. In the NIST/RMF framework: The ISSO (supporter role) is responsible for managing the day-to-day security of an information system, including overseeing its security posture through the C&A/authorization process-making E correct. The ISSE (advisor role) provides security…
Question
The Information System Security Officer (ISSO) and Information System Security Engineer (ISSE) play the role of a supporter and advisor, respectively. Which of the following statements are true about ISSO and ISSE? Each correct answer represents a complete solution. Choose all that apply.
Options
- AAn ISSE manages the security of the information system that is slated for Certification &
- BAn ISSO takes part in the development activities that are required to implement system ch
- CAn ISSE provides advice on the continuous monitoring of the information system.
- DAn ISSE provides advice on the impacts of system changes.
- EAn ISSO manages the security of the information system that is slated for Certification &
How the community answered
(20 responses)- A5% (1)
- B5% (1)
- C90% (18)
Explanation
In the NIST/RMF framework: The ISSO (supporter role) is responsible for managing the day-to-day security of an information system, including overseeing its security posture through the C&A/authorization process-making E correct. The ISSE (advisor role) provides security engineering guidance and advice throughout the system lifecycle-this includes advising on continuous monitoring (C) and advising on the security impacts of proposed system changes (D). Option A is incorrect because managing the IS security is the ISSO's role, not the ISSE's. Option B is incorrect because it is the ISSE, not the ISSO, who participates in development and engineering activities to implement security controls.
Topics
Community Discussion
No community discussion yet for this question.