nerdexam
(ISC)2

CAP · Question #258

Which of the following professionals is responsible for starting the Certification & Accreditation (C&A) process?

The correct answer is A. Information system owner. The Information System Owner (A) is responsible for initiating the C&A process because they own and are accountable for the system requiring authorization. They compile the system security plan, coordinate with security personnel, and formally request the C&A review. The…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following professionals is responsible for starting the Certification & Accreditation (C&A) process?

Options

  • AInformation system owner
  • BAuthorizing Official
  • CChief Risk Officer (CRO)
  • DChief Information Officer (CIO)

How the community answered

(33 responses)
  • A
    85% (28)
  • B
    3% (1)
  • C
    6% (2)
  • D
    6% (2)

Explanation

The Information System Owner (A) is responsible for initiating the C&A process because they own and are accountable for the system requiring authorization. They compile the system security plan, coordinate with security personnel, and formally request the C&A review. The Authorizing Official (B) makes the final accreditation decision but does not start the process. The Chief Risk Officer (C) and Chief Information Officer (D) play governance and oversight roles but are not the initiating party for a specific system's C&A.

Topics

#C&A process initiation#Information system owner#RMF roles

Community Discussion

No community discussion yet for this question.

Full CAP Practice