nerdexam
(ISC)2

CAP · Question #323

Which of the following individuals is responsible for monitoring the information system environment for factors that can negatively impact the security of the system and its accreditation?

The correct answer is C. Information System Owner. The Information System Owner (ISO) is the individual responsible for the overall procurement, development, integration, modification, operation, maintenance, and retirement of an information system. Critically, the ISO is responsible for monitoring the system environment on an…

Compliance Maintenance

Question

Which of the following individuals is responsible for monitoring the information system environment for factors that can negatively impact the security of the system and its accreditation?

Options

  • AChief Risk Officer
  • BChief Information Security Officer
  • CInformation System Owner
  • DChief Information Officer

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    94% (29)

Explanation

The Information System Owner (ISO) is the individual responsible for the overall procurement, development, integration, modification, operation, maintenance, and retirement of an information system. Critically, the ISO is responsible for monitoring the system environment on an ongoing basis for any changes or factors that could affect system security or its accreditation status (e.g., new threats, vulnerabilities, or configuration changes). The Chief Information Security Officer (CISO) sets policy and oversees the organization's overall security posture. The Chief Information Officer (CIO) manages IT strategy. The Chief Risk Officer manages enterprise-level risk. None of these roles own the day-to-day system-level monitoring responsibility that belongs to the Information System Owner.

Topics

#System Owner responsibilities#Accreditation maintenance#Continuous monitoring

Community Discussion

No community discussion yet for this question.

Full CAP Practice