nerdexam
(ISC)2

CAP · Question #34

Which of the following roles is also known as the accreditor?

The correct answer is C. Designated Approving Authority. The Designated Approving Authority (DAA) is the senior official with the authority and accountability to formally authorize (accredit) an information system to operate at an acceptable level of risk. The accreditor role specifically means the individual who signs the…

System Compliance

Question

Which of the following roles is also known as the accreditor?

Options

  • AChief Risk Officer
  • BData owner
  • CDesignated Approving Authority
  • DChief Information Officer

How the community answered

(50 responses)
  • A
    4% (2)
  • B
    8% (4)
  • C
    86% (43)
  • D
    2% (1)

Explanation

The Designated Approving Authority (DAA) is the senior official with the authority and accountability to formally authorize (accredit) an information system to operate at an acceptable level of risk. The accreditor role specifically means the individual who signs the Accreditation Decision-granting or denying authorization for a system to operate. The CIO manages overall IT strategy, the CRO manages enterprise risk, and the Data Owner is responsible for the classification and protection of specific data sets. None of these roles hold the formal accreditation authority that defines the DAA/accreditor role.

Topics

#RMF Roles#Designated Approving Authority#Accreditation#Authorization Official

Community Discussion

No community discussion yet for this question.

Full CAP Practice