CGRC · Question #121
Who has primary responsibility for the implementation of security controls? Response:
The correct answer is A. Information System Owner (ISO). The Information System Owner (ISO) bears the primary responsibility for ensuring the proper implementation and operation of security controls within an information system.
Question
Who has primary responsibility for the implementation of security controls? Response:
Options
- AInformation System Owner (ISO)
- BInformation System Security Engineer
- CSystem Administrator
- DAuthorizing Official (AO)
How the community answered
(50 responses)- A92% (46)
- B2% (1)
- C4% (2)
- D2% (1)
Why each option
The Information System Owner (ISO) bears the primary responsibility for ensuring the proper implementation and operation of security controls within an information system.
The Information System Owner (ISO) is accountable for the system throughout its lifecycle, including ensuring that security controls are properly implemented, operated, and maintained to meet security requirements. While other roles assist, the ISO has the ultimate primary responsibility for these actions.
An Information System Security Engineer designs and implements security solutions but does not hold primary responsibility for the overall implementation of controls across the system's lifecycle.
A System Administrator is responsible for the technical operation and maintenance of systems, including some security controls, but not the overarching primary responsibility for their implementation.
The Authorizing Official (AO) makes the risk-based decision to authorize a system's operation but does not have primary responsibility for the hands-on implementation of security controls.
Concept tested: Roles in security control implementation
Source: https://csrc.nist.gov/pubs/sp/800/37/r2/archive/toc
Topics
Community Discussion
No community discussion yet for this question.