nerdexam
(ISC)2

CGRC · Question #121

Who has primary responsibility for the implementation of security controls? Response:

The correct answer is A. Information System Owner (ISO). The Information System Owner (ISO) bears the primary responsibility for ensuring the proper implementation and operation of security controls within an information system.

Implementation of Security and Privacy Controls

Question

Who has primary responsibility for the implementation of security controls? Response:

Options

  • AInformation System Owner (ISO)
  • BInformation System Security Engineer
  • CSystem Administrator
  • DAuthorizing Official (AO)

How the community answered

(50 responses)
  • A
    92% (46)
  • B
    2% (1)
  • C
    4% (2)
  • D
    2% (1)

Why each option

The Information System Owner (ISO) bears the primary responsibility for ensuring the proper implementation and operation of security controls within an information system.

AInformation System Owner (ISO)Correct

The Information System Owner (ISO) is accountable for the system throughout its lifecycle, including ensuring that security controls are properly implemented, operated, and maintained to meet security requirements. While other roles assist, the ISO has the ultimate primary responsibility for these actions.

BInformation System Security Engineer

An Information System Security Engineer designs and implements security solutions but does not hold primary responsibility for the overall implementation of controls across the system's lifecycle.

CSystem Administrator

A System Administrator is responsible for the technical operation and maintenance of systems, including some security controls, but not the overarching primary responsibility for their implementation.

DAuthorizing Official (AO)

The Authorizing Official (AO) makes the risk-based decision to authorize a system's operation but does not have primary responsibility for the hands-on implementation of security controls.

Concept tested: Roles in security control implementation

Source: https://csrc.nist.gov/pubs/sp/800/37/r2/archive/toc

Topics

#Roles and Responsibilities#Information System Owner (ISO)#Security Control Implementation

Community Discussion

No community discussion yet for this question.

Full CGRC Practice