CGRC · Question #205
Once the System Owner selects the controls he wants to Continuously Monitor, he should coordinate with AO, AODR, and ___________. Response:
The correct answer is A. CISO. The question asks who else a System Owner should coordinate with when selecting controls for continuous monitoring, in addition to the AO and AODR.
Question
Once the System Owner selects the controls he wants to Continuously Monitor, he should coordinate with AO, AODR, and ___________. Response:
Options
- ACISO
- BAODR
- CISSO
- DAO
How the community answered
(23 responses)- A87% (20)
- B4% (1)
- C9% (2)
Why each option
The question asks who else a System Owner should coordinate with when selecting controls for continuous monitoring, in addition to the AO and AODR.
When a System Owner selects controls for continuous monitoring, coordination with the Authorizing Official (AO), Authorizing Official Designated Representative (AODR), and the Chief Information Security Officer (CISO) is crucial. The CISO provides overarching strategic direction and ensures continuous monitoring aligns with the organization's enterprise-wide security posture and objectives.
AODR (Authorizing Official Designated Representative) is already listed in the question as a party to coordinate with.
The ISSO (Information System Security Officer) is involved in implementing and monitoring security, but the CISO holds higher-level executive responsibility for organizational security strategy and coordination.
AO (Authorizing Official) is already listed in the question as a party to coordinate with.
Concept tested: Roles and responsibilities in NIST RMF continuous monitoring
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.