nerdexam
(ISC)2

CGRC · Question #219

What are the responsibilities of a system owner? Each correct answer represents a complete solution. Choose all that apply. Response:

The correct answer is A. Integrates security considerations into application and system purchasing decisions and B. Ensures that the systems are properly assessed for vulnerabilities and must report any to the C. Ensures that adequate security is being provided by the necessary controls, password. System owners are responsible for integrating security into purchasing decisions, overseeing vulnerability assessments and reporting, and ensuring adequate security via necessary controls. They are key stakeholders for the overall security posture of their systems.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

What are the responsibilities of a system owner? Each correct answer represents a complete solution. Choose all that apply. Response:

Options

  • AIntegrates security considerations into application and system purchasing decisions and
  • BEnsures that the systems are properly assessed for vulnerabilities and must report any to the
  • CEnsures that adequate security is being provided by the necessary controls, password
  • DEnsures that the necessary security controls are in place.

How the community answered

(50 responses)
  • A
    94% (47)
  • D
    6% (3)

Why each option

System owners are responsible for integrating security into purchasing decisions, overseeing vulnerability assessments and reporting, and ensuring adequate security via necessary controls. They are key stakeholders for the overall security posture of their systems.

AIntegrates security considerations into application and system purchasing decisions andCorrect

The System Owner is responsible for ensuring that security requirements and considerations are incorporated into all application and system purchasing and acquisition decisions.

BEnsures that the systems are properly assessed for vulnerabilities and must report any to theCorrect

System Owners are accountable for ensuring that their systems are regularly assessed for vulnerabilities and that any identified findings are reported and addressed according to organizational policy.

CEnsures that adequate security is being provided by the necessary controls, passwordCorrect

System Owners must ensure that adequate security is provided for their information systems through the proper implementation and maintenance of necessary controls, including those related to password management and other security mechanisms.

DEnsures that the necessary security controls are in place.

While a System Owner is accountable for the overall security posture, the statement 'Ensures that the necessary security controls are in place' is a very broad responsibility that is implicitly covered by ensuring 'adequate security is being provided by the necessary controls' (choice C) or is often delegated as a direct implementation task to an ISSO or technical staff, with the SO providing oversight.

Concept tested: NIST RMF System Owner responsibilities

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#System Owner#Roles and Responsibilities#Security Controls#Vulnerability Management

Community Discussion

No community discussion yet for this question.

Full CGRC Practice