CGRC · Question #228
Which role has the primary responsibility to conduct ongoing assessments after an initial system authorization? Response:
The correct answer is C. Security Control Assessor. The Security Control Assessor is primarily responsible for conducting ongoing assessments to verify the effectiveness of security controls after a system's initial authorization.
Question
Which role has the primary responsibility to conduct ongoing assessments after an initial system authorization? Response:
Options
- AAuthorizing Official (AO)
- BCommon Control Provider (CCP)
- CSecurity Control Assessor
- DInformation System Owner (ISO)
How the community answered
(41 responses)- A2% (1)
- B5% (2)
- C93% (38)
Why each option
The Security Control Assessor is primarily responsible for conducting ongoing assessments to verify the effectiveness of security controls after a system's initial authorization.
The Authorizing Official (AO) makes the risk-based decision to authorize the system, but does not typically conduct the ongoing technical assessments themselves.
A Common Control Provider (CCP) is responsible for developing, implementing, assessing, and monitoring common controls shared across multiple systems, not conducting ongoing assessments for a specific system's authorization.
The Security Control Assessor (SCA) is responsible for conducting comprehensive assessments of security controls implemented in an information system, including ongoing assessments after initial authorization, to independently determine their effectiveness and compliance with security requirements.
The Information System Owner (ISO) has overall responsibility for the system and its security, but typically relies on security professionals like the SCA to conduct the detailed technical assessments.
Concept tested: Security Control Assessor responsibilities
Source: https://csrc.nist.gov/glossary/term/security-control-assessor
Topics
Community Discussion
No community discussion yet for this question.