nerdexam
(ISC)2

CGRC · Question #228

Which role has the primary responsibility to conduct ongoing assessments after an initial system authorization? Response:

The correct answer is C. Security Control Assessor. The Security Control Assessor is primarily responsible for conducting ongoing assessments to verify the effectiveness of security controls after a system's initial authorization.

Assessment/Audit of Security and Privacy Controls

Question

Which role has the primary responsibility to conduct ongoing assessments after an initial system authorization? Response:

Options

  • AAuthorizing Official (AO)
  • BCommon Control Provider (CCP)
  • CSecurity Control Assessor
  • DInformation System Owner (ISO)

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    5% (2)
  • C
    93% (38)

Why each option

The Security Control Assessor is primarily responsible for conducting ongoing assessments to verify the effectiveness of security controls after a system's initial authorization.

AAuthorizing Official (AO)

The Authorizing Official (AO) makes the risk-based decision to authorize the system, but does not typically conduct the ongoing technical assessments themselves.

BCommon Control Provider (CCP)

A Common Control Provider (CCP) is responsible for developing, implementing, assessing, and monitoring common controls shared across multiple systems, not conducting ongoing assessments for a specific system's authorization.

CSecurity Control AssessorCorrect

The Security Control Assessor (SCA) is responsible for conducting comprehensive assessments of security controls implemented in an information system, including ongoing assessments after initial authorization, to independently determine their effectiveness and compliance with security requirements.

DInformation System Owner (ISO)

The Information System Owner (ISO) has overall responsibility for the system and its security, but typically relies on security professionals like the SCA to conduct the detailed technical assessments.

Concept tested: Security Control Assessor responsibilities

Source: https://csrc.nist.gov/glossary/term/security-control-assessor

Topics

#Security Control Assessor#Ongoing Assessments#RMF Roles#Continuous Monitoring

Community Discussion

No community discussion yet for this question.

Full CGRC Practice