nerdexam
(ISC)2

CGRC · Question #270

The level of assessor independence is determined based on applicable laws, executive orders, directives, regulations, policies, or standards. Who determines the level of assessor independence?…

The correct answer is A. The Authorizing Official. The Authorizing Official (AO) is ultimately responsible for determining the acceptable level of risk and, consequently, the required level of assessor independence for security assessments, in alignment with applicable regulations and organizational policies. The AO signs off…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The level of assessor independence is determined based on applicable laws, executive orders, directives, regulations, policies, or standards. Who determines the level of assessor independence? Response:

Options

  • AThe Authorizing Official
  • BThe Ifnormation System Owner (ISO)
  • CThe Common Control Provider (CCP)
  • DThe Information Owner (IO)

How the community answered

(19 responses)
  • A
    89% (17)
  • B
    5% (1)
  • D
    5% (1)

Why each option

The Authorizing Official (AO) is ultimately responsible for determining the acceptable level of risk and, consequently, the required level of assessor independence for security assessments, in alignment with applicable regulations and organizational policies. The AO signs off on the authorization to operate and therefore sets the assessment rigor.

AThe Authorizing OfficialCorrect

The Authorizing Official (AO) is ultimately responsible for accepting the risk associated with an information system and grants the authorization to operate. Therefore, the AO determines the required level of assessor independence to ensure the credibility and trustworthiness of the security assessment findings, based on legal, policy, and risk considerations.

BThe Ifnormation System Owner (ISO)

The Information System Owner (ISO) is responsible for the system's development, operation, and maintenance, but does not typically determine the level of assessor independence; that is an AO responsibility related to overall risk acceptance.

CThe Common Control Provider (CCP)

The Common Control Provider (CCP) is responsible for implementing and managing common controls, not for determining the independence level of assessors performing evaluations.

DThe Information Owner (IO)

The Information Owner (IO) is accountable for specific data sets within the system, including their classification and access, but not for determining assessor independence for the entire system's authorization.

Concept tested: RMF roles and responsibilities - Authorizing Official

Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-37r2.pdf

Topics

#Assessor Independence#Authorizing Official (AO)#NIST RMF Roles#Risk Acceptance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice