CGRC · Question #270
The level of assessor independence is determined based on applicable laws, executive orders, directives, regulations, policies, or standards. Who determines the level of assessor independence?…
The correct answer is A. The Authorizing Official. The Authorizing Official (AO) is ultimately responsible for determining the acceptable level of risk and, consequently, the required level of assessor independence for security assessments, in alignment with applicable regulations and organizational policies. The AO signs off…
Question
The level of assessor independence is determined based on applicable laws, executive orders, directives, regulations, policies, or standards. Who determines the level of assessor independence? Response:
Options
- AThe Authorizing Official
- BThe Ifnormation System Owner (ISO)
- CThe Common Control Provider (CCP)
- DThe Information Owner (IO)
How the community answered
(19 responses)- A89% (17)
- B5% (1)
- D5% (1)
Why each option
The Authorizing Official (AO) is ultimately responsible for determining the acceptable level of risk and, consequently, the required level of assessor independence for security assessments, in alignment with applicable regulations and organizational policies. The AO signs off on the authorization to operate and therefore sets the assessment rigor.
The Authorizing Official (AO) is ultimately responsible for accepting the risk associated with an information system and grants the authorization to operate. Therefore, the AO determines the required level of assessor independence to ensure the credibility and trustworthiness of the security assessment findings, based on legal, policy, and risk considerations.
The Information System Owner (ISO) is responsible for the system's development, operation, and maintenance, but does not typically determine the level of assessor independence; that is an AO responsibility related to overall risk acceptance.
The Common Control Provider (CCP) is responsible for implementing and managing common controls, not for determining the independence level of assessors performing evaluations.
The Information Owner (IO) is accountable for specific data sets within the system, including their classification and access, but not for determining assessor independence for the entire system's authorization.
Concept tested: RMF roles and responsibilities - Authorizing Official
Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.