CGRC · Question #301
The primary responsibility to select control assessors rests on which roles? Response:
The correct answer is B. Authorizing offical (AO), Authorizing Official Designated Representative (AODR). The primary responsibility for selecting control assessors within the Risk Management Framework (RMF) rests with the Authorizing Official (AO) and their designated representative (AODR).
Question
The primary responsibility to select control assessors rests on which roles? Response:
Options
- AAuthorizing Official (AO) and Information System Security Officer (ISSO)
- BAuthorizing offical (AO), Authorizing Official Designated Representative (AODR)
- CAuthorizing offical (AO), Information System Owner (ISO)
- DInformation System Owner (ISO), Security Control Assessor (SCA)
How the community answered
(42 responses)- B95% (40)
- C2% (1)
- D2% (1)
Why each option
The primary responsibility for selecting control assessors within the Risk Management Framework (RMF) rests with the Authorizing Official (AO) and their designated representative (AODR).
The ISSO primarily advises on security matters for the information system, but is not responsible for selecting independent control assessors.
The AO holds overall accountability for system authorization and delegates tasks to the AODR, including selecting independent and qualified assessors, to ensure the objectivity and integrity of the security control assessment process. This delegation allows for effective management of the assessment phase of the RMF.
The ISO is responsible for the system's overall lifecycle, not the selection of independent assessors for the authorization process.
The SCA performs the assessment but does not select the assessors for an independent evaluation.
Concept tested: RMF Roles and Responsibilities - Control Assessor Selection
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.