nerdexam
(ISC)2

CGRC · Question #321

Who determines the required level of independence for security control assessors? Response:

The correct answer is C. Authorizing official (AO). The Authorizing Official (AO) is responsible for determining the appropriate level of independence for security control assessors. This ensures the objectivity and credibility of the security assessments.

Assessment/Audit of Security and Privacy Controls

Question

Who determines the required level of independence for security control assessors? Response:

Options

  • AInformation system owner (ISO)
  • BInformation system security manager (ISSM)
  • CAuthorizing official (AO)
  • DInformation system security officer (ISSO)

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    90% (26)
  • D
    3% (1)

Why each option

The Authorizing Official (AO) is responsible for determining the appropriate level of independence for security control assessors. This ensures the objectivity and credibility of the security assessments.

AInformation system owner (ISO)

The Information System Owner (ISO) is responsible for the system itself and its operational effectiveness, not for determining the independence level of assessors.

BInformation system security manager (ISSM)

The Information System Security Manager (ISSM) manages the day-to-day security program, but the AO has the final authority on assessor independence.

CAuthorizing official (AO)Correct

The Authorizing Official (AO) is ultimately responsible for accepting the risk to an information system and therefore determines the appropriate level of independence for security control assessors to ensure unbiased and credible assessments. This decision is critical for maintaining the integrity and trustworthiness of the assessment findings that inform the authorization decision.

DInformation system security officer (ISSO)

The Information System Security Officer (ISSO) supports the ISO and ISSM, focusing on specific security aspects, and does not determine assessor independence.

Concept tested: RMF roles - Authorizing Official responsibilities

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Authorizing Official (AO)#Assessor Independence#RMF Roles#Security Control Assessment

Community Discussion

No community discussion yet for this question.

Full CGRC Practice