CGRC · Question #321
Who determines the required level of independence for security control assessors? Response:
The correct answer is C. Authorizing official (AO). The Authorizing Official (AO) is responsible for determining the appropriate level of independence for security control assessors. This ensures the objectivity and credibility of the security assessments.
Question
Who determines the required level of independence for security control assessors? Response:
Options
- AInformation system owner (ISO)
- BInformation system security manager (ISSM)
- CAuthorizing official (AO)
- DInformation system security officer (ISSO)
How the community answered
(29 responses)- A3% (1)
- B3% (1)
- C90% (26)
- D3% (1)
Why each option
The Authorizing Official (AO) is responsible for determining the appropriate level of independence for security control assessors. This ensures the objectivity and credibility of the security assessments.
The Information System Owner (ISO) is responsible for the system itself and its operational effectiveness, not for determining the independence level of assessors.
The Information System Security Manager (ISSM) manages the day-to-day security program, but the AO has the final authority on assessor independence.
The Authorizing Official (AO) is ultimately responsible for accepting the risk to an information system and therefore determines the appropriate level of independence for security control assessors to ensure unbiased and credible assessments. This decision is critical for maintaining the integrity and trustworthiness of the assessment findings that inform the authorization decision.
The Information System Security Officer (ISSO) supports the ISO and ISSM, focusing on specific security aspects, and does not determine assessor independence.
Concept tested: RMF roles - Authorizing Official responsibilities
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.