nerdexam
(ISC)2

CGRC · Question #386

The Information System Security Officer (ISSO) and Information System Security Engineer (ISSE) play the role of a supporter and advisor, respectively. Which of the following statements are true about

The correct answer is A. Each correct answer represents a complete solution. Choose all that apply. C. An ISSE provides advice on the impacts of system changes. E. An ISSO manages the security of the information system that is slated for Certification &. An Information System Security Engineer (ISSE) advises on system changes' impacts, while an Information System Security Officer (ISSO) manages the security of information systems for certification and accreditation.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The Information System Security Officer (ISSO) and Information System Security Engineer (ISSE) play the role of a supporter and advisor, respectively. Which of the following statements are true about ISSO and ISSE?

Options

  • AEach correct answer represents a complete solution. Choose all that apply.
  • BResponse:
  • CAn ISSE provides advice on the impacts of system changes.
  • DAn ISSE manages the security of the information system that is slated for Certification &
  • EAn ISSO manages the security of the information system that is slated for Certification &
  • FAn ISSO takes part in the development activities that are required to implement system changes.
  • GAn ISSE provides advice on the continuous monitoring of the information system.

How the community answered

(22 responses)
  • A
    86% (19)
  • D
    5% (1)
  • G
    9% (2)

Why each option

An Information System Security Engineer (ISSE) advises on system changes' impacts, while an Information System Security Officer (ISSO) manages the security of information systems for certification and accreditation.

AEach correct answer represents a complete solution. Choose all that apply.Correct
BResponse:
CAn ISSE provides advice on the impacts of system changes.Correct

An ISSE's primary role is to provide expert technical guidance on the integration of security into systems and software development, which includes advising on the security impacts of design decisions and proposed system changes. This aligns with the ISSE's role as an advisor on system modifications. An ISSO manages the security of the information system that is slated for Certification & Accreditation (C&A) because the ISSO is responsible for ensuring the system's security posture meets organizational requirements and assists in the formal process of security authorization.

DAn ISSE manages the security of the information system that is slated for Certification &
EAn ISSO manages the security of the information system that is slated for Certification &Correct

An ISSO's core responsibility includes managing and overseeing the security of an information system throughout its lifecycle, including preparation for and execution of the Certification and Accreditation (C&A) or Authorization to Operate (ATO) processes. This involves ensuring security controls are implemented and maintained, aligning with their role as a supporter and manager of the system's security posture.

FAn ISSO takes part in the development activities that are required to implement system changes.

An ISSO's role is typically focused on security management, oversight, and compliance, not directly participating in the technical development activities required to implement system changes. That is more often the role of an ISSE or development team.

GAn ISSE provides advice on the continuous monitoring of the information system.

While an ISSE provides technical input for system design to support continuous monitoring, the direct 'advice on the continuous monitoring' (i.e., the ongoing process and findings) is typically within the purview of the ISSO or dedicated continuous monitoring teams who manage the operational security posture.

Concept tested: Information system security roles and responsibilities

Source: https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/rev-1/final

Topics

#ISSO roles#ISSE roles#Security roles and responsibilities#System authorization

Community Discussion

No community discussion yet for this question.

Full CGRC Practice