CGRC · Question #417
Which of the following individuals informs all C&A participants about life cycle actions, security requirements, and documented user needs? Response:
The correct answer is A. IS program manager. The Information System (IS) program manager is the RMF role responsible for overseeing the system's lifecycle and communicating critical information, including security requirements and user needs, to all Certification and Accreditation (C&A) participants.
Question
Which of the following individuals informs all C&A participants about life cycle actions, security requirements, and documented user needs? Response:
Options
- AIS program manager
- BCertification Agent
- CUser representative
- DDAA
How the community answered
(23 responses)- A87% (20)
- B9% (2)
- D4% (1)
Why each option
The Information System (IS) program manager is the RMF role responsible for overseeing the system's lifecycle and communicating critical information, including security requirements and user needs, to all Certification and Accreditation (C&A) participants.
The IS Program Manager (often synonymous with the System Owner in some frameworks) has overall responsibility for the information system throughout its lifecycle. This role is crucial for ensuring that security requirements are defined, communicated to all stakeholders, and integrated into the system's development and operation, thereby informing C&A participants about these aspects.
A Certification Agent (or Security Assessor) is responsible for assessing the security controls and producing the security assessment report, not primarily for informing all participants about life cycle actions and user needs.
A User Representative advocates for the end-users' needs and requirements but does not typically have the overarching responsibility to inform all C&A participants about system lifecycle and security requirements.
The Designated Approving Authority (DAA), now often referred to as the Authorizing Official (AO), is responsible for making the final risk-based decision to authorize the system's operation, not for informing participants about life cycle actions or security requirements in a communicative role.
Concept tested: RMF (Risk Management Framework) roles
Source: https://csrc.nist.gov/glossary/term/system-owner
Topics
Community Discussion
No community discussion yet for this question.