nerdexam
(ISC)2

CGRC · Question #419

Which RMF role is responsibility for securing the system and managing all security aspects of the system. Closely monitors the day-to-day security of the system and monitors effectiveness of…

The correct answer is A. ISSO. The Information System Security Officer (ISSO) is the RMF role specifically tasked with the day-to-day operational security of a system, including managing security aspects, monitoring controls, and ensuring continuous effectiveness.

Compliance Maintenance

Question

Which RMF role is responsibility for securing the system and managing all security aspects of the system. Closely monitors the day-to-day security of the system and monitors effectiveness of controls. Response:

Options

  • AISSO
  • BISO
  • CISA
  • DPOAM

How the community answered

(31 responses)
  • A
    90% (28)
  • C
    3% (1)
  • D
    6% (2)

Why each option

The Information System Security Officer (ISSO) is the RMF role specifically tasked with the day-to-day operational security of a system, including managing security aspects, monitoring controls, and ensuring continuous effectiveness.

AISSOCorrect

The Information System Security Officer (ISSO) is responsible for the overall security of an information system, including managing all security aspects, closely monitoring day-to-day security operations, and assessing the effectiveness of security controls within that specific system. This role involves implementing and maintaining the system's security posture.

BISO

The Information Security Officer (ISO) typically holds a broader, enterprise-level role, focusing on the overall information security program for an organization, rather than the day-to-day specifics of a single system.

CISA

An Information Security Architect (ISA) or Analyst is more involved in designing and analyzing security solutions or performing assessments, not typically the continuous day-to-day operational management and monitoring described.

DPOAM

POAM (Plan of Action and Milestones) is a document that identifies security weaknesses and outlines remediation steps, not a role within the RMF.

Concept tested: RMF (Risk Management Framework) roles (ISSO)

Source: https://csrc.nist.gov/glossary/term/information-system-security-officer

Topics

#RMF Roles#ISSO Responsibilities#System Security Operations#Control Monitoring

Community Discussion

No community discussion yet for this question.

Full CGRC Practice