CGRC · Question #430
Which of the following individuals is responsible for the final accreditation decision? Response:
The correct answer is A. Information System Owner. The Information System Owner is ultimately responsible for the overall security of their system and, often acting as or reporting to the Authorizing Official, holds the authority to make the final accreditation or authorization decision.
Question
Which of the following individuals is responsible for the final accreditation decision? Response:
Options
- AInformation System Owner
- BCertification Agent
- CUser Representative
- DRisk Executive
How the community answered
(37 responses)- A89% (33)
- B5% (2)
- C3% (1)
- D3% (1)
Why each option
The Information System Owner is ultimately responsible for the overall security of their system and, often acting as or reporting to the Authorizing Official, holds the authority to make the final accreditation or authorization decision.
The Information System Owner is ultimately accountable for the information system's security and, in many organizational structures, acts as or is directly responsible to the Authorizing Official (AO). The AO makes the final authorization or accreditation decision to permit the system to operate based on an acceptable level of risk.
The Certification Agent (or Security Control Assessor) is responsible for assessing controls and providing findings, but does not make the final authorization decision.
A User Representative provides input on system usage and requirements but does not have the authority to make the final security authorization decision.
The Risk Executive provides oversight of the enterprise-wide risk management program, but the specific authorization decision for an individual system falls to the Authorizing Official, often the System Owner.
Concept tested: Final authorization decision responsibility
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.