nerdexam
(ISC)2

CGRC · Question #430

Which of the following individuals is responsible for the final accreditation decision? Response:

The correct answer is A. Information System Owner. The Information System Owner is ultimately responsible for the overall security of their system and, often acting as or reporting to the Authorizing Official, holds the authority to make the final accreditation or authorization decision.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following individuals is responsible for the final accreditation decision? Response:

Options

  • AInformation System Owner
  • BCertification Agent
  • CUser Representative
  • DRisk Executive

How the community answered

(37 responses)
  • A
    89% (33)
  • B
    5% (2)
  • C
    3% (1)
  • D
    3% (1)

Why each option

The Information System Owner is ultimately responsible for the overall security of their system and, often acting as or reporting to the Authorizing Official, holds the authority to make the final accreditation or authorization decision.

AInformation System OwnerCorrect

The Information System Owner is ultimately accountable for the information system's security and, in many organizational structures, acts as or is directly responsible to the Authorizing Official (AO). The AO makes the final authorization or accreditation decision to permit the system to operate based on an acceptable level of risk.

BCertification Agent

The Certification Agent (or Security Control Assessor) is responsible for assessing controls and providing findings, but does not make the final authorization decision.

CUser Representative

A User Representative provides input on system usage and requirements but does not have the authority to make the final security authorization decision.

DRisk Executive

The Risk Executive provides oversight of the enterprise-wide risk management program, but the specific authorization decision for an individual system falls to the Authorizing Official, often the System Owner.

Concept tested: Final authorization decision responsibility

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Roles and Responsibilities#Accreditation Decision#Information System Owner#Authorization Official

Community Discussion

No community discussion yet for this question.

Full CGRC Practice