nerdexam
(ISC)2

CGRC · Question #448

Documenting the description of the system in the system security plan is the primary responsibility of which Risk Management Framework (RMF) role? Response:

The correct answer is D. Information system owner. The primary responsibility for documenting the system description in the system security plan within the Risk Management Framework (RMF) rests with the Information System Owner.

Scope of the System

Question

Documenting the description of the system in the system security plan is the primary responsibility of which Risk Management Framework (RMF) role? Response:

Options

  • AAuthorizing official (AO)
  • BInformation owner
  • CInformation system security officer (ISSO)
  • DInformation system owner

How the community answered

(25 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    92% (23)

Why each option

The primary responsibility for documenting the system description in the system security plan within the Risk Management Framework (RMF) rests with the Information System Owner.

AAuthorizing official (AO)

The Authorizing Official (AO) is responsible for making the final authorization decision for the system, not for the primary documentation of the system description.

BInformation owner

While the Information Owner (or Data Owner) is responsible for the data within the system, the Information System Owner is explicitly responsible for the system itself and its documentation.

CInformation system security officer (ISSO)

The Information System Security Officer (ISSO) is responsible for maintaining the security posture of the system, advising the System Owner, and implementing security controls, but the primary documentation responsibility lies with the System Owner.

DInformation system ownerCorrect

The Information System Owner has the primary responsibility for the development, documentation, operation, and maintenance of an information system throughout its lifecycle. This specifically includes providing a detailed description of the system within the System Security Plan (SSP) as part of the RMF's Prepare and Categorize steps.

Concept tested: RMF roles and responsibilities (System Owner)

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#RMF Roles#Information System Owner#System Security Plan#System Definition

Community Discussion

No community discussion yet for this question.

Full CGRC Practice