CGRC · Question #458
Who has the responsibility to track corrective actions to their completion keeping the approving authority informed with periodic updates as directed? Response:
The correct answer is B. The ISO. The question asks to identify the role responsible for tracking and reporting on the completion of corrective actions to an approving authority.
Question
Who has the responsibility to track corrective actions to their completion keeping the approving authority informed with periodic updates as directed? Response:
Options
- AThe ISSSE
- BThe ISO
- CThe ISSO
- DThe SISO
How the community answered
(42 responses)- A7% (3)
- B88% (37)
- C2% (1)
- D2% (1)
Why each option
The question asks to identify the role responsible for tracking and reporting on the completion of corrective actions to an approving authority.
“ISSSE” (Information System Security Systems Engineer) is not a standard role with this specific tracking responsibility; engineers typically focus on technical implementation.
The Information System Owner (ISO) is typically responsible for the overall procurement, development, integration, modification, operation, and maintenance of a specific information system. This includes ensuring that corrective actions for identified deficiencies are tracked, implemented, and reported to the authorizing official or approving authority.
“ISSO” (Information System Security Officer) generally assists the ISO in ensuring the security of the system, including compliance and coordination, but the ultimate responsibility for tracking and reporting often rests with the ISO.
“SISO” (Senior Information Security Officer) is not a commonly defined role in NIST or similar frameworks for this specific task; a CISO or SAOIS has broader program responsibility, not system-specific action tracking.
Concept tested: Information System Owner Responsibilities
Source: https://csrc.nist.gov/glossary/term/information-system-owner
Topics
Community Discussion
No community discussion yet for this question.