nerdexam
(ISC)2

CGRC · Question #458

Who has the responsibility to track corrective actions to their completion keeping the approving authority informed with periodic updates as directed? Response:

The correct answer is B. The ISO. The question asks to identify the role responsible for tracking and reporting on the completion of corrective actions to an approving authority.

Compliance Maintenance

Question

Who has the responsibility to track corrective actions to their completion keeping the approving authority informed with periodic updates as directed? Response:

Options

  • AThe ISSSE
  • BThe ISO
  • CThe ISSO
  • DThe SISO

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    88% (37)
  • C
    2% (1)
  • D
    2% (1)

Why each option

The question asks to identify the role responsible for tracking and reporting on the completion of corrective actions to an approving authority.

AThe ISSSE

“ISSSE” (Information System Security Systems Engineer) is not a standard role with this specific tracking responsibility; engineers typically focus on technical implementation.

BThe ISOCorrect

The Information System Owner (ISO) is typically responsible for the overall procurement, development, integration, modification, operation, and maintenance of a specific information system. This includes ensuring that corrective actions for identified deficiencies are tracked, implemented, and reported to the authorizing official or approving authority.

CThe ISSO

“ISSO” (Information System Security Officer) generally assists the ISO in ensuring the security of the system, including compliance and coordination, but the ultimate responsibility for tracking and reporting often rests with the ISO.

DThe SISO

“SISO” (Senior Information Security Officer) is not a commonly defined role in NIST or similar frameworks for this specific task; a CISO or SAOIS has broader program responsibility, not system-specific action tracking.

Concept tested: Information System Owner Responsibilities

Source: https://csrc.nist.gov/glossary/term/information-system-owner

Topics

#Roles and Responsibilities#Information System Owner (ISO)#Corrective Actions#Compliance Monitoring

Community Discussion

No community discussion yet for this question.

Full CGRC Practice