nerdexam
(ISC)2

CGRC · Question #466

Who has primary responsibility to develop a report of the results of the security and privacy control assessments, including recommendations for correcting deficiencies in the implemented controls?…

The correct answer is D. Security Control Assessor (SCA). The Security Control Assessor (SCA) is primarily responsible for conducting security control assessments and reporting on identified deficiencies and recommendations.

Assessment/Audit of Security and Privacy Controls

Question

Who has primary responsibility to develop a report of the results of the security and privacy control assessments, including recommendations for correcting deficiencies in the implemented controls? Response:

Options

  • AInformation System Security Officer (ISSO)
  • BInformation System Owner (ISO)
  • CCommon Control Provider (CCP)
  • DSecurity Control Assessor (SCA)

How the community answered

(44 responses)
  • A
    7% (3)
  • B
    5% (2)
  • C
    2% (1)
  • D
    86% (38)

Why each option

The Security Control Assessor (SCA) is primarily responsible for conducting security control assessments and reporting on identified deficiencies and recommendations.

AInformation System Security Officer (ISSO)

The Information System Security Officer (ISSO) typically advises on security matters and helps ensure controls are implemented but does not primarily conduct independent assessments or generate the reports.

BInformation System Owner (ISO)

The Information System Owner (ISO) is responsible for the system's overall security and risk acceptance but does not perform the detailed control assessments or generate the assessment reports.

CCommon Control Provider (CCP)

The Common Control Provider (CCP) is responsible for providing common controls to multiple systems, but not for assessing the controls of individual systems or generating assessment reports for them.

DSecurity Control Assessor (SCA)Correct

The Security Control Assessor (SCA) conducts the actual assessments of security and privacy controls and is explicitly responsible for generating the assessment reports, including findings and recommendations for addressing identified weaknesses.

Concept tested: NIST RMF roles and responsibilities - SCA

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Roles and Responsibilities#Security Control Assessor (SCA)#Control Assessment#Security Assessment Report

Community Discussion

No community discussion yet for this question.

Full CGRC Practice