CGRC · Question #466
Who has primary responsibility to develop a report of the results of the security and privacy control assessments, including recommendations for correcting deficiencies in the implemented controls?…
The correct answer is D. Security Control Assessor (SCA). The Security Control Assessor (SCA) is primarily responsible for conducting security control assessments and reporting on identified deficiencies and recommendations.
Question
Who has primary responsibility to develop a report of the results of the security and privacy control assessments, including recommendations for correcting deficiencies in the implemented controls? Response:
Options
- AInformation System Security Officer (ISSO)
- BInformation System Owner (ISO)
- CCommon Control Provider (CCP)
- DSecurity Control Assessor (SCA)
How the community answered
(44 responses)- A7% (3)
- B5% (2)
- C2% (1)
- D86% (38)
Why each option
The Security Control Assessor (SCA) is primarily responsible for conducting security control assessments and reporting on identified deficiencies and recommendations.
The Information System Security Officer (ISSO) typically advises on security matters and helps ensure controls are implemented but does not primarily conduct independent assessments or generate the reports.
The Information System Owner (ISO) is responsible for the system's overall security and risk acceptance but does not perform the detailed control assessments or generate the assessment reports.
The Common Control Provider (CCP) is responsible for providing common controls to multiple systems, but not for assessing the controls of individual systems or generating assessment reports for them.
The Security Control Assessor (SCA) conducts the actual assessments of security and privacy controls and is explicitly responsible for generating the assessment reports, including findings and recommendations for addressing identified weaknesses.
Concept tested: NIST RMF roles and responsibilities - SCA
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.