nerdexam
(ISC)2

CGRC · Question #491

Which organizational official is responsible for the procurement, development, integration, modification, operation, maintenance, and disposal of an information system? Response:

The correct answer is C. Information system owner (ISO). The Information System Owner (ISO) is the organizational official with end-to-end responsibility for an information system's entire lifecycle, from procurement through disposal.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which organizational official is responsible for the procurement, development, integration, modification, operation, maintenance, and disposal of an information system? Response:

Options

  • AInformation system security engineer (ISSE)
  • BChief information officer (CIO)
  • CInformation system owner (ISO)
  • DInformation security architect

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    93% (27)

Why each option

The Information System Owner (ISO) is the organizational official with end-to-end responsibility for an information system's entire lifecycle, from procurement through disposal.

AInformation system security engineer (ISSE)

An Information System Security Engineer (ISSE) focuses on the security aspects of design, implementation, and operations, not the overall system ownership.

BChief information officer (CIO)

A Chief Information Officer (CIO) oversees the entire organization's information technology strategy and operations, a broader role than specific system ownership.

CInformation system owner (ISO)Correct

The Information System Owner (ISO) is accountable for the management, acquisition, and full lifecycle of an information system, encompassing procurement, development, integration, modification, operation, maintenance, and disposal. They ensure the system meets its mission needs while adhering to security policies.

DInformation security architect

An Information Security Architect designs the security framework and controls, but does not own the full lifecycle responsibility for a specific system.

Concept tested: Information System Owner responsibilities

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Information System Owner (ISO)#Roles and Responsibilities#System Lifecycle#Accountability

Community Discussion

No community discussion yet for this question.

Full CGRC Practice