CGRC · Question #496
What RMF role is responsible for assessing impact of changes on systems, process it supports, & data it processes (ISO, AO, ISSO)? Response:
The correct answer is A. Information System Owner. The Information System Owner (ISO) is responsible for the overall procurement, development, integration, modification, and operation of an information system, including assessing the impact of changes on the system, its processes, and data. This role manages the system…
Question
What RMF role is responsible for assessing impact of changes on systems, process it supports, & data it processes (ISO, AO, ISSO)? Response:
Options
- AInformation System Owner
- BAuthorizing Official
- CInformation Systems Security Officer
- DIndustry Standard Architecture
How the community answered
(36 responses)- A89% (32)
- B3% (1)
- C3% (1)
- D6% (2)
Why each option
The Information System Owner (ISO) is responsible for the overall procurement, development, integration, modification, and operation of an information system, including assessing the impact of changes on the system, its processes, and data. This role manages the system throughout its lifecycle.
The Information System Owner (ISO) has primary responsibility for an information system throughout its lifecycle, including understanding its mission, business processes, and the data it processes. Therefore, the ISO is directly responsible for assessing the impact of changes on the system, the processes it supports, and the data it handles to ensure continued operational effectiveness and security.
The Authorizing Official (AO) grants authorization for a system to operate, but relies on others, like the ISO, for detailed impact assessments.
The Information Systems Security Officer (ISSO) advises on and oversees security, but the overall responsibility for system impact assessment typically rests with the ISO.
Industry Standard Architecture is not a recognized role within the Risk Management Framework (RMF).
Concept tested: NIST RMF roles and responsibilities, Information System Owner
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.