nerdexam
(ISC)2

CGRC · Question #496

What RMF role is responsible for assessing impact of changes on systems, process it supports, & data it processes (ISO, AO, ISSO)? Response:

The correct answer is A. Information System Owner. The Information System Owner (ISO) is responsible for the overall procurement, development, integration, modification, and operation of an information system, including assessing the impact of changes on the system, its processes, and data. This role manages the system…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

What RMF role is responsible for assessing impact of changes on systems, process it supports, & data it processes (ISO, AO, ISSO)? Response:

Options

  • AInformation System Owner
  • BAuthorizing Official
  • CInformation Systems Security Officer
  • DIndustry Standard Architecture

How the community answered

(36 responses)
  • A
    89% (32)
  • B
    3% (1)
  • C
    3% (1)
  • D
    6% (2)

Why each option

The Information System Owner (ISO) is responsible for the overall procurement, development, integration, modification, and operation of an information system, including assessing the impact of changes on the system, its processes, and data. This role manages the system throughout its lifecycle.

AInformation System OwnerCorrect

The Information System Owner (ISO) has primary responsibility for an information system throughout its lifecycle, including understanding its mission, business processes, and the data it processes. Therefore, the ISO is directly responsible for assessing the impact of changes on the system, the processes it supports, and the data it handles to ensure continued operational effectiveness and security.

BAuthorizing Official

The Authorizing Official (AO) grants authorization for a system to operate, but relies on others, like the ISO, for detailed impact assessments.

CInformation Systems Security Officer

The Information Systems Security Officer (ISSO) advises on and oversees security, but the overall responsibility for system impact assessment typically rests with the ISO.

DIndustry Standard Architecture

Industry Standard Architecture is not a recognized role within the Risk Management Framework (RMF).

Concept tested: NIST RMF roles and responsibilities, Information System Owner

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#RMF Roles#Information System Owner (ISO)#Impact Assessment#Change Management

Community Discussion

No community discussion yet for this question.

Full CGRC Practice