CGRC · Question #500
What are five primary roles associated with the system authorization program? Response:
The correct answer is A. 1. CISO (Chief Information Security Officer or senior information security officer). The Chief Information Security Officer (CISO) is a primary role in a system authorization program, responsible for overall security governance and often advising the Authorizing Official (AO). This choice correctly identifies a key leadership role involved in the system…
Question
What are five primary roles associated with the system authorization program? Response:
Options
- A
- CISO (Chief Information Security Officer or senior information security officer)
- B
- System Owner
- C
- ISSO (Information System Security Officer)
- D
- CISO (Chief Information Security Officer or senior information security officer)
How the community answered
(44 responses)- A93% (41)
- C2% (1)
- D5% (2)
Why each option
The Chief Information Security Officer (CISO) is a primary role in a system authorization program, responsible for overall security governance and often advising the Authorizing Official (AO). This choice correctly identifies a key leadership role involved in the system authorization process.
The Chief Information Security Officer (CISO), or a senior information security officer, is a primary role in the system authorization program. They are responsible for overseeing the organization's information security program and often play a critical role in approving security policies, resource allocation for security, and providing recommendations to the Authorizing Official regarding system authorization decisions.
While System Owner is a primary role, the option provided is just "1. System Owner," implying it's an incomplete list or not the most comprehensive starting point for a list of five primary roles that would also include CISO as a high-level authority.
While ISSO is a primary role, similar to option B, it's just "1. ISSO" and not the beginning of a complete list of five roles.
This is identical to option A, reinforcing that the CISO is a correct starting point for a list of primary authorization program roles.
Concept tested: NIST RMF roles and responsibilities, System Authorization Program
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.