nerdexam
(ISC)2

CGRC · Question #500

What are five primary roles associated with the system authorization program? Response:

The correct answer is A. 1. CISO (Chief Information Security Officer or senior information security officer). The Chief Information Security Officer (CISO) is a primary role in a system authorization program, responsible for overall security governance and often advising the Authorizing Official (AO). This choice correctly identifies a key leadership role involved in the system…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

What are five primary roles associated with the system authorization program? Response:

Options

  • A
    1. CISO (Chief Information Security Officer or senior information security officer)
  • B
    1. System Owner
  • C
    1. ISSO (Information System Security Officer)
  • D
    1. CISO (Chief Information Security Officer or senior information security officer)

How the community answered

(44 responses)
  • A
    93% (41)
  • C
    2% (1)
  • D
    5% (2)

Why each option

The Chief Information Security Officer (CISO) is a primary role in a system authorization program, responsible for overall security governance and often advising the Authorizing Official (AO). This choice correctly identifies a key leadership role involved in the system authorization process.

A1. CISO (Chief Information Security Officer or senior information security officer)Correct

The Chief Information Security Officer (CISO), or a senior information security officer, is a primary role in the system authorization program. They are responsible for overseeing the organization's information security program and often play a critical role in approving security policies, resource allocation for security, and providing recommendations to the Authorizing Official regarding system authorization decisions.

B1. System Owner

While System Owner is a primary role, the option provided is just "1. System Owner," implying it's an incomplete list or not the most comprehensive starting point for a list of five primary roles that would also include CISO as a high-level authority.

C1. ISSO (Information System Security Officer)

While ISSO is a primary role, similar to option B, it's just "1. ISSO" and not the beginning of a complete list of five roles.

D1. CISO (Chief Information Security Officer or senior information security officer)

This is identical to option A, reinforcing that the CISO is a correct starting point for a list of primary authorization program roles.

Concept tested: NIST RMF roles and responsibilities, System Authorization Program

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#System Authorization Program Roles#CISO#Risk Management Framework (RMF)#Organizational Roles

Community Discussion

No community discussion yet for this question.

Full CGRC Practice