CGRC · Question #502
The primary responsibility to update authorization package documents lies on which of the following officials? Response:
The correct answer is C. System Owner and Common Control Provider. The System Owner and Common Control Provider bear the primary responsibility for ensuring the authorization package documents are regularly updated.
Question
The primary responsibility to update authorization package documents lies on which of the following officials? Response:
Options
- ASystem Owner and System Administrator
- BAssessor and System Owner
- CSystem Owner and Common Control Provider
- DAuthorizing Official Designated Representative and Assessor
How the community answered
(40 responses)- A3% (1)
- C93% (37)
- D5% (2)
Why each option
The System Owner and Common Control Provider bear the primary responsibility for ensuring the authorization package documents are regularly updated.
While System Administrators perform operational tasks, the overarching responsibility for authorization package updates lies with the System Owner and Common Control Provider, not primarily the System Administrator.
The Assessor's role is to evaluate security controls and documentation, not to update the authorization package documents.
The System Owner is accountable for the system throughout its lifecycle, including the accuracy and currency of its authorization documentation. The Common Control Provider is responsible for maintaining the documentation for common controls that other systems inherit, ensuring it remains up-to-date for leveraging organizations.
The Authorizing Official Designated Representative (AODR) makes authorization decisions, and the Assessor conducts evaluations; neither has primary responsibility for ongoing document maintenance.
Concept tested: RMF Authorization Document Maintenance Roles
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.