nerdexam
(ISC)2

CGRC · Question #543

Which of the following C&A professionals plays the role of an advisor? Response:

The correct answer is A. Information System Security Engineer (ISSE). The Information System Security Engineer (ISSE) serves as an advisor in the Certification & Accreditation (C&A) process. They provide technical expertise for integrating security into system design and development.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following C&A professionals plays the role of an advisor? Response:

Options

  • AInformation System Security Engineer (ISSE)
  • BChief Information Officer (CIO)
  • CAuthorizing Official
  • DInformation Owner

How the community answered

(47 responses)
  • A
    94% (44)
  • B
    2% (1)
  • C
    4% (2)

Why each option

The Information System Security Engineer (ISSE) serves as an advisor in the Certification & Accreditation (C&A) process. They provide technical expertise for integrating security into system design and development.

AInformation System Security Engineer (ISSE)Correct

An Information System Security Engineer (ISSE) plays a crucial advisory role by applying their deep technical knowledge to design, develop, and implement secure information systems throughout their lifecycle. The ISSE ensures that security requirements are effectively integrated into system architectures and operations, offering expert guidance to various stakeholders involved in the C&A process. They translate security policies into practical technical solutions, thereby advising on the most effective ways to secure an information system.

BChief Information Officer (CIO)

The Chief Information Officer (CIO) is a senior executive responsible for IT strategy and operations, not typically an advisor on individual C&A technical implementations.

CAuthorizing Official

The Authorizing Official (AO) holds the ultimate responsibility for authorizing a system to operate, a decision-making role rather than an advisory one.

DInformation Owner

An Information Owner is responsible for the data's classification and access, not primarily for advising on system security engineering or C&A processes.

Concept tested: C&A roles - ISSE

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#RMF Roles#ISSE#Security Personnel#Advisory Role

Community Discussion

No community discussion yet for this question.

Full CGRC Practice