CGRC · Question #554
Which RMF role must ensure security assessment plan is constent with or security objectives, reflects the use of tools, techniques, etc..? Response:
The correct answer is A. Information System Owner. The Information System Owner holds the RMF role responsible for ensuring that the security assessment plan aligns with the system's security objectives and accurately reflects the appropriate tools and techniques to be used.
Question
Which RMF role must ensure security assessment plan is constent with or security objectives, reflects the use of tools, techniques, etc..? Response:
Options
- AInformation System Owner
- BAuthorizing Official
- CInformation Systems Security Officer
- DIntegrated Safeguards Security Management
How the community answered
(31 responses)- A87% (27)
- C10% (3)
- D3% (1)
Why each option
The Information System Owner holds the RMF role responsible for ensuring that the security assessment plan aligns with the system's security objectives and accurately reflects the appropriate tools and techniques to be used.
The Information System Owner is accountable for the security of their system throughout its lifecycle, including ensuring that the security assessment plan supports the system's security objectives. This role ensures the plan properly outlines the methods, tools, and techniques for assessing the system's security posture.
The Authorizing Official makes the final risk acceptance decision but does not typically ensure the specific details of the security assessment plan's tools and techniques.
The Information Systems Security Officer (ISSO) advises on security and helps ensure compliance but the primary accountability for the system's security and assessment plan consistency rests with the System Owner.
"Integrated Safeguards Security Management" is not a standard, recognized role within the Risk Management Framework (RMF).
Concept tested: RMF Information System Owner responsibilities
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.