nerdexam
(ISC)2

CGRC · Question #555

Who provides oversight of activities of the system owner, who provides trend analysis to id problems that may impact security posture. From Enterprise perspective reports to AO and system owners on…

The correct answer is A. CISO. The Chief Information Security Officer (CISO) provides enterprise-level oversight to system owners, conducts trend analysis to identify potential security impacts, and reports on organization-wide risks to the Authorizing Official (AO) and other stakeholders.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Who provides oversight of activities of the system owner, who provides trend analysis to id problems that may impact security posture. From Enterprise perspective reports to AO and system owners on organization wide risks (ISSO, CISO, ISO). Response:

Options

  • ACISO
  • BISSO
  • CISO
  • DAODR

How the community answered

(52 responses)
  • A
    92% (48)
  • B
    2% (1)
  • C
    2% (1)
  • D
    4% (2)

Why each option

The Chief Information Security Officer (CISO) provides enterprise-level oversight to system owners, conducts trend analysis to identify potential security impacts, and reports on organization-wide risks to the Authorizing Official (AO) and other stakeholders.

ACISOCorrect

The CISO is the senior-level executive responsible for developing and managing the organization's information security program and strategy, encompassing enterprise-wide risk management, oversight, and reporting on overall security posture to the AO and system owners.

BISSO

The Information System Security Officer (ISSO) typically focuses on specific information systems, reporting to the System Owner, and does not generally provide enterprise-wide oversight or report organization-wide risks to the AO.

CISO

The Information System Owner (ISO) is responsible for a particular system but does not typically provide enterprise-level trend analysis or oversight across other system owners.

DAODR

An AODR (Authorizing Official Designated Representative) acts on behalf of the AO but does not possess the overarching enterprise-wide risk analysis and oversight responsibilities described.

Concept tested: Chief Information Security Officer (CISO) role

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#Roles and Responsibilities#Information Security Governance#Risk Management#Enterprise Security

Community Discussion

No community discussion yet for this question.

Full CGRC Practice