nerdexam
(ISC)2

CGRC · Question #592

Besides the System Owner (SO), what role has the PRIMARY responsibility for implementing the security controls in the security and privacy plans for an Information Systems (IS)? Response:

The correct answer is A. Common Control Provider (CPP). The Common Control Provider (CPP) has the primary responsibility for implementing security controls that are designated as common controls and inherited by multiple information systems.

Implementation of Security and Privacy Controls

Question

Besides the System Owner (SO), what role has the PRIMARY responsibility for implementing the security controls in the security and privacy plans for an Information Systems (IS)? Response:

Options

  • ACommon Control Provider (CPP)
  • BSystem administrator
  • CInformation Owner (IO)
  • DInformation System Security Officer (ISSO)

How the community answered

(38 responses)
  • A
    95% (36)
  • B
    3% (1)
  • C
    3% (1)

Why each option

The Common Control Provider (CPP) has the primary responsibility for implementing security controls that are designated as common controls and inherited by multiple information systems.

ACommon Control Provider (CPP)Correct

A Common Control Provider (CPP) is specifically tasked with developing, implementing, assessing, and monitoring security controls that are provided to and inherited by other information systems, thereby fulfilling a primary implementation role for those shared controls.

BSystem administrator

A System Administrator typically focuses on the operational implementation and maintenance of controls for specific systems, rather than having primary responsibility for common controls across an enterprise.

CInformation Owner (IO)

An Information Owner (IO) is responsible for the data's classification and protection requirements but does not primarily implement system-level security controls.

DInformation System Security Officer (ISSO)

An Information System Security Officer (ISSO) advises on and monitors the security posture of an IS, but their role is not primarily the implementation of security controls.

Concept tested: Roles and responsibilities in Information Security

Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-fedramp-roles-responsibilities

Topics

#RMF Roles and Responsibilities#Common Control Provider (CPP)#Control Implementation#System Owner (SO)

Community Discussion

No community discussion yet for this question.

Full CGRC Practice