nerdexam
(ISC)2

CGRC · Question #60

Who has the responsibility to review and ensure that only substantive items are incorporated in the plan of action and milestones? Response:

The correct answer is C. Authorizing Official. The Authorizing Official (AO) is ultimately responsible for reviewing and approving the Plan of Action and Milestones (POA&M). This role ensures that all proposed remediations are substantive and effectively address identified deficiencies, reflecting the AO's acceptance of resid

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Who has the responsibility to review and ensure that only substantive items are incorporated in the plan of action and milestones? Response:

Options

  • AInformation System Owner
  • BCommon Control Provider
  • CAuthorizing Official
  • DInformation Owner

How the community answered

(42 responses)
  • B
    2% (1)
  • C
    95% (40)
  • D
    2% (1)

Why each option

The Authorizing Official (AO) is ultimately responsible for reviewing and approving the Plan of Action and Milestones (POA&M). This role ensures that all proposed remediations are substantive and effectively address identified deficiencies, reflecting the AO's acceptance of residual risk.

AInformation System Owner

The Information System Owner is typically responsible for developing and implementing the POA&M, but the Authorizing Official performs the final review and approval.

BCommon Control Provider

A Common Control Provider is responsible for implementing and managing common controls, not specifically for reviewing or approving POA&Ms for individual systems.

CAuthorizing OfficialCorrect

The Authorizing Official (AO) has the ultimate responsibility to review and approve the Plan of Action and Milestones (POA&M), ensuring that only substantive items that effectively address identified deficiencies are incorporated before authorizing a system to operate.

DInformation Owner

An Information Owner is responsible for the data within a system but does not hold the authorization responsibility for system operations or POA&M approval.

Concept tested: RMF roles and responsibilities-Authorizing Official

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Authorizing Official#POAM#Roles and Responsibilities#Risk Management

Community Discussion

No community discussion yet for this question.

Full CGRC Practice