nerdexam
(ISC)2

CGRC · Question #601

Who initiates system authorization process and has the full responsibility over the life cycle of an information system? Response:

The correct answer is B. Information System Owner (ISO). The Information System Owner (ISO) initiates the system authorization process and bears overall responsibility for the information system throughout its entire lifecycle.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Who initiates system authorization process and has the full responsibility over the life cycle of an information system? Response:

Options

  • ASecurity Control Assessor (SCA) and Risk Executive
  • BInformation System Owner (ISO)
  • CAuthorizing Official (AO)
  • DInformation System Security Officer (ISSO)

How the community answered

(63 responses)
  • A
    5% (3)
  • B
    90% (57)
  • C
    2% (1)
  • D
    3% (2)

Why each option

The Information System Owner (ISO) initiates the system authorization process and bears overall responsibility for the information system throughout its entire lifecycle.

ASecurity Control Assessor (SCA) and Risk Executive

A Security Control Assessor (SCA) conducts assessments, and a Risk Executive provides enterprise-wide risk management direction, but neither holds the primary lifecycle responsibility for a specific system.

BInformation System Owner (ISO)Correct

The Information System Owner (ISO) is the individual with statutory, contractual, or operational responsibility for an information system, including its development, deployment, and disposal, and thus initiates and maintains overall responsibility for its authorization and lifecycle management.

CAuthorizing Official (AO)

The Authorizing Official (AO) makes the final decision to authorize or deny system operation but does not possess the full lifecycle responsibility for the system's management and operation.

DInformation System Security Officer (ISSO)

The Information System Security Officer (ISSO) advises on and monitors the system's security posture but does not have the ultimate responsibility for the system's entire lifecycle.

Concept tested: Roles and Responsibilities in NIST RMF

Source: https://www.nist.gov/system/files/documents/2019/12/26/sp800-37r2-final.pdf

Topics

#Information System Owner (ISO)#System Life Cycle#Authorization Process#Roles and Responsibilities

Community Discussion

No community discussion yet for this question.

Full CGRC Practice