nerdexam
(ISC)2

CGRC · Question #612

The security assessment plan is prepared to provide the Authorizing Official and other organizational officials with a plan of how the security assessment will be conducted. Which roles have the…

The correct answer is A. Authorizing official (AO), Authorizing Official Designated Representative (AODR), Security Control. The Security Control Assessor (SCA) holds the primary responsibility for preparing the security assessment plan, which outlines how the security assessment will be conducted. This process often involves coordination and oversight from the Authorizing Official (AO) and their…

Assessment/Audit of Security and Privacy Controls

Question

The security assessment plan is prepared to provide the Authorizing Official and other organizational officials with a plan of how the security assessment will be conducted. Which roles have the primary responsibility to prepare the security assessment plan? Response:

Options

  • AAuthorizing official (AO), Authorizing Official Designated Representative (AODR), Security Control
  • BInformation System Owner (ISO), Security Control Assessor (SCA), Information System Security
  • CAuthorizing official (AO), Authorizing Official Designated Representative (AODR), Information
  • DAuthorizing official (AO), Information System Owner (ISO), Security Control Assessor (SCA)

How the community answered

(39 responses)
  • A
    92% (36)
  • C
    5% (2)
  • D
    3% (1)

Why each option

The Security Control Assessor (SCA) holds the primary responsibility for preparing the security assessment plan, which outlines how the security assessment will be conducted. This process often involves coordination and oversight from the Authorizing Official (AO) and their Designated Representative (AODR).

AAuthorizing official (AO), Authorizing Official Designated Representative (AODR), Security ControlCorrect

The Security Control Assessor (SCA) has the primary responsibility to prepare the Security Assessment Plan, outlining the scope and methodology for assessing security controls. The Authorizing Official (AO) and their Designated Representative (AODR) provide oversight and approval, ensuring the plan aligns with organizational risk tolerance and requirements.

BInformation System Owner (ISO), Security Control Assessor (SCA), Information System Security

The Information System Owner (ISO) is responsible for the system itself and its security, while the Information System Security Officer (ISSO) advises on security matters, but neither primarily prepares the assessment plan.

CAuthorizing official (AO), Authorizing Official Designated Representative (AODR), Information

This option incorrectly includes "Information" without a specific role, making it incomplete and inaccurate for the primary preparers of the security assessment plan.

DAuthorizing official (AO), Information System Owner (ISO), Security Control Assessor (SCA)

The Information System Owner (ISO) is responsible for the system's overall security and operation, but the Security Control Assessor (SCA) is the one who drafts the security assessment plan.

Concept tested: NIST RMF roles for Security Assessment Plan

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Security Assessment Planning#Roles and Responsibilities#Authorizing Official (AO)#Security Control Assessor (SCA)

Community Discussion

No community discussion yet for this question.

Full CGRC Practice