CGRC · Question #612
The security assessment plan is prepared to provide the Authorizing Official and other organizational officials with a plan of how the security assessment will be conducted. Which roles have the…
The correct answer is A. Authorizing official (AO), Authorizing Official Designated Representative (AODR), Security Control. The Security Control Assessor (SCA) holds the primary responsibility for preparing the security assessment plan, which outlines how the security assessment will be conducted. This process often involves coordination and oversight from the Authorizing Official (AO) and their…
Question
The security assessment plan is prepared to provide the Authorizing Official and other organizational officials with a plan of how the security assessment will be conducted. Which roles have the primary responsibility to prepare the security assessment plan? Response:
Options
- AAuthorizing official (AO), Authorizing Official Designated Representative (AODR), Security Control
- BInformation System Owner (ISO), Security Control Assessor (SCA), Information System Security
- CAuthorizing official (AO), Authorizing Official Designated Representative (AODR), Information
- DAuthorizing official (AO), Information System Owner (ISO), Security Control Assessor (SCA)
How the community answered
(39 responses)- A92% (36)
- C5% (2)
- D3% (1)
Why each option
The Security Control Assessor (SCA) holds the primary responsibility for preparing the security assessment plan, which outlines how the security assessment will be conducted. This process often involves coordination and oversight from the Authorizing Official (AO) and their Designated Representative (AODR).
The Security Control Assessor (SCA) has the primary responsibility to prepare the Security Assessment Plan, outlining the scope and methodology for assessing security controls. The Authorizing Official (AO) and their Designated Representative (AODR) provide oversight and approval, ensuring the plan aligns with organizational risk tolerance and requirements.
The Information System Owner (ISO) is responsible for the system itself and its security, while the Information System Security Officer (ISSO) advises on security matters, but neither primarily prepares the assessment plan.
This option incorrectly includes "Information" without a specific role, making it incomplete and inaccurate for the primary preparers of the security assessment plan.
The Information System Owner (ISO) is responsible for the system's overall security and operation, but the Security Control Assessor (SCA) is the one who drafts the security assessment plan.
Concept tested: NIST RMF roles for Security Assessment Plan
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.