nerdexam
(ISC)2

CGRC · Question #630

Who has the authority to divide a complex system in order to establish realistic security authorization boundaries? Response:

The correct answer is B. Authorizing Official (AO) and Information System Security Officer (ISSO). The Authorizing Official (AO) and the Information System Security Officer (ISSO) collaboratively hold the authority to divide complex systems to establish realistic security authorization boundaries. This collaboration ensures effective risk management and clear security scope.

Scope of the System

Question

Who has the authority to divide a complex system in order to establish realistic security authorization boundaries? Response:

Options

  • AAuthorizing Official (AO) and Senior Information Security Officer (SISO)
  • BAuthorizing Official (AO) and Information System Security Officer (ISSO)
  • CSecurity Control Assessor (SCA) and Risk Executive
  • DSecurity Control Assessor (SCA) and Information System Security Officer (ISSO)

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    89% (24)
  • C
    7% (2)

Why each option

The Authorizing Official (AO) and the Information System Security Officer (ISSO) collaboratively hold the authority to divide complex systems to establish realistic security authorization boundaries. This collaboration ensures effective risk management and clear security scope.

AAuthorizing Official (AO) and Senior Information Security Officer (SISO)

While the AO has authority, the Senior Information Security Officer (SISO) typically focuses on enterprise-level security policy and strategy, not the specific definition or division of individual system authorization boundaries.

BAuthorizing Official (AO) and Information System Security Officer (ISSO)Correct

The Authorizing Official (AO) bears ultimate responsibility for making risk management decisions, including defining authorization boundaries. The Information System Security Officer (ISSO) provides essential technical and security expertise to the AO, advising on the practical aspects of system boundaries and assisting in proposals to divide complex systems to achieve realistic and manageable security accreditation scopes.

CSecurity Control Assessor (SCA) and Risk Executive

The Security Control Assessor (SCA) is responsible for assessing security controls, not for establishing or dividing authorization boundaries. A Risk Executive focuses on broader organizational risk management.

DSecurity Control Assessor (SCA) and Information System Security Officer (ISSO)

While the ISSO advises on boundaries, the Security Control Assessor (SCA) does not possess the authority to establish or divide authorization boundaries for systems.

Concept tested: RMF roles and authorization boundaries

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#System authorization boundaries#Authorizing Official (AO) responsibilities#Information System Security Officer (ISSO) responsibilities#System scope definition

Community Discussion

No community discussion yet for this question.

Full CGRC Practice