CGRC · Question #630
Who has the authority to divide a complex system in order to establish realistic security authorization boundaries? Response:
The correct answer is B. Authorizing Official (AO) and Information System Security Officer (ISSO). The Authorizing Official (AO) and the Information System Security Officer (ISSO) collaboratively hold the authority to divide complex systems to establish realistic security authorization boundaries. This collaboration ensures effective risk management and clear security scope.
Question
Who has the authority to divide a complex system in order to establish realistic security authorization boundaries? Response:
Options
- AAuthorizing Official (AO) and Senior Information Security Officer (SISO)
- BAuthorizing Official (AO) and Information System Security Officer (ISSO)
- CSecurity Control Assessor (SCA) and Risk Executive
- DSecurity Control Assessor (SCA) and Information System Security Officer (ISSO)
How the community answered
(27 responses)- A4% (1)
- B89% (24)
- C7% (2)
Why each option
The Authorizing Official (AO) and the Information System Security Officer (ISSO) collaboratively hold the authority to divide complex systems to establish realistic security authorization boundaries. This collaboration ensures effective risk management and clear security scope.
While the AO has authority, the Senior Information Security Officer (SISO) typically focuses on enterprise-level security policy and strategy, not the specific definition or division of individual system authorization boundaries.
The Authorizing Official (AO) bears ultimate responsibility for making risk management decisions, including defining authorization boundaries. The Information System Security Officer (ISSO) provides essential technical and security expertise to the AO, advising on the practical aspects of system boundaries and assisting in proposals to divide complex systems to achieve realistic and manageable security accreditation scopes.
The Security Control Assessor (SCA) is responsible for assessing security controls, not for establishing or dividing authorization boundaries. A Risk Executive focuses on broader organizational risk management.
While the ISSO advises on boundaries, the Security Control Assessor (SCA) does not possess the authority to establish or divide authorization boundaries for systems.
Concept tested: RMF roles and authorization boundaries
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.