CGRC · Question #643
Which of the following roles is not one of those with primary responsibility for ongoing risk response? Response:
The correct answer is C. Information Owner. The Information Owner is not typically identified as having primary responsibility for ongoing risk response, unlike the Authorizing Official, Information System Owner, and Common Control Provider. Their role is more focused on the data itself, rather than the system's…
Question
Which of the following roles is not one of those with primary responsibility for ongoing risk response? Response:
Options
- AAuthorizing Official (AO)
- BInformation System Owner (ISO)
- CInformation Owner
- DCommon Control Provider
How the community answered
(25 responses)- A8% (2)
- B4% (1)
- C88% (22)
Why each option
The Information Owner is not typically identified as having primary responsibility for ongoing risk response, unlike the Authorizing Official, Information System Owner, and Common Control Provider. Their role is more focused on the data itself, rather than the system's operational risks.
The Authorizing Official (AO) retains ongoing accountability for the system's risk and ensures that risks are managed throughout its lifecycle.
The Information System Owner (ISO) has primary responsibility for the day-to-day operations and security of the system, including managing and responding to identified risks.
The Information Owner is responsible for the information's content, classification, and access policies, but primary responsibility for ongoing risk response related to the information system typically falls to roles like the AO, ISO, or CCP.
The Common Control Provider (CCP) is responsible for managing and responding to risks specifically associated with the common controls they provide across multiple systems.
Concept tested: RMF roles in ongoing risk response
Source: https://csrc.nist.gov/glossary/term/information_owner
Topics
Community Discussion
No community discussion yet for this question.