nerdexam
(ISC)2

CGRC · Question #643

Which of the following roles is not one of those with primary responsibility for ongoing risk response? Response:

The correct answer is C. Information Owner. The Information Owner is not typically identified as having primary responsibility for ongoing risk response, unlike the Authorizing Official, Information System Owner, and Common Control Provider. Their role is more focused on the data itself, rather than the system's…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following roles is not one of those with primary responsibility for ongoing risk response? Response:

Options

  • AAuthorizing Official (AO)
  • BInformation System Owner (ISO)
  • CInformation Owner
  • DCommon Control Provider

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    88% (22)

Why each option

The Information Owner is not typically identified as having primary responsibility for ongoing risk response, unlike the Authorizing Official, Information System Owner, and Common Control Provider. Their role is more focused on the data itself, rather than the system's operational risks.

AAuthorizing Official (AO)

The Authorizing Official (AO) retains ongoing accountability for the system's risk and ensures that risks are managed throughout its lifecycle.

BInformation System Owner (ISO)

The Information System Owner (ISO) has primary responsibility for the day-to-day operations and security of the system, including managing and responding to identified risks.

CInformation OwnerCorrect

The Information Owner is responsible for the information's content, classification, and access policies, but primary responsibility for ongoing risk response related to the information system typically falls to roles like the AO, ISO, or CCP.

DCommon Control Provider

The Common Control Provider (CCP) is responsible for managing and responding to risks specifically associated with the common controls they provide across multiple systems.

Concept tested: RMF roles in ongoing risk response

Source: https://csrc.nist.gov/glossary/term/information_owner

Topics

#Risk Management Roles#Ongoing Risk Response#Organizational Roles and Responsibilities#Information Security Governance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice