nerdexam
(ISC)2

CGRC · Question #652

Organization official that's responsible for procurement, development, integration, modification, operation, maintenance, and disposal of an Information System. Response:

The correct answer is A. Information System Owner. An Information System Owner is the official responsible for the entire lifecycle of an information system, from procurement to disposal.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Organization official that's responsible for procurement, development, integration, modification, operation, maintenance, and disposal of an Information System. Response:

Options

  • AInformation System Owner
  • BAuthorizing Official
  • CInformation Security Architect
  • DChief Information Officer

How the community answered

(51 responses)
  • A
    88% (45)
  • B
    4% (2)
  • C
    6% (3)
  • D
    2% (1)

Why each option

An Information System Owner is the official responsible for the entire lifecycle of an information system, from procurement to disposal.

AInformation System OwnerCorrect

The Information System Owner is assigned the responsibility for the procurement, development, integration, modification, operation, maintenance, and disposal of an information system, making them accountable for its entire lifecycle.

BAuthorizing Official

An Authorizing Official grants authorization for a system to operate based on an acceptable risk level, but does not manage its day-to-day or lifecycle activities.

CInformation Security Architect

An Information Security Architect designs and implements security solutions for systems but does not hold overall responsibility for the system's operational lifecycle.

DChief Information Officer

A Chief Information Officer typically manages the overall IT strategy and resources for an organization, not the specific lifecycle responsibilities for individual information systems.

Concept tested: Information System Owner responsibilities

Source: https://csrc.nist.gov/glossary/term/system-owner

Topics

#Information System Owner#Roles and Responsibilities#System Lifecycle Management#IT Governance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice