nerdexam
(ISC)2

CGRC · Question #671

Which of the following professionals is responsible for starting the Certification & Accreditation (C&A) process? Response:

The correct answer is A. Information system owner. The question asks who among the listed professionals is responsible for initiating the Certification & Accreditation (C&A) process for an information system.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following professionals is responsible for starting the Certification & Accreditation (C&A) process? Response:

Options

  • AInformation system owner
  • BAuthorizing Official
  • CChief Risk Officer (CRO)
  • DChief Information Officer (CIO)

How the community answered

(37 responses)
  • A
    86% (32)
  • B
    8% (3)
  • C
    3% (1)
  • D
    3% (1)

Why each option

The question asks who among the listed professionals is responsible for initiating the Certification & Accreditation (C&A) process for an information system.

AInformation system ownerCorrect

The Information System Owner is ultimately responsible for the overall lifecycle of an information system, including its development, operation, maintenance, and eventual decommissioning, and is therefore responsible for initiating the C&A (now RMF Authorization) process to ensure the system's security and compliance throughout its operational life. They typically formally request the assessment and authorization.

BAuthorizing Official

The Authorizing Official (AO) is responsible for making the final decision to authorize (or deny authorization) a system, not for initiating the process.

CChief Risk Officer (CRO)

A Chief Risk Officer (CRO) oversees enterprise-wide risk management but typically does not initiate individual system-level C&A processes.

DChief Information Officer (CIO)

A Chief Information Officer (CIO) has overall responsibility for IT, but the specific initiation of C&A for a given system falls to the system's dedicated owner.

Concept tested: C&A/RMF Roles and Responsibilities

Source: https://csrc.nist.gov/glossary/term/information_system_owner

Topics

#Certification & Accreditation (C&A)#Risk Management Framework (RMF)#Information System Owner#Roles and Responsibilities

Community Discussion

No community discussion yet for this question.

Full CGRC Practice