CGRC · Question #671
Which of the following professionals is responsible for starting the Certification & Accreditation (C&A) process? Response:
The correct answer is A. Information system owner. The question asks who among the listed professionals is responsible for initiating the Certification & Accreditation (C&A) process for an information system.
Question
Which of the following professionals is responsible for starting the Certification & Accreditation (C&A) process? Response:
Options
- AInformation system owner
- BAuthorizing Official
- CChief Risk Officer (CRO)
- DChief Information Officer (CIO)
How the community answered
(37 responses)- A86% (32)
- B8% (3)
- C3% (1)
- D3% (1)
Why each option
The question asks who among the listed professionals is responsible for initiating the Certification & Accreditation (C&A) process for an information system.
The Information System Owner is ultimately responsible for the overall lifecycle of an information system, including its development, operation, maintenance, and eventual decommissioning, and is therefore responsible for initiating the C&A (now RMF Authorization) process to ensure the system's security and compliance throughout its operational life. They typically formally request the assessment and authorization.
The Authorizing Official (AO) is responsible for making the final decision to authorize (or deny authorization) a system, not for initiating the process.
A Chief Risk Officer (CRO) oversees enterprise-wide risk management but typically does not initiate individual system-level C&A processes.
A Chief Information Officer (CIO) has overall responsibility for IT, but the specific initiation of C&A for a given system falls to the system's dedicated owner.
Concept tested: C&A/RMF Roles and Responsibilities
Source: https://csrc.nist.gov/glossary/term/information_system_owner
Topics
Community Discussion
No community discussion yet for this question.