CGRC · Question #690
Which of the following organizational officials have the primary responsibility for putting together the authorization package? Response:
The correct answer is C. The Senior Agency Official for Privacy, CCP, and ISO. The primary responsibility for compiling the authorization package typically lies with the Senior Agency Official for Privacy (SAOP), the Common Control Provider (CCP) for inherited controls, and the Information System Owner (ISO), as they collectively manage privacy, common cont
Question
Which of the following organizational officials have the primary responsibility for putting together the authorization package? Response:
Options
- AThe ISO, SCA, and CCP
- BThe CCP, ISO, and CIO
- CThe Senior Agency Official for Privacy, CCP, and ISO
- DThe Senior Agency Official for Privacy, ISO, and AO
How the community answered
(39 responses)- A5% (2)
- B3% (1)
- C90% (35)
- D3% (1)
Why each option
The primary responsibility for compiling the authorization package typically lies with the Senior Agency Official for Privacy (SAOP), the Common Control Provider (CCP) for inherited controls, and the Information System Owner (ISO), as they collectively manage privacy, common control implementation, and system-specific security details.
The Security Control Assessor (SCA) conducts the assessment and produces the Security Assessment Report, but they do not typically put together the entire authorization package.
The Chief Information Officer (CIO) often has oversight but is not typically the primary individual putting together the detailed package, which is more operational/system-owner focused.
The authorization package is a comprehensive collection of documents that supports the Authorization Official's (AO) decision. Key roles involved in putting together this package include the Senior Agency Official for Privacy (SAOP) for privacy-related aspects, the Common Control Provider (CCP) for documentation related to common controls, and the Information System Owner (ISO) who is ultimately responsible for the system's security plan and overall authorization.
While the AO makes the authorization decision, they do not typically put together the package; rather, they review and act upon it.
Concept tested: RMF Roles and Responsibilities (Authorization Package)
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev2/final
Topics
Community Discussion
No community discussion yet for this question.