nerdexam
(ISC)2

CGRC · Question #690

Which of the following organizational officials have the primary responsibility for putting together the authorization package? Response:

The correct answer is C. The Senior Agency Official for Privacy, CCP, and ISO. The primary responsibility for compiling the authorization package typically lies with the Senior Agency Official for Privacy (SAOP), the Common Control Provider (CCP) for inherited controls, and the Information System Owner (ISO), as they collectively manage privacy, common cont

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following organizational officials have the primary responsibility for putting together the authorization package? Response:

Options

  • AThe ISO, SCA, and CCP
  • BThe CCP, ISO, and CIO
  • CThe Senior Agency Official for Privacy, CCP, and ISO
  • DThe Senior Agency Official for Privacy, ISO, and AO

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    90% (35)
  • D
    3% (1)

Why each option

The primary responsibility for compiling the authorization package typically lies with the Senior Agency Official for Privacy (SAOP), the Common Control Provider (CCP) for inherited controls, and the Information System Owner (ISO), as they collectively manage privacy, common control implementation, and system-specific security details.

AThe ISO, SCA, and CCP

The Security Control Assessor (SCA) conducts the assessment and produces the Security Assessment Report, but they do not typically put together the entire authorization package.

BThe CCP, ISO, and CIO

The Chief Information Officer (CIO) often has oversight but is not typically the primary individual putting together the detailed package, which is more operational/system-owner focused.

CThe Senior Agency Official for Privacy, CCP, and ISOCorrect

The authorization package is a comprehensive collection of documents that supports the Authorization Official's (AO) decision. Key roles involved in putting together this package include the Senior Agency Official for Privacy (SAOP) for privacy-related aspects, the Common Control Provider (CCP) for documentation related to common controls, and the Information System Owner (ISO) who is ultimately responsible for the system's security plan and overall authorization.

DThe Senior Agency Official for Privacy, ISO, and AO

While the AO makes the authorization decision, they do not typically put together the package; rather, they review and act upon it.

Concept tested: RMF Roles and Responsibilities (Authorization Package)

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev2/final

Topics

#Authorization Package#RMF Roles#ISO#SAOP

Community Discussion

No community discussion yet for this question.

Full CGRC Practice