CGRC · Question #701
Which of the following roles is also known as the accreditor? Response:
The correct answer is C. Designated Approving Authority. The Designated Approving Authority (DAA) is the individual responsible for formally accepting the risk associated with operating an information system, a role often referred to as the accreditor. This authority grants authorization to operate based on security assessments.
Question
Which of the following roles is also known as the accreditor? Response:
Options
- AChief Risk Officer
- BData owner
- CDesignated Approving Authority
- DChief Information Officer
How the community answered
(62 responses)- A2% (1)
- B3% (2)
- C89% (55)
- D6% (4)
Why each option
The Designated Approving Authority (DAA) is the individual responsible for formally accepting the risk associated with operating an information system, a role often referred to as the accreditor. This authority grants authorization to operate based on security assessments.
The Chief Risk Officer (CRO) oversees risk management across the organization but is not specifically the accreditor for individual systems.
A Data Owner is responsible for the classification and protection of specific data, not the accreditation of the entire system.
The Designated Approving Authority (DAA) is the official who has the authority to formally assume responsibility for operating a system at an acceptable level of risk. This individual is responsible for making the decision to authorize a system to operate (ATO) and is often referred to as the accreditor because they grant official accreditation based on the system's security posture and risk assessment.
The Chief Information Officer (CIO) manages IT resources and strategy but typically delegates the system-level accreditation decision to the DAA.
Concept tested: Designated Approving Authority (DAA) role
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.