nerdexam
(ISC)2

CGRC · Question #701

Which of the following roles is also known as the accreditor? Response:

The correct answer is C. Designated Approving Authority. The Designated Approving Authority (DAA) is the individual responsible for formally accepting the risk associated with operating an information system, a role often referred to as the accreditor. This authority grants authorization to operate based on security assessments.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following roles is also known as the accreditor? Response:

Options

  • AChief Risk Officer
  • BData owner
  • CDesignated Approving Authority
  • DChief Information Officer

How the community answered

(62 responses)
  • A
    2% (1)
  • B
    3% (2)
  • C
    89% (55)
  • D
    6% (4)

Why each option

The Designated Approving Authority (DAA) is the individual responsible for formally accepting the risk associated with operating an information system, a role often referred to as the accreditor. This authority grants authorization to operate based on security assessments.

AChief Risk Officer

The Chief Risk Officer (CRO) oversees risk management across the organization but is not specifically the accreditor for individual systems.

BData owner

A Data Owner is responsible for the classification and protection of specific data, not the accreditation of the entire system.

CDesignated Approving AuthorityCorrect

The Designated Approving Authority (DAA) is the official who has the authority to formally assume responsibility for operating a system at an acceptable level of risk. This individual is responsible for making the decision to authorize a system to operate (ATO) and is often referred to as the accreditor because they grant official accreditation based on the system's security posture and risk assessment.

DChief Information Officer

The Chief Information Officer (CIO) manages IT resources and strategy but typically delegates the system-level accreditation decision to the DAA.

Concept tested: Designated Approving Authority (DAA) role

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Roles and Responsibilities#Accreditation#Designated Approving Authority (DAA)#Authorization Process

Community Discussion

No community discussion yet for this question.

Full CGRC Practice