CGRC · Question #72
The official primarily responsibility for security of an Info System; who establishes sensitivity level and types of controls required to protect the IS and initiates system authorization activities.
The correct answer is A. Information System Owner. The Information System Owner is the individual primarily responsible for the security of an information system, including determining its sensitivity and required controls. This role is crucial in initiating system authorization activities within an organization.
Question
The official primarily responsibility for security of an Info System; who establishes sensitivity level and types of controls required to protect the IS and initiates system authorization activities. Response:
Options
- AInformation System Owner
- BSystem Development Life-Cycle
- CRisk Management Framework
- DDesignated Representative
How the community answered
(29 responses)- A93% (27)
- C3% (1)
- D3% (1)
Why each option
The Information System Owner is the individual primarily responsible for the security of an information system, including determining its sensitivity and required controls. This role is crucial in initiating system authorization activities within an organization.
The Information System Owner holds the primary responsibility for the overall security of an information system, defining its criticality and the security controls needed. They are also responsible for initiating and supporting the system's authorization process, ensuring its compliance with organizational and federal security policies.
The System Development Life-Cycle (SDLC) is a process for developing and maintaining systems, not an individual responsible for security.
The Risk Management Framework (RMF) is a structured process for managing security risks, not an individual responsible for security.
While a Designated Representative might act on behalf of an owner, the core responsibility lies with the Information System Owner.
Concept tested: Information System Owner responsibilities
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.