nerdexam
(ISC)2

CGRC · Question #72

The official primarily responsibility for security of an Info System; who establishes sensitivity level and types of controls required to protect the IS and initiates system authorization activities.

The correct answer is A. Information System Owner. The Information System Owner is the individual primarily responsible for the security of an information system, including determining its sensitivity and required controls. This role is crucial in initiating system authorization activities within an organization.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The official primarily responsibility for security of an Info System; who establishes sensitivity level and types of controls required to protect the IS and initiates system authorization activities. Response:

Options

  • AInformation System Owner
  • BSystem Development Life-Cycle
  • CRisk Management Framework
  • DDesignated Representative

How the community answered

(29 responses)
  • A
    93% (27)
  • C
    3% (1)
  • D
    3% (1)

Why each option

The Information System Owner is the individual primarily responsible for the security of an information system, including determining its sensitivity and required controls. This role is crucial in initiating system authorization activities within an organization.

AInformation System OwnerCorrect

The Information System Owner holds the primary responsibility for the overall security of an information system, defining its criticality and the security controls needed. They are also responsible for initiating and supporting the system's authorization process, ensuring its compliance with organizational and federal security policies.

BSystem Development Life-Cycle

The System Development Life-Cycle (SDLC) is a process for developing and maintaining systems, not an individual responsible for security.

CRisk Management Framework

The Risk Management Framework (RMF) is a structured process for managing security risks, not an individual responsible for security.

DDesignated Representative

While a Designated Representative might act on behalf of an owner, the core responsibility lies with the Information System Owner.

Concept tested: Information System Owner responsibilities

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#System Owner#Roles and Responsibilities#Information Security Governance#System Authorization

Community Discussion

No community discussion yet for this question.

Full CGRC Practice