nerdexam
(ISC)2

CGRC · Question #77

Which organization is responsible for procurement, development, integration, modification, operation, maintenance, and disposal of an Information System? Response:

The correct answer is A. Information System Owner. The Information System Owner is broadly responsible for the entire lifecycle of an information system, encompassing its procurement, development, operation, maintenance, and eventual disposal. This role ensures the system meets its mission while adhering to security policies…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which organization is responsible for procurement, development, integration, modification, operation, maintenance, and disposal of an Information System? Response:

Options

  • AInformation System Owner
  • BInformation system security engineer (ISSE)
  • CChief Information Officer (CIO)
  • DInformation security architect

How the community answered

(44 responses)
  • A
    93% (41)
  • B
    2% (1)
  • D
    5% (2)

Why each option

The Information System Owner is broadly responsible for the entire lifecycle of an information system, encompassing its procurement, development, operation, maintenance, and eventual disposal. This role ensures the system meets its mission while adhering to security policies throughout its existence.

AInformation System OwnerCorrect

The Information System Owner has cradle-to-grave responsibility for an information system, covering its entire lifecycle from initial procurement and development through to operation, maintenance, and ultimate disposal. This comprehensive oversight ensures accountability for the system's functionality and security.

BInformation system security engineer (ISSE)

An Information system security engineer (ISSE) focuses on the security aspects of system design and implementation, but not the overall lifecycle management.

CChief Information Officer (CIO)

A Chief Information Officer (CIO) has broader organizational IT responsibilities, but the Information System Owner is specifically accountable for a given system.

DInformation security architect

An Information security architect designs security solutions and frameworks, but does not typically manage the full lifecycle from procurement to disposal.

Concept tested: Information System Owner lifecycle responsibilities

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Information System Owner#System Lifecycle#Roles and Responsibilities#Accountability

Community Discussion

No community discussion yet for this question.

Full CGRC Practice