nerdexam
(ISC)2

CGRC · Question #85

Which of the following individuals is responsible for ensuring the security posture of the organization's information system? Response:

The correct answer is A. Authorizing Official. The Authorizing Official (AO) holds the ultimate responsibility for accepting the risk associated with an information system's operation and for ensuring its overall security posture.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following individuals is responsible for ensuring the security posture of the organization's information system? Response:

Options

  • AAuthorizing Official
  • BChief Information Officer
  • CSecurity Control Assessor
  • DCommon Control Provider

How the community answered

(29 responses)
  • A
    90% (26)
  • B
    3% (1)
  • D
    7% (2)

Why each option

The Authorizing Official (AO) holds the ultimate responsibility for accepting the risk associated with an information system's operation and for ensuring its overall security posture.

AAuthorizing OfficialCorrect

The Authorizing Official (AO) is a senior federal agency official with the authority to formally assume responsibility for operating an information system at an acceptable level of risk. This role involves reviewing the security documentation and assessment results, making a risk determination, and granting an Authorization to Operate (ATO) for the system, thereby ensuring its security posture is acceptable.

BChief Information Officer

The Chief Information Officer (CIO) is responsible for overall IT strategy and management, but the AO is specifically responsible for the risk acceptance and security posture of individual systems.

CSecurity Control Assessor

A Security Control Assessor (SCA) evaluates the security controls, but does not ultimately authorize the system to operate or bear the responsibility for its security posture.

DCommon Control Provider

A Common Control Provider is responsible for implementing and managing common controls shared by multiple systems, but the AO still makes the risk decision for systems using those controls.

Concept tested: NIST RMF roles and responsibilities (Authorizing Official)

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Authorizing Official (AO)#Roles and Responsibilities#Information Security Posture#Risk Management Framework (RMF)

Community Discussion

No community discussion yet for this question.

Full CGRC Practice