CGRC · Question #98
NIST SP 800-37 defines this role as an organizational official responsible for the development, implementation, assessment, and monitoring of common controls (i.e., security controls inherited by…
The correct answer is A. Common Controls Provider. NIST SP 800-37 defines the 'Common Controls Provider' as the organizational official responsible for the comprehensive management of security controls that are inherited by multiple information systems.
Question
NIST SP 800-37 defines this role as an organizational official responsible for the development, implementation, assessment, and monitoring of common controls (i.e., security controls inherited by information systems). Response:
Options
- ACommon Controls Provider
- BImplement Controls
- CSecurity Controls
- DCommon Controls
How the community answered
(38 responses)- A95% (36)
- C3% (1)
- D3% (1)
Why each option
NIST SP 800-37 defines the 'Common Controls Provider' as the organizational official responsible for the comprehensive management of security controls that are inherited by multiple information systems.
NIST SP 800-37 Rev. 2 defines the 'Common Controls Provider' as the organizational official who is accountable for the development, implementation, assessment, and continuous monitoring of common controls that are shared across and inherited by multiple information systems. This role ensures consistent security posture for shared services.
The phrase 'Implement Controls' describes an activity or process within the RMF, not an organizational role.
'Security Controls' refers to the safeguards themselves, not a person or role responsible for them.
'Common Controls' refers to the specific type of security controls that are inherited, not the official responsible for their management.
Concept tested: NIST RMF roles - Common Controls Provider
Source: https://csrc.nist.gov/projects/risk-management-framework/key-rmf-roles
Topics
Community Discussion
No community discussion yet for this question.