nerdexam
(ISC)2

CSSLP · Question #21

The Information System Security Officer (ISSO) and Information System Security Engineer (ISSE) play the role of a supporter and advisor, respectively. Which of the following statements are true about

The correct answer is B. An ISSE provides advice on the continuous monitoring of the information system. C. An ISSO manages the security of the information system that is slated for Certification & Accreditation (C&A). D. An ISSE provides advice on the impacts of system changes.. The ISSO manages system security for C&A, while the ISSE advises on continuous monitoring and the impacts of system changes.

Secure Software Deployment, Operations, Maintenance

Question

The Information System Security Officer (ISSO) and Information System Security Engineer (ISSE) play the role of a supporter and advisor, respectively. Which of the following statements are true about ISSO and ISSE? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AAn ISSE manages the security of the information system that is slated for Certification & Accreditation (C&A).
  • BAn ISSE provides advice on the continuous monitoring of the information system.
  • CAn ISSO manages the security of the information system that is slated for Certification & Accreditation (C&A).
  • DAn ISSE provides advice on the impacts of system changes.
  • EAn ISSO takes part in the development activities that are required to implement system changes.

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    93% (38)
  • E
    5% (2)

Why each option

The ISSO manages system security for C&A, while the ISSE advises on continuous monitoring and the impacts of system changes.

AAn ISSE manages the security of the information system that is slated for Certification & Accreditation (C&A).

An ISSE provides engineering advice and guidance for system security; they do not typically hold the management responsibility for the overall security of an information system undergoing C&A, which falls to the ISSO or System Owner.

BAn ISSE provides advice on the continuous monitoring of the information system.Correct

An ISSE (Information System Security Engineer) provides expert technical advice on how to secure information systems throughout their lifecycle, which includes recommendations and guidance on continuous monitoring strategies and implementation.

CAn ISSO manages the security of the information system that is slated for Certification & Accreditation (C&A).Correct

An ISSO (Information System Security Officer) is typically responsible for managing the overall security posture of an information system, including its preparation for and maintenance through the Certification & Accreditation (C&A), now commonly Risk Management Framework (RMF), process.

DAn ISSE provides advice on the impacts of system changes.Correct

An ISSE, as a security engineering expert, is well-suited to provide technical advice and analysis on the security impacts of proposed system changes, ensuring that modifications do not introduce new vulnerabilities or compromise existing controls.

EAn ISSO takes part in the development activities that are required to implement system changes.

While an ISSO works closely with development teams, their primary role is security oversight and management, not direct participation in the technical development activities required to implement system changes.

Concept tested: Roles and responsibilities of ISSO and ISSE

Source: https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/final

Topics

#ISSO roles#ISSE roles#Certification & Accreditation (C&A)#Continuous Monitoring

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice