22. According to NIST SP 800-37 Rev 1, who is primarily responsible for the following TWO tasks? CHOOSE ALL THAT APPLY
TASK 6-3: Conduct remediation actions based on the results of ongoing monitoring activities, assessment of risk, and outstanding items in the plan of action and milestones.
TASK 6-4: Update the security plan, security assessment report, and plan of action and milestones based on the results of the continuous monitoring process.
The correct answer is:
Information System Owner (ISO)
TASK 6-3: Conduct remediation actions based on the results of ongoing monitoring activities, assessment of risk, and outstanding items in the plan of action and milestones.
Primary Responsibility: Information System Owner or Common Control Provider.
Supporting Roles: Authorizing Official or Designated Representative; Information Owner/Steward; Information System Security Officer; Information System Security Engineer; Security Control Assessor
TASK 6-4: Update the security plan, security assessment report, and plan of action and milestones based on the results of the continuous monitoring process.
Primary Responsibility: Information System Owner or Common Control Provider.
Supporting Roles: Information Owner/Steward; Information System Security Officer
Common Control Provider
TASK 6-3: Conduct remediation actions based on the results of ongoing monitoring activities, assessment of risk, and outstanding items in the plan of action and milestones.
Primary Responsibility: Information System Owner or Common Control Provider.
Supporting Roles: Authorizing Official or Designated Representative; Information Owner/Steward; Information System Security Officer; Information System Security Engineer; Security Control Assessor
TASK 6-4: Update the security plan, security assessment report, and plan of action and milestones based on the results of the continuous monitoring process.
Primary Responsibility: Information System Owner or Common Control Provider.
Supporting Roles: Information Owner/Steward; Information System Security Officer
The following answers are incorrect:
Information System Security Officer
TASK 6-3: Conduct remediation actions based on the results of ongoing monitoring activities, assessment of risk, and outstanding items in the plan of action and milestones.
Primary Responsibility: Information System Owner or Common Control Provider.
Supporting Roles: Authorizing Official or Designated Representative; Information Owner/Steward; Information System Security Officer; Information System Security Engineer; Security Control Assessor
TASK 6-4: Update the security plan, security assessment report, and plan of action and milestones based on the results of the continuous monitoring process.
Primary Responsibility: Information System Owner or Common Control Provider.
Supporting Roles: Information Owner/Steward; Information System Security Officer
Information Security Architect
TASK 6-3: Conduct remediation actions based on the results of ongoing monitoring activities, assessment of risk, and outstanding items in the plan of action and milestones.
Primary Responsibility: Information System Owner or Common Control Provider.
Supporting Roles: Authorizing Official or Designated Representative; Information Owner/Steward; Information System Security Officer; Information System Security Engineer; Security Control Assessor
TASK 6-4: Update the security plan, security assessment report, and plan of action and milestones based on the results of the continuous monitoring process.
Primary Responsibility: Information System Owner or Common Control Provider.
Supporting Roles: Information Owner/Steward; Information System Security Officer
Information System Security Engineer
TASK 6-3: Conduct remediation actions based on the results of ongoing monitoring activities, assessment of risk, and outstanding items in the plan of action and milestones.
Primary Responsibility: Information System Owner or Common Control Provider.
Supporting Roles: Authorizing Official or Designated Representative; Information Owner/Steward; Information System Security Officer; Information System Security Engineer; Security Control Assessor
TASK 6-4: Update the security plan, security assessment report, and plan of action and milestones based on the results of the continuous monitoring process.
Primary Responsibility: Information System Owner or Common Control Provider.
Supporting Roles: Information Owner/Steward; Information System Security Officer