Study. uk . com
  1. Home
  2. All questions
  3. Question 617

CISM study material · question 617 of 1000

Who approves a system security plan before authorisation, and what makes that approval meaningful?

  1. The information owner, who owns the data that the system is putting at risk here
  2. The authorising official, who is independent of the system owner
  3. The system owner, who knows the system best
  4. The security officer, who wrote the control requirements the plan responds to
Show the answer

Answer: B. The authorising official, who is independent of the system owner

SP 800-100 states that prior to the certification and accreditation process, the authorising official, independent from the system owner, typically approves the plan.

Source: NIST SP 800-100 (NIST) — Sec. 8.4 System Security Plan Approval

Challenge yourself on this topic → Study as cards