Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 436 discussion

Actual exam question from ISC's CISSP
Question #: 436
Topic #: 1
[All CISSP Questions]

An organization needs to evaluate the effectiveness of security controls implemented on a new system. Which of the following roles should the organization entrust to conduct the evaluation?

  • A. Authorizing Official (AO)
  • B. System owner
  • C. Control assessor
  • D. Information System Security Officer (ISSO)
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
yottabyte
Highly Voted 1 year, 9 months ago
Selected Answer: C
As per NIST from google search: This role conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST SP 800-37).
upvoted 7 times
jackdryan
1 year, 6 months ago
C is correct
upvoted 1 times
...
...
Cyberjerry
Most Recent 6 months, 1 week ago
Selected Answer: C
OSG 9th Edition page 340. "An AO is an authorized entity who can evaluate an IT/IS system, its operations, and its risks, and potentially issue an ATO. Other terms for AO include designated approving authority (DAA), Approving Authority (AA), Security Control Assessor (SCA), and Recommending Official (RO)
upvoted 1 times
...
Soleandheel
11 months, 1 week ago
C. Control assessor. Control assessors, also known as security assessors or security auditors, are responsible for evaluating and assessing the security controls and safeguards in place within an information system. They conduct assessments, tests, and reviews to determine whether the controls are effectively mitigating security risks and complying with security policies, standards, and regulations.
upvoted 2 times
...
InclusiveSTEAM
1 year, 1 month ago
C) A control assessor should be entrusted to evaluate the effectiveness of newly implemented security controls on a system. Control assessors are specifically responsible for the impartial evaluation and testing of controls to provide an objective view of their implementation, effectiveness, and potential gaps. Their independent perspective makes them ideal for assessing new controls. The other roles have responsibilities that could introduce bias: A) The Authorizing Official authorizes system operation so may be incentivized to approve controls. B) The system owner is responsible for system security and implemented the controls, so is not independent. D) The ISSO may have been involved in control implementation and oversight.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...