Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 Exam CSSLP Topic 1 Question 90 Discussion

Actual exam question for ISC2's CSSLP exam
Question #: 90
Topic #: 1
[All CSSLP Questions]

Who amongst the following makes the final accreditation decision?

Show Suggested Answer Hide Answer
Suggested Answer: C

The DAA, also known as Authorizing Official, makes the final accreditation decision. The Designated Approving Authority (DAA), in the United

States Department of Defense, is the official with the authority to formally assume responsibility for operating a system at an acceptable level

of risk. The DAA is responsible for implementing system security. The DAA can grant the accreditation and can determine that the system's

risks are not at an acceptable level and the system is not ready to be operational.

Answer D is incorrect. An Information System Security Officer (ISSO) plays the role of a supporter. The responsibilities of an Information

System Security Officer (ISSO) are as follows:

Manages the security of the information system that is slated for Certification & Accreditation (C&A).

Insures the information systems configuration with the agency's information security policy.

Supports the information system owner/information owner for the completion of security-related responsibilities.

Takes part in the formal configuration management process.

Prepares Certification & Accreditation (C&A) packages.

Answer A is incorrect. An Information System Security Engineer (ISSE) plays the role of an advisor. The responsibilities of an

Information System Security Engineer are as follows:

Provides view on the continuous monitoring of the information system.

Provides advice on the impacts of system changes.

Takes part in the configuration management process.

Takes part in the development activities that are required to implement system changes.

Follows approved system changes.

Answer B is incorrect. A Chief Risk Officer (CRO) is also known as Chief Risk Management Officer (CRMO). The Chief Risk Officer or Chief

Risk Management Officer of a corporation is the executive accountable for enabling the efficient and effective governance of significant risks,

and related opportunities, to a business and its various segments. Risks are commonly categorized as strategic, reputational, operational,

financial, or compliance-related. CRO's are accountable to the Executive Committee and The Board for enabling the business to balance risk

and reward. In more complex organizations, they are generally responsible for coordinating the organization's Enterprise Risk Management

(ERM) approach.


Contribute your Thoughts:

Dick
4 months ago
If the DAA doesn't make the final accreditation decision, I'm going to have to re-evaluate my entire career path. That's gotta be the right answer.
upvoted 0 times
...
Ashley
4 months ago
I bet the ISSO is the one who gets to play 'accreditation superhero' and save the day. Just kidding, but I'm pretty sure it's the CRO.
upvoted 0 times
Yvonne
3 months ago
Well, I guess we'll have to wait and see who the real 'accreditation superhero' is!
upvoted 0 times
...
Luke
3 months ago
I'm going to have to disagree with both of you, I believe it's the CRO who makes the final decision.
upvoted 0 times
...
Emmanuel
3 months ago
No way, I'm pretty sure it's the ISSE who has the final say.
upvoted 0 times
...
Lawrence
4 months ago
I think it's actually the DAA who makes the final accreditation decision.
upvoted 0 times
...
...
Adelina
5 months ago
The ISSE? Really? That's like asking the intern to make the big decisions. Clearly, the CRO is the one in charge here.
upvoted 0 times
Bong
3 months ago
Yeah, the ISSE may have a role, but the final decision lies with the CRO.
upvoted 0 times
...
Odette
3 months ago
I agree, the CRO is the one in charge of the accreditation decision.
upvoted 0 times
...
Angelo
3 months ago
ISSE is not the one making the final decision, it's definitely the CRO.
upvoted 0 times
...
Celestina
3 months ago
Yeah, the ISSE seems like they wouldn't have the authority to make such a big decision.
upvoted 0 times
...
Loreta
3 months ago
I agree, the CRO is definitely the one in charge here.
upvoted 0 times
...
Cassie
4 months ago
ISSE? No way, the CRO is the one who makes the final accreditation decision.
upvoted 0 times
...
...
Janna
5 months ago
Because ISSE is usually responsible for final decisions in our organization.
upvoted 0 times
...
Justine
5 months ago
Wait, doesn't the ISSO have the final say on accreditation decisions? I'm a little confused on this one.
upvoted 0 times
...
Naomi
5 months ago
Hmm, I'm leaning towards the DAA as the one who makes the final call. They're the decision authority, after all.
upvoted 0 times
Willis
4 months ago
I'm not so sure, I believe it's the ISSO who makes the final call.
upvoted 0 times
...
Honey
4 months ago
No, it's definitely the DAA. They have the ultimate authority in the process.
upvoted 0 times
...
Irma
4 months ago
Really? I always thought it was the ISSE who had the final say.
upvoted 0 times
...
An
5 months ago
I think it's actually the CRO who makes the final accreditation decision.
upvoted 0 times
...
...
Luther
5 months ago
Why do you think it's ISSE?
upvoted 0 times
...
Denny
5 months ago
The CRO is the one who makes the final accreditation decision, right? I'm pretty sure that's the correct answer.
upvoted 0 times
Joanna
4 months ago
That's right, the CRO is the one who makes the final accreditation decision.
upvoted 0 times
...
Lajuana
5 months ago
Yes, you are correct. The CRO is the one who makes the final accreditation decision.
upvoted 0 times
...
...
Janna
5 months ago
I believe it's A) ISSE.
upvoted 0 times
...
Luther
6 months ago
I think it's C) DAA.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77