191k views
1 vote
Which role in the security authorization process is responsible for organizational information systems?

a. is program manager
b. designated authorizing official
c. certification agent
d. user representative

User Falguni
by
7.4k points

1 Answer

6 votes

Final answer:

B. Designated Authorizing Official is responsible for organizational information systems in the security authorization process and has the authority to formally assume responsibility

Step-by-step explanation:

The role in the security authorization process responsible for organizational information systems is the Designated Authorizing Official (DAO). The DAO is accountable for the security of the system and has the authority to formally assume responsibility for operating a system at an acceptable level of risk.

While the IS Program Manager may be involved in overseeing the program that includes the information system, and a Certification Agent (also known as a Security Control Assessor) evaluates the security controls, it is the DAO's role to grant the system authorization to operate.

A User Representative provides input on system requirements and ensures the system meets the needs of the user, but does not have the responsibility to authorize system operation.

User Mesmin
by
7.8k points