This is responsible for ensuring that the IAP is developed and implemented in accordance with regulatory and business requirements; allocates resources and foster commitment to the IAP
Chief Executive Officer (CEO)
This is responsible for the execution of overall IT program and delegate authority to the CISO for the management of the IAP
Chief Information Officer (CIO)
This is the focal point for IT management and governance of IT portfolios
Chief Information Officer (CIO)
Responsibilities of a Chief Information Officer (CIO)
This carries out the CIO’s security and privacy responsibilities under FISMA and is responsible for managing the IAP
Chief Information Security Officer (CISO)
Characteristics of a Chief Information Security Officer (CISO)
What does FISMA mean
Federal Information Security Management Act
Responsibilities of CISO
This is appointed by the CEO and is granted the authority to formally assume responsibility for operating an information system at an acceptable level of risk
Authorizing Official
True or false: The AO has budgetary oversight for an information system and is responsible for the mission/business operations supported by the system
True
They approve systems security plans (SSPs), memorandums of agreement or understanding (MOA/MOU), and plans of action and milestones (POA & Ms).
Authorizing Official
True or false: AOs can deny authorization to operate an information system if unacceptable risks exist
True
True or False: It is possible that a particular information system may involve multiple AOs
True
Responsibilities of the AO
Appointed by the CEO and serves as the focal point for the information system and is the central point of contact during the security authorization process
Information System Owner (ISO)
Responsibilities of the ISO
This is an official with regulatory, management, or operational authority for specified information and is responsible for establishing the policies and procedures governing its generation, collection, processing, dissemination, and disposal.
Information Owner
Responsibilities of Information Owner (IO)
Appointed by the ISO and works closely with the ISO or ISSM to ensure that the appropriate security posture is maintained for the information system
Information System Security Officer
True or False: The Information System Security Officer (ISSO) serves as a principal advisor on all the security related issues of an information system
True
This supports activities at the system level and includes physical and environmental protection, personnel security, incident handling, and security training and awareness
Information System Security Officer (ISSO)
Responsibilities of the Information System Security Officer (ISSO)
This serves as the primary liaison for the CISO to individuals with security and privacy responsibilities and supports activities at the IAP level
Information Assurance Manager (IAM)
Responsibilities of the Information Assurance Manager (IAM)