QuestionQ229

Secure Software Lifecycle Management

The Chief Information Officer (CIO), or Information Technology (IT) director, is a title commonly assigned to the most senior executive in an enterprise. What are the responsibilities of a Chief Information Officer? Each correct answer represents a complete solution. Choose all that apply.

Choose three
  • A Facilitating the sharing of security risk-related information among authorizing officials
  • B Preserving high-level communications and working group relationships in an organization
  • C Establishing effective continuous monitoring program for the organization
  • D Proposing the information technology needed by an enterprise to achieve its goals and then working within a budget to implement the plan
Explanation

A CIO provides enterprise IT leadership: defining and resourcing technology needed to meet organizational goals, maintaining cross-organizational executive and working-group relationships, and ensuring an effective continuous-monitoring program. Under the NIST Risk Management Framework, facilitating the sharing of security risk-related information among authorizing officials is a responsibility of the Risk Executive (function), rather than the CIO.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!