CAP · Question #404
Which of the following individuals makes the final accreditation decision?
The correct answer is B. DAA. The Designated Approving Authority (DAA) - also called the Authorizing Official - holds exclusive final authority to grant or deny system accreditation in government security frameworks.
Question
Which of the following individuals makes the final accreditation decision?
Options
- AISSE
- BDAA
- CCRO
- DISSO
How the community answered
(33 responses)- A3% (1)
- B94% (31)
- C3% (1)
Why each option
The Designated Approving Authority (DAA) - also called the Authorizing Official - holds exclusive final authority to grant or deny system accreditation in government security frameworks.
The Information Systems Security Engineer (ISSE) designs and implements security architecture and controls but does not hold accreditation decision authority.
The DAA, formalized as the Authorizing Official (AO) in NIST SP 800-37, is the senior management official with the authority to formally accept responsibility for operating an information system at an acceptable level of risk and to issue the Authorization to Operate (ATO). No other security role - engineer, officer, or risk officer - has this final decision-making authority; the DAA is ultimately accountable for the accreditation decision.
The Chief Risk Officer (CRO) manages enterprise-wide risk strategy but is not the designated authority responsible for making individual system accreditation decisions.
The Information System Security Officer (ISSO) manages day-to-day security operations and compliance activities for a system but does not have final accreditation decision authority.
Concept tested: Designated Approving Authority role in system accreditation
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.