CGRC · Question #105
During an annual assessment, numerous high-risk findings are discovered on a critical organizational system. The system's Federal Information Processing Standard (FIPS) 199 rating is "high" integrity,
The correct answer is A. The authorizing official should deny operation of the system until risk is reduced to an acceptable. Given high-risk findings on a critical system and a very low organizational risk tolerance, the authorizing official should deny system operation until identified risks are reduced to an acceptable level.
Question
During an annual assessment, numerous high-risk findings are discovered on a critical organizational system. The system's Federal Information Processing Standard (FIPS) 199 rating is "high" integrity, "high" confidentiality, and "low" availability. The organization has a very low risk tolerance. What is the best decision that should be made in this situation? Response:
Options
- AThe authorizing official should deny operation of the system until risk is reduced to an acceptable
- BThe information system owner should resolve issues as quickly as possible while keeping the
- CThe security control assessor should implement immediate compensating controls.
- DThe chief information security officer should scope and tailor the weak controls to ensure proper
How the community answered
(60 responses)- A73% (44)
- B8% (5)
- C3% (2)
- D15% (9)
Why each option
Given high-risk findings on a critical system and a very low organizational risk tolerance, the authorizing official should deny system operation until identified risks are reduced to an acceptable level.
The authorizing official (AO) is ultimately responsible for making a risk-based decision to authorize the operation of an information system. With numerous high-risk findings, a "high" FIPS 199 rating for confidentiality and integrity, and a very low risk tolerance, the AO must prioritize reducing the risk to an acceptable level before granting authorization, even if it means denying continued operation.
While the information system owner is responsible for resolving issues, simply resolving them "as quickly as possible" without an explicit decision from the AO, especially given high risk and low tolerance, is insufficient and doesn't address the immediate authorization status.
The security control assessor's role is to assess and report, not to implement controls; implementation is the responsibility of system developers or administrators.
The CISO's role involves overseeing security, but scoping and tailoring controls are typically done during the initial control selection and implementation phases, not as a primary response to numerous high-risk findings after an assessment, especially when the organization has low risk tolerance.
Concept tested: Authorizing Official's risk-based decision making.
Source: https://csrc.nist.gov/glossary/term/authorizing_official
Topics
Community Discussion
No community discussion yet for this question.