CGRC · Question #200
"The authorization for the system or the common control is approved or denied" is an an outcome of which of the ensuing tasks? Response:
The correct answer is C. Authorization decision. The approval or denial of authorization for a system or common control is the direct outcome of the authorization decision task within the Risk Management Framework.
Question
"The authorization for the system or the common control is approved or denied" is an an outcome of which of the ensuing tasks? Response:
Options
- AAuthorization reporting
- BAuthorization package
- CAuthorization decision
- DRisk response
How the community answered
(28 responses)- B4% (1)
- C89% (25)
- D7% (2)
Why each option
The approval or denial of authorization for a system or common control is the direct outcome of the authorization decision task within the Risk Management Framework.
Authorization reporting involves communicating the status and outcomes of the authorization process, but it's not the decision itself.
The authorization package is a collection of documents and artifacts used to support the authorization decision, not the decision itself.
In the NIST Risk Management Framework (RMF), the authorization decision is the formal declaration by a Senior Agency Official for Authorizing Official (SAO/AO) that explicitly grants or denies authorization for an information system or common control to operate. This decision is based on a thorough review of the security authorization package and the assessed risk posture.
Risk response refers to the actions taken to mitigate, transfer, accept, or avoid identified risks, which informs the authorization decision but is not the decision itself.
Concept tested: NIST RMF authorization decision
Source: https://csrc.nist.gov/glossary/term/authorization_decision
Topics
Community Discussion
No community discussion yet for this question.