nerdexam
(ISC)2

CGRC · Question #200

"The authorization for the system or the common control is approved or denied" is an an outcome of which of the ensuing tasks? Response:

The correct answer is C. Authorization decision. The approval or denial of authorization for a system or common control is the direct outcome of the authorization decision task within the Risk Management Framework.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

"The authorization for the system or the common control is approved or denied" is an an outcome of which of the ensuing tasks? Response:

Options

  • AAuthorization reporting
  • BAuthorization package
  • CAuthorization decision
  • DRisk response

How the community answered

(28 responses)
  • B
    4% (1)
  • C
    89% (25)
  • D
    7% (2)

Why each option

The approval or denial of authorization for a system or common control is the direct outcome of the authorization decision task within the Risk Management Framework.

AAuthorization reporting

Authorization reporting involves communicating the status and outcomes of the authorization process, but it's not the decision itself.

BAuthorization package

The authorization package is a collection of documents and artifacts used to support the authorization decision, not the decision itself.

CAuthorization decisionCorrect

In the NIST Risk Management Framework (RMF), the authorization decision is the formal declaration by a Senior Agency Official for Authorizing Official (SAO/AO) that explicitly grants or denies authorization for an information system or common control to operate. This decision is based on a thorough review of the security authorization package and the assessed risk posture.

DRisk response

Risk response refers to the actions taken to mitigate, transfer, accept, or avoid identified risks, which informs the authorization decision but is not the decision itself.

Concept tested: NIST RMF authorization decision

Source: https://csrc.nist.gov/glossary/term/authorization_decision

Topics

#Authorization Decision#Risk Management Framework (RMF)#Authority to Operate (ATO)#System Approval

Community Discussion

No community discussion yet for this question.

Full CGRC Practice