nerdexam
(ISC)2

CGRC · Question #22

The official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations (including…

The correct answer is A. Authorization (to operate). Authorization (to operate) is the official management decision by a senior organizational official to permit an information system's operation and accept its associated risks. This decision is based on the system's implemented security controls.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The official management decision given by a senior organizational official to authorize operation of an information system and to explicitly accept the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls. Response:

Options

  • AAuthorization (to operate)
  • BSystems operated
  • CSecurity Authorization
  • DSenior Organizational

How the community answered

(23 responses)
  • A
    91% (21)
  • C
    4% (1)
  • D
    4% (1)

Why each option

Authorization (to operate) is the official management decision by a senior organizational official to permit an information system's operation and accept its associated risks. This decision is based on the system's implemented security controls.

AAuthorization (to operate)Correct

Authorization (to operate), often referred to as ATO, is the formal decision by an authorizing official to accept the residual risk of operating an information system. This process confirms that the system's security controls are deemed sufficient and that the organization is willing to bear any remaining risks.

BSystems operated

Systems operated is a generic term that does not represent a specific formal decision or process in risk management.

CSecurity Authorization

Security Authorization is a broader term that encompasses the entire process leading to an authorization decision, but Authorization (to operate) is the specific decision itself.

DSenior Organizational

Senior Organizational describes a position or a type of official, not the decision being made.

Concept tested: Risk Management Framework - Authorization to Operate (ATO)

Source: https://csrc.nist.gov/glossary/term/authorization_to_operate

Topics

#Authorization to Operate (ATO)#Risk Acceptance#Management Decision#Information System Security

Community Discussion

No community discussion yet for this question.

Full CGRC Practice