CGRC · Question #29
The authorizing official may determine that additional information supporting the authorization package is needed. The additional documentation may include all but one of the following. Response:
The correct answer is A. Plan of action and milestones. The Plan of Action and Milestones (POA&M) is a document detailing deficiencies and their remediation, which is a required component of an authorization package. Therefore, an authorizing official would typically not request it as additional information, as it's foundational.
Question
The authorizing official may determine that additional information supporting the authorization package is needed. The additional documentation may include all but one of the following. Response:
Options
- APlan of action and milestones
- BRisk assessments
- CContingency plans
- DSupply chain risk management plans
How the community answered
(45 responses)- A71% (32)
- B4% (2)
- C18% (8)
- D7% (3)
Why each option
The Plan of Action and Milestones (POA&M) is a document detailing deficiencies and their remediation, which is a required component of an authorization package. Therefore, an authorizing official would typically not request it as additional information, as it's foundational.
The Plan of Action and Milestones (POA&M) is a mandatory document that identifies security deficiencies and outlines a remediation schedule, making it an inherent part of the authorization package. An authorizing official would typically review the POA&M as a core component, not request it as additional supporting documentation.
Risk assessments provide detailed analysis of risks and mitigation strategies, which an authorizing official may request as supplemental information.
Contingency plans outline procedures for responding to disruptions and restoring operations, which an authorizing official may require for a comprehensive view of system resilience.
Supply chain risk management plans address risks associated with external providers and components, often requested to ensure the trustworthiness of the system's supply chain.
Concept tested: RMF Authorization Package Components
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.