nerdexam
(ISC)2

CGRC · Question #370

Why would the authorization decision issue a determination of Not Authorized? Response:

The correct answer is B. If it is deemed that the agency level risk is unacceptably high.. This question asks for the primary reason an information system would receive a "Not Authorized" decision during the RMF authorization step.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Why would the authorization decision issue a determination of Not Authorized? Response:

Options

  • AIf the system is not authorized (NA) to process classified information.
  • BIf it is deemed that the agency level risk is unacceptably high.
  • CIf the system is mission critical and requires an interim authority to operate.
  • DThe information system is always accredited without any restrictions or limitations on its operation.

How the community answered

(51 responses)
  • A
    2% (1)
  • B
    90% (46)
  • C
    6% (3)
  • D
    2% (1)

Why each option

This question asks for the primary reason an information system would receive a "Not Authorized" decision during the RMF authorization step.

AIf the system is not authorized (NA) to process classified information.

Whether a system processes classified information or not is part of its categorization and requirements, not the sole reason for a "Not Authorized" decision unless it directly contributes to unacceptable risk. "NA" in the context of classified information is not directly related to an overall system authorization determination.

BIf it is deemed that the agency level risk is unacceptably high.Correct

An authorization decision of "Not Authorized" is issued when the Authorizing Official (AO) determines that the residual risk to the agency, based on the system's security posture and mission impact, is unacceptably high. This indicates that the identified risks outweigh the benefits of operating the system in its current state.

CIf the system is mission critical and requires an interim authority to operate.

If a system is mission critical and requires an interim authority to operate (IATO), it suggests a temporary authorization with conditions, not a complete denial ("Not Authorized"). An IATO is a conditional authorization, not a refusal.

DThe information system is always accredited without any restrictions or limitations on its operation.

It is incorrect to assume an information system is always accredited without restrictions; accreditation is a risk-based decision and can include conditions or even denial of authorization.

Concept tested: NIST RMF Authorization decision outcomes

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Authorization Decision#Risk Management#Residual Risk#Not Authorized Determination

Community Discussion

No community discussion yet for this question.

Full CGRC Practice