CGRC · Question #370
Why would the authorization decision issue a determination of Not Authorized? Response:
The correct answer is B. If it is deemed that the agency level risk is unacceptably high.. This question asks for the primary reason an information system would receive a "Not Authorized" decision during the RMF authorization step.
Question
Why would the authorization decision issue a determination of Not Authorized? Response:
Options
- AIf the system is not authorized (NA) to process classified information.
- BIf it is deemed that the agency level risk is unacceptably high.
- CIf the system is mission critical and requires an interim authority to operate.
- DThe information system is always accredited without any restrictions or limitations on its operation.
How the community answered
(51 responses)- A2% (1)
- B90% (46)
- C6% (3)
- D2% (1)
Why each option
This question asks for the primary reason an information system would receive a "Not Authorized" decision during the RMF authorization step.
Whether a system processes classified information or not is part of its categorization and requirements, not the sole reason for a "Not Authorized" decision unless it directly contributes to unacceptable risk. "NA" in the context of classified information is not directly related to an overall system authorization determination.
An authorization decision of "Not Authorized" is issued when the Authorizing Official (AO) determines that the residual risk to the agency, based on the system's security posture and mission impact, is unacceptably high. This indicates that the identified risks outweigh the benefits of operating the system in its current state.
If a system is mission critical and requires an interim authority to operate (IATO), it suggests a temporary authorization with conditions, not a complete denial ("Not Authorized"). An IATO is a conditional authorization, not a refusal.
It is incorrect to assume an information system is always accredited without restrictions; accreditation is a risk-based decision and can include conditions or even denial of authorization.
Concept tested: NIST RMF Authorization decision outcomes
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.