CGRC · Question #387
Which RMF role needs to be aware of id of new threats, evolving risks, changes in data sensitivity/criticality and changes in operating environment; to make conscious decision on whether system needs
The correct answer is A. Authorizing Official (AO). The Authorizing Official (AO) is the RMF role responsible for understanding evolving risks and changes to a system's environment to make re-certification decisions.
Question
Which RMF role needs to be aware of id of new threats, evolving risks, changes in data sensitivity/criticality and changes in operating environment; to make conscious decision on whether system needs to re-certify. Response:
Options
- AAuthorizing Official (AO)
- BPolar Ozone and Aerosol Measurement (POAM)
- CIndustry Standard Architecture (ISA)
- DSuperintendent of Police (SP)
How the community answered
(41 responses)- A90% (37)
- B2% (1)
- C2% (1)
- D5% (2)
Why each option
The Authorizing Official (AO) is the RMF role responsible for understanding evolving risks and changes to a system's environment to make re-certification decisions.
The Authorizing Official (AO) is the senior management official who formally accepts the risk of operating an information system based on the security assessment. This role requires continuous awareness of new threats, evolving risks, changes in data criticality, and environmental shifts to make informed decisions regarding system authorization or re-certification, as they bear the ultimate accountability for the system's operational risk.
Polar Ozone and Aerosol Measurement (POAM) is a satellite instrument, completely unrelated to RMF roles.
Industry Standard Architecture (ISA) refers to a computer bus standard and is not an RMF role.
Superintendent of Police (SP) is a law enforcement rank and not an RMF role.
Concept tested: Risk Management Framework (RMF) roles
Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.